Full-Time

Identity Governance & Controls Monitoring Senior Manager

Posted on 4/15/2024

FanDuel

FanDuel

1,001-5,000 employees

Sports betting and daily fantasy sports provider

Data & Analytics

Senior, Expert

Atlanta, GA, USA

Required Skills
Microsoft Azure
Management
AWS
Google Cloud Platform
Requirements
  • Minimum 10 years of cybersecurity experience in GRC or across a variety of cybersecurity domains in a highly regulated industry.
  • Hands-on experience with IT controls, internal auditing, or IT risk management, including SOC 2, SOX, GDPR, PCI-DSS, NIST CSF, and ISO 27001. Exposure to GLI preferred.
  • Hands-on experience with Identity & Continuous control monitoring tools such as SailPoint, Zilla, Vanta, Drata, ZenGRC, etc. or building custom technical assurance capabilities.
  • Advanced understanding of identity lifecycle management e.g., Contractor path vs FTE, rehire, conversions (contractor to FTE).
  • Advanced technical knowledge of cloud technology (AWS, GCP, Azure), security controls, database systems, network systems, auditing and compliance software and tools, and IT infrastructure.
  • Experience with decision making around when to buy vs. build for tooling and capabilities.
  • Relevant cybersecurity certification(s), including CISSP, CISA, CISM, or CCSP preferred.
Responsibilities
  • Play an integral role in enhancing and developing the strategic direction of the Identity Governance and Continuous Controls Monitoring programs.
  • Own and maintain the efficacy of all team policies, procedures, and processes in accordance with the business needs.
  • Manage overall technical solution(s) supporting Identity & Controls Monitoring.
  • Identify opportunities for automation and improvement to help the team and other key stakeholders work smarter, faster, and more effectively.
  • Conduct continuous research, development, and adaptation of innovative technologies, best practices, and strategies to increase the effectiveness of continuous monitoring within the context of the company's operational landscape.
  • Develop and present KPIs, KRIs, and key program initiatives for Identity & Controls Monitoring.
  • Drive innovation and delivery of critical initiatives, assignments, and audits within the department.
  • Manage the end-to-end performance management lifecycle activities for a hybrid team of 5-6 analysts and engineers.
  • Provide guidance and mentorship to team members on department processes and security best practices.
  • Serve as first line of escalation for FanDuel’s controls adherence, overall health, and team inquiries.
  • Collaborate with cross-functional teams to integrate continuous assurance monitoring into existing security processes and workflows.
  • Assist the business in evaluating and mitigating potential risks by highlighting areas of concern, recommending potential solutions, implementing controls assurance system design updates, procedures, and changes to continuously monitor FanDuel’s required state of compliance for operation.
  • Provide training and support to enterprise teams on the program (process & tooling) and how to leverage the capability to monitor their control effectiveness.
  • Maintain contact with vendors, industry peers, and professional associations to keep informed of existing and evolving industry standards, technologies, and cyber threats especially around identity.
  • Become a trusted security advisor through bi-directional partnership across a wide range of stakeholders from Cyber GRC, Risk & Compliance, Internal Controls, Internal Audit, Enterprise IT, and Engineering.
  • Develop a risk-based approach for scoping, on-boarding, maintaining, and off-boarding applications in the IGA solution.
  • Oversee the User and Privileged Access Review lifecycle and ensure accuracy and compliance with critical controls.
  • Manage Access Management SOX ITGCs overall health and adoption, JML process oversight and lookbacks for SOX and other critical applications, separation of duties, and support application teams with audit evidence & responses as needed.
  • Advise FanDuel stakeholders across all departments on ways to enable better audit and assurance testing of cybersecurity controls and policies across key authoritative sources, e.g., NIST CSF, SOX ITGC, SOC2, PCI, GLI, etc.
  • Proactively seek to understand FanDuel’s internal policies and regulatory landscape and drive the alignment of all testing automation and control monitoring to applicable internal guidance, regulations, applicable laws, and standards.
  • Ensure timely alert and identification of control drift and work with control owners, Cyber GRC, and Enterprise Risk team members to document path to green.

FanDuel Group specializes in sports betting, fantasy sports, and online casino games, employing sports-tech to enhance user engagement across various popular sports and leagues. This company stands out as a leader in the sports-tech industry, providing services to a vast customer base of approximately 17 million across the US. Its commitment to technological advancement and customer satisfaction make it an exciting workplace for those passionate about merging technology with sports entertainment.

Company Stage

M&A

Total Funding

$4.6B

Headquarters

New York, New York

Founded

2009

Growth & Insights
Headcount

6 month growth

9%

1 year growth

19%

2 year growth

71%

Benefits

From peer-to-peer learning to industry conferences, there are a number of ways to develop your career

From your head to your toes we’ve got you covered with our 100% health insurance coverage

We keep a well-stocked supply of snacks and refreshments to keep you going throughout the day

Flexible hours and vacation scheduling let you work when you’re at your best

We provide the latest tech and equipment, you get the job done

INACTIVE