ForgeApply · Job listing
Senior Technology Governance, Risk & Compliance (GRC) Analyst
Fanduel
Apply in about a minute — without sacrificing quality.
ForgeApply autofills this application and tailors your resume to this exact posting. You review everything before it's sent. Free trial, no card required.
About this role
THE POSITION Our roster has an opening with your name on it
FanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers a unique opportunity to shape how technology governance, risk management, and compliance work together across the organization. The ideal candidate brings breadth of knowledge and understanding across the full GRC landscape—understanding not just where controls fit, but how governance frameworks drive accountability, how risks cascade through technology systems, and where to plug into partner teams to deliver meaningful outcomes.
At its core, this role is about building and maturing our Technology Unified Controls framework. You will be instrumental in designing and establishing the governance structures and frameworks that define how technology decisions are made, who has authority over critical systems, and how accountability flows through the organization. You'll develop and maintain the comprehensive technology governance policies, standards, and procedures that serve as the backbone for consistent, compliant operations. Beyond creating these frameworks, you'll ensure they remain aligned with enterprise governance principles and regulatory requirements as the landscape evolves.
Across the risk and control landscape, you will navigate the complete control lifecycle. This means collaborating on process discovery to understand how FanDuel workstreams function, identifying controls that address key risks and regulatory requirements, implementing those controls across the technology environment, and establishing testing and continuous assurance mechanisms to ensure controls remain effective. You'll manage issues as they emerge, providing remediation guidance and tracking progress toward resolution. You'll also lead relevant compliance obligations and assessments—whether PCI, SOC2, GLI, state regulatory requirements, or others—ensuring that technology controls specifically address these mandates.
In addition to the specific responsibilities outlined above, employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs.
THE GAME PLAN Everyone on our team has a part to play
• Lead and mature a risk-based technology control program to design, implement, and monitor the effectiveness of key controls across the Technology organization, ensuring alignment with FanDuel's security frameworks, industry best practices, and regulatory requirements (NIST CSF, GLI-GSF, PCI, SOC2, SOX)
• Navigate the complete control lifecycle - including process discovery, control identification and implementation, testing and continuous assurance, and issue management with remediation guidance bringing along an automation-first mindset
• Develop and deliver executive reports of technology control health, issues, and risk posture
• Serve as the Technology organization's first line point of contact for various compliance activities (e.g. SOC2, PCI, State Regulatory Exams) and act as a primary liaison between audit teams and internal control stakeholders to ensure clear communication of requirements, timelines, and expectations
• Partner with Technology and Enterprise Risk Management teams to maintain FanDuel's technology risk and controls framework, ensuring risks are identified, assessed, documented, and mapped to effective controls aligned with the company's risk appetite
• Advise and support technology control owners during regulatory examinations or internal audits / assessments, including clarifying scope, expectations and timelines, coordinating meetings, facilitating evidence gathering, clarifying issues with relevant SMEs & stakeholders, and developing necessary action plans and management responses
• Develop and maintain comprehensive technology governance policies, standards, and procedures; ensure alignment with enterprise governance principles and regulatory requirements
• Actively develop, support, and maintain FanDuel's GRC tools to provide continuous controls monitoring and consistent control health reporting while pushing forward an audit-ready environment.
• Align control standards with Flutter Entertainment and other brands' GRC groups to push efficiencies and best practices across the enterprise
• Track issues throughout the lifecycle, from initial deviation identification, root cause analysis, remediation plan development, and reporting, as well as supporting resolution and ongoing monitoring
• Lead cross-functional discussions and workshops to enhance awareness and foster continuous improvement across the technology control environment
• Stay abreast of evolving technology & cybersecurity threats, trends, and regulatory changes to enhance control, risk, and governance strategies
• Develop and deliver tailored training and communications on relevant GRC obligations for the technology community, as needed
• Maintain procedures, playbooks, reference documentation, and metrics dashboards
• Assist with special GRC, regulatory, and control assessment and department initiatives, as assigned
• Mentor and guide junior team members, sharing expertise and promoting continuous professional development
THE STATS What we're looking for in our next teammate
• Bachelor’s degree preferred in a technical field (e.g., Cybersecurity, Information Technology) or equivalent combination of education, training, and relevant experience.
• 5+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.
• Hands-on experience navigating the full control lifecycle – process and risk identification, control design and definition, design and operating effectiveness testing, issue management, and remediation tracking.
• Experience cond
Salary insight
The midpoint of this range ($156k) is about 11% below the median disclosed salary for New York roles listed on ForgeApply ($175k across 4,613 jobs).
Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.
Ready to apply to Fanduel?
Apply in about a minuteSimilar jobs
- Senior Technology Governance, Risk & Compliance (GRC) Analyst — Fanduel · Atlanta, Georgia, United States
- Security Governance, Risk & Compliance Analyst — Makeawishamerica · Remote
- Third Party Risk Analyst, Security GRC — Anthropic · Remote-Friendly (Travel Required) | San Francisco, CA
- Senior Security GRC Analyst — Roblox · San Mateo, CA, United States
- Sr Manager, InfoSec Governance Risk and Compliance (GRC) — Ivalua · New York City, New York, US
- Sr Manager, InfoSec Governance Risk and Compliance (GRC) — Ivalua · San Francisco Bay Area, California, United States
- Sr Manager, InfoSec Governance Risk and Compliance (GRC) — Ivalua · Pittsburgh, Pennsylvania, United States
- Vendor Risk and GRC Analyst — Patrianna · Remote
More like this: More jobs at Fanduel · Browse all jobs