Senior Technology Governance, Risk & Compliance (GRC) Analyst
FanDuel is a premier US-based gaming destination, offering daily fantasy sports, sports betting, and online casino games. Founded in 2009 to innovate the fantasy sports industry, it has become a leading mobile sports betting operator, allowing users to bet on sports, play online games, and build fantasy teams across a wide array of professional sports leagues.
Funding
Projects
About FanDuel
FanDuel is the premier gaming destination and #1 Sportsbook in the United States. What started as a backyard brainstorm in Texas in 2009 has grown into a major force in the gaming industry. The company revolutionized fantasy sports by simplifying the season-long game into daily contests, allowing fans to compete and win daily. Today, with over 12 million registered users, FanDuel offers a wide range of products including sports betting on leagues like the NFL, NBA, MLB, and NHL; an online casino with blackjack, slots, and live dealer games; daily fantasy sports for various sports like football, baseball, and basketball; and horse racing betting for major events. Additionally, FanDuel provides content through FanDuel TV and insights via FanDuel Research, making every moment of the game more engaging for its users.
Skills
About the Role
You will join the Technology GRC team as a strategic specialist supporting the first line of defense function. You will design and mature the Technology Unified Controls framework, developing the governance policies, standards, and procedures that define how technology decisions are made and how accountability flows across the organization. You will navigate the complete control lifecycle: collaborating on process discovery, identifying and implementing controls that address key risks and regulatory requirements, and establishing testing and continuous assurance mechanisms to keep controls effective. You will manage issues as they emerge, provide remediation guidance, and track progress toward resolution. You will serve as the first-line point of contact for compliance activities such as SOC2, PCI, and state regulatory exams, acting as liaison between audit teams and internal control stakeholders. You will deliver executive reports on control health and risk posture, maintain GRC tools and metrics dashboards, align control standards with Flutter Entertainment's GRC groups, lead cross-functional workshops, and mentor junior team members.
Requirements
- Bachelor's degree preferred in a technical field such as Cybersecurity or Information Technology, or equivalent experience
- 5+ years of related experience across technology and cybersecurity Governance, Risk, and Compliance
- Hands-on experience navigating the full control lifecycle including control design, testing, issue management, and remediation tracking
- Experience conducting technology risk assessments and maintaining risk registers
- In-depth understanding of IT platforms and systems including AWS, Okta, GitHub, and Atlassian products
- Ability to discover, analyze, and document comprehensive data flows across infrastructure
- Experience developing technology policies, standards, and procedures and supporting governance committees
- Hands-on experience executing and managing IT and security audits or regulatory assessments in a heavily regulated industry
- Strong IT and security risk domain knowledge including GLI-33b, GLI-19, NIST 800-53, NIST CSF, SOX, SOC2, and PCI
- Knowledge of qualitative and quantitative risk management methodologies such as NIST RMF and FAIR
- Ability to translate risk and control standards into functional business requirements
- Strong written and verbal communication skills for technical and non-technical stakeholders
- Proficiency with Microsoft Office, GRC and project management tools such as Optro, Anecdotes, Jira, and SharePoint
- Experience as a consultant in risk, compliance, or audit is a plus
- Certifications such as CISA, CISM, CISSP, CRISC, CGEIT, CCSK/CCSP, PCI ISA/QSA, or Security+ are preferred
Responsibilities
- Lead and mature a risk-based technology control program across the Technology organization
- Navigate the complete control lifecycle including process discovery, control implementation, testing, and issue management
- Develop and deliver executive reports of technology control health, issues, and risk posture
- Serve as first-line point of contact for compliance activities and liaison between audit teams and control stakeholders
- Partner with Technology and Enterprise Risk Management teams to maintain the technology risk and controls framework
- Advise and support technology control owners during regulatory examinations and internal audits
- Develop and maintain comprehensive technology governance policies, standards, and procedures
- Develop, support, and maintain GRC tools for continuous controls monitoring and reporting
- Align control standards with Flutter Entertainment and other brands' GRC groups
- Track issues throughout the lifecycle from identification through remediation and monitoring
- Lead cross-functional discussions and workshops to enhance awareness of the control environment
- Stay abreast of evolving technology and cybersecurity threats, trends, and regulatory changes
- Develop and deliver tailored training and communications on GRC obligations
- Maintain procedures, playbooks, reference documentation, and metrics dashboards
- Mentor and guide junior team members
Benefits
- Health plans including fertility and family planning programs, mental health support, and fitness benefits
- Generous paid time off and sick leave
- Annual bonus and long-term incentive opportunities
- 401k with up to a 5% match
- Commuter benefits
- Pet insurance
- Medical, vision, and dental insurance
- Life insurance
- Disability insurance
- Short-term and long-term incentive compensation including cash bonuses and stock program participation
- 14 paid company holidays
