ABOUT FANDUEL GROUP
FanDuel Group is a world-class team of brands and products all built with one goal in mind — to give fans new and innovative ways to interact with their favorite games, sports, teams, and leagues. That’s no easy task, which is why we’re so dedicated to building a winning team. And make no mistake, we are here to win, but we believe in winning right. That means we’ll never compromise when it comes to looking out for our teammates. From our many opportunities for professional development to our generous insurance and paid leave policies, we’re committed to making sure our employees get as much out of FanDuel as we ask them to give.
FanDuel Group is based in New York, with offices in California, New Jersey, Florida, Oregon and Scotland. Our brands include:
- FanDuel — A game-changing real-money fantasy sports app
- FanDuel Sportsbook — America’s #1 sports betting app
- TVG — The best-in-class horse racing TV/media network and betting platform
- FanDuel Racing — A horse racing app built for the average sports fan
- FanDuel Casino & Betfair Casino — Fan-favorite online casino apps
- FOXBet — A world-class betting platform and affiliate of FanDuel Group
- PokerStars — The premier online poker product and affiliate of FanDuel Group
Our roster has an opening with your name on it
The Cyber Security TPSA (Third Party Supplier Assurance) Analyst will ensure that we maintain a safe and healthy relationship with suppliers via third-party risk management processes.
THE GAME PLAN
Everyone on our team has a part to play
- The Cyber Security TPSA Analyst must understand the cyber security risks posed by third parties working across with group and in context to the Flutter risk appetite.
- The analyst will identify and assist with the management of third-party risk using established risk management processes both at group and divisional level.
- Working within the third-party supplier engagement life cycle, the analyst will complete security assessments of new suppliers.
- Perform continuous assessments of existing suppliers based on a risk-based selection process. This process involves reviewing evidence of the third-parties control environment.
- When the relationship ends with a third-party supplier, the analyst must work with the business relationship owner to ensure that contract termination activities have been completed, including ensuring all Flutter data and assets have been deleted or returned.
- Ensure the list of suppliers for the Flutter group is updated with accurate information including business relationship owners and the risk category.
- Support the procurement process with the provision of relevant security contract clauses.
- In collaboration with the Cyber Security Senior Manager – Technical Operational Compliance assess and track remediation plans for control deficiencies uncovered.
- Work with the business relationship owner to ensure security is a top priority and build safe and healthy relationships with third party suppliers.
- Perform regular governance activities to ensure third parties are being managed appropriately, e.g. no excessive access entitlements assigned.
- Ensure any systems used to support the assurance program remain operational; including the monitoring of performance, ensure that the systems remain patched and any upgrades are managed.
- Support the group business processes with accurate, relevant risk-based information about a third-party supplier’s security posture.
- Collate data for other risk reporting functions as required, e.g. Flutter KRI regular reporting, internal or external audit.
- Maintain accurate records of all TPSA activity which can stand up to scrutiny by internal & external auditors as well as divisional stakeholders.
- Build and maintain relationships with key stakeholders across the group.
What we’re looking for in our next teammate
- A security information security governance, risk & compliance professional with an understanding of third-party cyber security risk.
- Experience of dealing with supplier contracts, security controls, industry standard security processes and technologies, and personal data regulations (e.g. GDPR).
- Experience performing risk assessments of the supply chain and articulating the risk to ensure processes and technologies are adapted to manage the risk to an acceptable level.
- Understanding of the risk management lifecycle.
- Inquisitive, disciplined and logical thinker who possesses strong investigative and analytical qualities that will translate into providing independent and objective analysis of cyber security Risk based on complex data sets.
- Excellent verbal and written communications skills with a flexible attitude and the ability to meet deadlines under pressure.
- Able to adapt communication style and to appreciate different and opposing perspectives across multiple divisions.
- Results-oriented with the ability to influence outcomes with pragmatic recommendations and guidance.
- A working knowledge of current IT Security standards such as ISO 27001, PCI, NIST, ISF, UKGC and Data Protection.
- CRISC, CISA, CISSP, ISO 27001, COBIT, or ITIL certification is desirable.
We treat our team right
Competitive compensation is just the beginning. As part of our team, you can expect:
- An exciting and fun environment committed to driving real growth
- Opportunities to build really cool products that fans love
- Mentorship and professional development resources to help you refine your game
- Flexible vacation allowance to let you refuel
- Hall of Fame benefit programs and platforms
FanDuel Group is an equal opportunities employer. Diversity and inclusion in FanDuel means that we respect and value everyone as individuals. We don't tolerate bias, judgement or harassment. Our focus is on developing employees so that they reach their full potential.