Back to jobs

TPRM Analyst, Info Sec

New York, NY, United States

About Us

Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally. 

About the Role

We are seeking a detail-oriented, analytical, and highly motivated Senior/Staff Analyst to support and scale our Information Security Third-Party Risk Management (TPRM) program. This role will play a key part in assessing, monitoring, and mitigating risks associated with third-party vendors. You will use our new modern, AI-powered TPRM platform to assess risk, analyze vendor responses and artifacts, and drive practical informed recommendations. You will partner closely with cross-functional teams, including Legal, Procurement, Information Security, and business stakeholders to enable risk-informed decisions and strengthen our overall third-party risk posture.

 

Your Impact

  • Strengthen Resilience: Directly contribute to the security and resilience of the organization by developing and supporting a robust third-party risk management framework
  • Drive Compliance: Ensure third-party relationships adhere to company policies, regulatory requirements, and industry best practices
  • Enable the Business: Partner with business units to support risk-aware decision-making, enabling effective supplier engagement while safeguarding the organization

 

Key Responsibilities

Risk Assessment & Due Diligence

  • Perform thorough due diligence reviews with the assistance of our AI-powered platform, including risk questionnaires, documentation analysis, and standard supplier due diligence assessments
  • Ensure all third-party due diligence artifacts and supporting documentation are properly captured and maintained in the TPRM platform
  • Evaluate third-party controls and documentation (e.g., SOC reports, policies, certifications etc.)
  • Coordinate closely with other Information Security (e.g., security architecture / engineering, and subsidiary GRC) teams throughout the business  to further assess third-party solutions as needed
  • Advise business and stakeholders on third-party risk

Monitoring, Remediation, and Offboarding

  • Continuously monitor third-party cyber posture, including ransomware susceptibility, breach likelihood, and other open-source intelligence signals using our modern cyber rating platform
  • Triage alerts and escalate early warnings as appropriate
  • Develop and manage corrective action plans and control documentation for identified risks and/or issues
  • Track and evaluate vendor remediation efforts to ensure timely and effective resolution, working with business owners to address underperformance or emerging concerns
  • Conduct periodic and event-driven reassessments of third parties based on risk and criticality
  • Ensure secure third-party offboarding, including data handling, access revocation, and closure of contractual and security obligations.

Collaboration & Process Improvement

  • Collaborate with business units, Legal, Information Security, and other risk subject matter experts to address and mitigate identified risks
  • Support internal, customer, and third-party audits related to supplier risk and compliance
  • Contribute to the development and enhancement of TPRM policies, standards, and procedures
  • Create and implement scalable solutions for supplier tracking, monitoring, and compliance
  • Stay current on industry trends, emerging risks, and regulatory changes impacting third-party relationships

What We’re Looking For

  • Deep experience in Information Security Third-Party Risk Management, Risk Management, GRC Compliance, or a related field
  • Strong analytical skills with the ability to identify, assess, and resolve complex issues
  • Familiarity with risk management frameworks (e.g., NIST, ISO etc.) and vendor risk best practices
  • Excellent communication and interpersonal skills, with the ability to collaborate effectively across teams
  • High level of professionalism, integrity, and commitment to accuracy and thoroughness
  • A risk-focused, outcomes-focused mindset - you know how to balance thoroughness with speed, and you're comfortable prioritizing efforts to address most critical risks and moving quickly in a fast-paced business without compromising control integrity
  • Comfortable working with technology platforms and AI-assisted tooling (you don't need to be technical, but you should be curious and adaptable)

 What Success Looks Like

  • Consistent, high-quality execution of vendor risk assessments and due diligence
  • Clear, actionable reporting that enhances leadership visibility into third-party risk
  • Strong cross-functional partnerships enabling risk-informed business decisions
  • Continuous improvement of TPRM processes, tools, and controls

Why Join Us

  • Opportunity to help build and mature a critical risk management function
  • High visibility role with cross-functional impact
  • Collaborative and fast-paced environment

The salary range represents base pay only and does not include short-term or long-term incentive compensation. When determining base pay as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training. For information about our benefits, please visit https://benefitsatfanatics.com/

Salary Range

$155,000 - $165,000 USD

Create a Job Alert

Interested in building your career at Fanatics Inc.? Get future opportunities sent straight to your email.

Apply for this job

*

indicates a required field

Phone
Resume/CV*

Accepted file types: pdf, doc, docx, txt, rtf

Cover Letter

Accepted file types: pdf, doc, docx, txt, rtf


Employment

Select...
Select...

Education

Select...
Select...
Select...

Select...
Select...
Select...
Select...
Select...
Select...
Select...
Select...

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in Fanatics Inc.’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Select...
Select...
Race & Ethnicity Definitions

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Classification of protected categories is as follows:

A "disabled veteran" is one of the following: a veteran of the U.S. military, ground, naval or air service who is entitled to compensation (or who but for the receipt of military retired pay would be entitled to compensation) under laws administered by the Secretary of Veterans Affairs; or a person who was discharged or released from active duty because of a service-connected disability.

A "recently separated veteran" means any veteran during the three-year period beginning on the date of such veteran's discharge or release from active duty in the U.S. military, ground, naval, or air service.

An "active duty wartime or campaign badge veteran" means a veteran who served on active duty in the U.S. military, ground, naval or air service during a war, or in a campaign or expedition for which a campaign badge has been authorized under the laws administered by the Department of Defense.

An "Armed forces service medal veteran" means a veteran who, while serving on active duty in the U.S. military, ground, naval or air service, participated in a United States military operation for which an Armed Forces service medal was awarded pursuant to Executive Order 12985.

Select...

Voluntary Self-Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number 1250-0005
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. We have a goal of having at least 7% of our workers as people with disabilities. The law says we must measure our progress towards this goal. To do this, we must ask applicants and employees if they have a disability or have ever had one. People can become disabled, so we need to ask this question at least every five years.

Completing this form is voluntary, and we hope that you will choose to do so. Your answer is confidential. No one who makes hiring decisions will see it. Your decision to complete the form and your answer will not harm you in any way. If you want to learn more about the law or this form, visit the U.S. Department of Labor’s Office of Federal Contract Compliance Programs (OFCCP) website at www.dol.gov/ofccp.

How do you know if you have a disability?

A disability is a condition that substantially limits one or more of your “major life activities.” If you have or have ever had such a condition, you are a person with a disability. Disabilities include, but are not limited to:

  • Alcohol or other substance use disorder (not currently using drugs illegally)
  • Autoimmune disorder, for example, lupus, fibromyalgia, rheumatoid arthritis, HIV/AIDS
  • Blind or low vision
  • Cancer (past or present)
  • Cardiovascular or heart disease
  • Celiac disease
  • Cerebral palsy
  • Deaf or serious difficulty hearing
  • Diabetes
  • Disfigurement, for example, disfigurement caused by burns, wounds, accidents, or congenital disorders
  • Epilepsy or other seizure disorder
  • Gastrointestinal disorders, for example, Crohn's Disease, irritable bowel syndrome
  • Intellectual or developmental disability
  • Mental health conditions, for example, depression, bipolar disorder, anxiety disorder, schizophrenia, PTSD
  • Missing limbs or partially missing limbs
  • Mobility impairment, benefiting from the use of a wheelchair, scooter, walker, leg brace(s) and/or other supports
  • Nervous system condition, for example, migraine headaches, Parkinson’s disease, multiple sclerosis (MS)
  • Neurodivergence, for example, attention-deficit/hyperactivity disorder (ADHD), autism spectrum disorder, dyslexia, dyspraxia, other learning disabilities
  • Partial or complete paralysis (any cause)
  • Pulmonary or respiratory conditions, for example, tuberculosis, asthma, emphysema
  • Short stature (dwarfism)
  • Traumatic brain injury
Select...

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.