Fanatics logo
Security Analyst II
full-timeUnited States$87k - $172k

Summary

Location

United States

Salary

$87k - $172k

Type

full-time

Explore Jobs

About this role

Overview

As Fanatics Betting & Gaming (FBG) accelerates Fanatics' mission to build the ultimate digital sports platform, the Information Security Analyst II role is critical to ensuring our governance, risk, and compliance programs keep pace with our rapid growth and evolving regulatory landscape. As an Information Security Analyst II at FBG, you'll serve as a key contributor to our security compliance efforts, conducting user access reviews, managing audit readiness activities, and implementing controls that protect our customers and business operations across our real-time, high-performance betting and gaming systems.

This role combines deep GRC expertise, policy development skills, and collaborative partnership with stakeholders across the organization to strengthen our security posture and compliance programs. You'll lead user access review processes, develop and socialize security policies and standards, manage audit and assessment activities, support incident response efforts, and build dashboards that provide visibility into control effectiveness. Working in a highly regulated industry, you'll help ensure our systems meet rigorous security and compliance standards including SOC 2, ISO 27001, and SOX while enabling the business to innovate with confidence. We need analysts who can balance thorough compliance rigor with the practical realities of a fast-moving organization—who understand both security frameworks and how to make controls work effectively in the real world. If you're passionate about building strong compliance programs that actually make organizations more secure and have the experience to back it up, we want to talk with you.

Responsibilities:

● Administer and enhance the user access review process to identify and address access control issues effectively.

● Draft, refine, and socialize policies/standards (access control, change management, vendor security, incident response); maintain clear SOPs and RACI.

● Prepare high‑quality evidence, narratives, and diagrams; coordinate with auditors/assessors; manage requests and deadlines.

● Participate in Incident response efforts by conducting log analysis, gathering evidence, and executing remediation tasks.

● Build dashboards for control health, User Access Reviews completion, vendor coverage, and audit findings; present insights to InfoSec leadership and stakeholders.

● Automate evidence collection and access reviews where possible; propose control enhancements that improve security and reduce operational toil.

● Deliver security awareness presentations for both technical and non-technical users. Actively contribute to ongoing information security education through diverse methods such as phishing simulations, annual training sessions, on-demand courses, and workshops.

● Support Governance, Risk, and Compliance (GRC) initiatives by implementing controls and gathering necessary evidence, and control testing.

● Support InfoSec Risk Issue Intake process to assess and risk rank new issues, identify and document mitigation plans/timelines with risk owners and SMEs, and track to resolution.

● Support quarterly user access review process (UARs) for SOX systems and ensure tickets are tracked to resolution and actioned within audit requirements. Complete lookback analysis where necessary

● Support Data Loss Prevention process by triaging and investigating alerts in the Mimecast/Code42 solution.

● Participate in an on-call rotation to address security incidents and escalations promptly.

Qualifications:

● Minimum of 2 years of experience as a Information security analyst or in a similar role

● Ability to leverage security compliance frameworks to support control improvement and evidence correlation.

● Working knowledge of SOC 2 (Trust Services Criteria) and ISO/IEC 27001/27002; familiarity with mapping controls across frameworks.

● Practical experience running User Access Reviews: scoping, sampling, evidence collection including completeness and accuracy, exception handling, and remediation follow‑through.

● Solid grasp of least privilege, SoD, joiner/mover/leaver, break‑glass, and privileged access management fundamentals.

● Strong documentation skills (control narratives, test plans, SOPs) and stakeholder communication.

● Comfort with spreadsheets and basic scripting/queries (e.g., SQL or Python) for sampling and evidence validation.

● Foundational knowledge in Agile methodologies with ability to successfully collaborate with multiple stakeholders.

● Ability to communicate effectively with technical and non-technical stakeholders.

● Ability to prioritize and balance multiple projects simultaneously.

● Ability to collaborate and work in a team environment.

● Proven experience drafting documentation such as standards, policies and architecture diagrams.

● Background in risk assessment methodologies such as NIST and FAIR is a plus

 

The expected salary range for this role is based on job-related knowledge, skills, and experience. This role is eligible for the Fanatics Betting and Gaming annual bonus program and an equity award. Salary range is listed in USD; actual salary will vary based on location. Salary Range: 87,400 - 172,000 per year (actual salary will be determined in part by a successful candidate’s geographic location). In addition to base salary, bonus, and equity, full-time employees are eligible for Medical, Dental, Vision, 401K, paid time off, and other benefits like GymPass, Pet Insurance, Family Care Benefits, and more. Remote employee may also be eligible for a home office setup stipend.

Depending on the role, your interview and onboarding experience may include in-person components, such as onsite interviews or Launching into Better: LIVE—a multi-day cultural immersion in New York City for full-time, non-seasonal hires. These sessions are designed to build connection and bring our culture to life, though specific travel and participation requirements will be confirmed based on your role and location. Your recruiter will provide clear guidance at each stage of the process.

Other facts

Tech stack
Information Security,Governance,Risk Management,Compliance,User Access Reviews,Incident Response,Security Policies,Documentation,SQL,Python,Agile,Security Awareness,Data Loss Prevention,Audit Readiness,Control Testing,Risk Assessment

About Fanatics

The Topps Company, Inc. is the iconic, preeminent leader in physical and digital collectibles. Acquired by Fanatics Collectibles in January 2022, Topps is the company's cornerstone licensed trading card brand.
Founded in 1938, The Topps Company started in confections with "Topps Gum" (later introducing Bazooka Bubble Gum) and released its first trading card set in 1950. Today, the company produces trading cards and collectibles, custom cards, memorabilia, sticker album collections and more related to iconic and pop culture brands such as Major League Baseball, Major League Soccer, Star Wars, Bundesliga, UEFA Champions League, World Wrestling Entertainment and Garbage Pail Kids. Fanatics Collectibles has also secured long-term, exclusive rights to design, manufacture and distribute trading cards for several additional sports properties, including NBA, NBPA and NFLPA, in the coming years.

Topps’ Digital Apps division produces, develops and operates mobile applications that give you access to an exclusive digital card collection at your fingertips that are sold via the Apple and Google app stores under the brand names BUNT, KICK, NHL SKATE, Star Wars Card Trader, The Walking Dead Universe Collect, WWE SLAM, Marvel Collect! and Disney Collect! https://play.toppsapps.com/.

Headquartered in New York City, Topps maintains offices in several countries including the United Kingdom, Germany, Italy, India and Brazil.

Team size: 201-500 employees
LinkedIn: Visit
Industry: Manufacturing

What you'll do

  • The Security Analyst II will administer user access reviews, manage audit readiness activities, and implement controls to protect business operations. They will also support incident response efforts and build dashboards for control effectiveness.

Ready to join Fanatics?

Take the next step in your career journey

Frequently Asked Questions

What does Fanatics pay for a Security Analyst II?

Fanatics offers a competitive compensation package for the Security Analyst II role. The salary range is USD 87k - 172k per year. Apply through Clera to learn more about the full compensation details.

What does a Security Analyst II do at Fanatics?

As a Security Analyst II at Fanatics, you will: the Security Analyst II will administer user access reviews, manage audit readiness activities, and implement controls to protect business operations. They will also support incident response efforts and build dashboards for control effectiveness..

Why join Fanatics as a Security Analyst II?

Fanatics is a leading Manufacturing company. The Security Analyst II role offers competitive compensation.

Is the Security Analyst II position at Fanatics remote?

The Security Analyst II position at Fanatics is based in United States, United States. Contact the company through Clera for specific work arrangement details.

How do I apply for the Security Analyst II position at Fanatics?

You can apply for the Security Analyst II position at Fanatics directly through Clera. Click the "Apply Now" button above to start your application. Clera's AI-powered platform will help match your profile with this opportunity and guide you through the application process. You can also learn more about Fanatics on their website.