About Us
Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally.
About the Team
Launched in 2021, Fanatics Betting and Gaming is the online and retail sports betting subsidiary of Fanatics, a global digital sports platform. The Fanatics Sportsbook is available to 95% of the addressable online sports bettor market in the U.S. Fanatics Casino is currently available online in Michigan, New Jersey, Pennsylvania and West Virginia. Fanatics Betting and Gaming operates twenty-two retail sports betting locations, including the only sportsbook inside an NFL stadium at Northwest Stadium. Fanatics Betting and Gaming is headquartered in New York with offices in Denver, Leeds and Dublin.
As a Security Analyst II at Fanatics Betting & Gaming (FBG), your knowledge and experience in third party security and risk management will help ensure that our vendor ecosystem operates securely, minimizing risk while enabling the business to scale confidently and compliantly. This role sits within the Information Security department and reports to the Director of Information Security.
Responsibilities:
β’ Conduct comprehensive third-party security risk assessments by evaluating vendor controls, policies, and documentation (e.g., SOC 2, ISO, penetration tests) against established frameworks.
β’ Analyze assessment results to identify risks, document findings, and provide actionable remediation recommendations.
β’ Assess risks related to data handling, privacy, critical integrations, and system dependencies
β’ Assess risks associated with third parties use of emerging technologies, including AI/ML, with a focus on data security and governance
β’ Collaborate with procurement, legal, and business stakeholders to embed security requirements into vendor onboarding and lifecycle management processes.
β’ Monitor vendor risk posture over time, including tracking security incidents, control changes, and emerging risks.
β’ Track, measure, and report on third-party risk metrics, trends, and remediation progress to leadership.
β’ Support the development, maintenance, and continuous improvement of third-party risk management policies, standards, and procedures.
β’ Leverage available tools, including AI-assisted technologies, to improve the efficiency and consistency of third party security risk assessments and documentation.
β’ Ensure compliance with applicable regulatory and security frameworks (e.g., NIST, ISO 27001, SOX) and support incident response efforts involving third parties.
Qualifications:
β’ 2 - 3+ years of experience in cybersecurity, risk management, or third-party/vendor risk management.
β’ Strong understanding of security frameworks and standards such as NIST CSF, NIST 800-53, ISO 27001, and SOC 2.
β’ Experience reviewing and assessing vendor security documentation (e.g., SOC reports, ISO certifications, security questionnaires).
β’ Experience working with or supporting third-party risk management programs and tools (e.g., OneTrust, SecurityScorecard)
β’ Understanding of risks associated with third-party use of AI/ML technologies
β’ Strong written and verbal communication skills, with the ability to communicate effectively with both technical and non-technical stakeholders.
β’ Ability to prioritize and balance multiple projects simultaneously
β’ Ability to collaborate and work in a team environment
Salary Range: $128,250 - $168,750 USD per year
The base salary for this role is based on job-related knowledge, skills, and experience and may vary depending on the successful candidateβs geographic location. For information about our benefits, please visit [Upgrade to PRO to see link]
Depending on the role, your interview and onboarding experience may include in-person components, such as onsite interviews or Launching into Better: LIVEβa multi-day cultural immersion in New York City for full-time, non-seasonal hires. These sessions are designed to build connection and bring our culture to life, though specific travel and participation requirements will be confirmed based on your role and location. Your recruiter will provide clear guidance at each stage of the process.
#LI-CC1
For information about our benefits, please visit [Upgrade to PRO to see link]
Ranges will change based on country and state of residence, which are reflected in Geographical Zones defined by Fanatics Betting and Gaming. The range incorporates all of our Geographical Compensation Zones and is subject to change as the Zone associated with the actual offer is confirmed. In addition to the base and bonus, full-time employment, and more. For information about our benefits, please visit [Upgrade to PRO to see link]
Salary Range$128,250β$168,750 USD