E-3 Visa Governance Risk And Compliance Jobs
Governance, risk, and compliance roles qualify as E-3 visa specialty occupations when tied to a relevant bachelor's degree in business, law, finance, or a related field. Australian professionals in GRC can secure E-3 sponsorship without entering a lottery, making the path to U.S. employment more predictable than most work visas.
Find E-3 Visa Governance Risk And Compliance JobsOverview
Showing 4 of 9+ Governance Risk And Compliance jobs








See all Governance Risk And Compliance Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Governance Risk And Compliance roles.
Get Access To All Jobs
THE POSITION
Our roster has an opening with your name on it
FanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers a unique opportunity to shape how technology governance, risk management, and compliance work together across the organization. The ideal candidate brings breadth of knowledge and understanding across the full GRC landscape—understanding not just where controls fit, but how governance frameworks drive accountability, how risks cascade through technology systems, and where to plug into partner teams to deliver meaningful outcomes.
At its core, this role is about building and maturing our Technology Unified Controls framework. You will be instrumental in designing and establishing the governance structures and frameworks that define how technology decisions are made, who has authority over critical systems, and how accountability flows through the organization. You'll develop and maintain the comprehensive technology governance policies, standards, and procedures that serve as the backbone for consistent, compliant operations. Beyond creating these frameworks, you'll ensure they remain aligned with enterprise governance principles and regulatory requirements as the landscape evolves.
Across the risk and control landscape, you will navigate the complete control lifecycle. This means collaborating on process discovery to understand how FanDuel workstreams function, identifying controls that address key risks and regulatory requirements, implementing those controls across the technology environment, and establishing testing and continuous assurance mechanisms to ensure controls remain effective. You'll manage issues as they emerge, providing remediation guidance and tracking progress toward resolution. You'll also lead relevant compliance obligations and assessments—whether PCI, SOC2, GLI, state regulatory requirements, or others—ensuring that technology controls specifically address these mandates.
In addition to the specific responsibilities outlined above, employees may be required to perform other such duties as assigned by the Company. This ensures operational flexibility and allows the Company to meet evolving business needs.
THE GAME PLAN
Everyone on our team has a part to play
- Lead and mature a risk-based technology control program to design, implement, and monitor the effectiveness of key controls across the Technology organization, ensuring alignment with FanDuel's security frameworks, industry best practices, and regulatory requirements (NIST CSF, GLI-GSF, PCI, SOC2, SOX)
- Navigate the complete control lifecycle – including process discovery, control identification and implementation, testing and continuous assurance, and issue management with remediation guidance bringing along an automation-first mindset
- Develop and deliver executive reports of technology control health, issues, and risk posture
- Serve as the Technology organization's first line point of contact for various compliance activities (e.g. SOC2, PCI, State Regulatory Exams) and act as a primary liaison between audit teams and internal control stakeholders to ensure clear communication of requirements, timelines, and expectations
- Partner with Technology and Enterprise Risk Management teams to maintain FanDuel's technology risk and controls framework, ensuring risks are identified, assessed, documented, and mapped to effective controls aligned with the company's risk appetite
- Advise and support technology control owners during regulatory examinations or internal audits / assessments, including clarifying scope, expectations and timelines, coordinating meetings, facilitating evidence gathering, clarifying issues with relevant SMEs & stakeholders, and developing necessary action plans and management responses
- Develop and maintain comprehensive technology governance policies, standards, and procedures; ensure alignment with enterprise governance principles and regulatory requirements
- Actively develop, support, and maintain FanDuel's GRC tools to provide continuous controls monitoring and consistent control health reporting while pushing forward an audit-ready environment
- Align control standards with Flutter Entertainment and other brands' GRC groups to push efficiencies and best practices across the enterprise
- Track issues throughout the lifecycle, from initial deviation identification, root cause analysis, remediation plan development, and reporting, as well as supporting resolution and ongoing monitoring
- Lead cross-functional discussions and workshops to enhance awareness and foster continuous improvement across the technology control environment
- Stay abreast of evolving technology & cybersecurity threats, trends, and regulatory changes to enhance control, risk, and governance strategies
- Develop and deliver tailored training and communications on relevant GRC obligations for the technology community, as needed
- Maintain procedures, playbooks, reference documentation, and metrics dashboards
- Assist with special GRC, regulatory, and control assessment and department initiatives, as assigned
- Mentor and guide junior team members, sharing expertise and promoting continuous professional development
THE STATS
What we're looking for in our next teammate
- Bachelor's degree preferred in a technical field (e.g., Cybersecurity, Information Technology) or equivalent combination of education, training, and relevant experience.
- 5+ years related experience across technology and cybersecurity Governance, Risk, and Compliance (GRC), with demonstrated breadth across all three disciplines.
- Hands-on experience navigating the full control lifecycle – process and risk identification, control design and definition, design and operating effectiveness testing, issue management, and remediation tracking.
- Experience conducting technology risk assessments and maintaining risk registers and partnering with risk owners to define and track mitigation strategies aligned to risk appetite.
- In-depth understanding of various IT platform and systems including but not limited to AWS, Okta, GitHub, and Atlassian products.
- Ability to partner with technical stakeholders to discover, analyze, and document comprehensive data flows, establishing a clear line of sight into how data moves across our infrastructure.
- Experience developing or maintaining technology policies, standards, procedures, and supporting governance committees / forums with related reporting.
- Hands-on experience executing and managing IT and security audits or regulatory assessments in a heavily regulated industry, including writing, documenting, and assessing risks/controls and drafting business process summaries for executives.
- "Stay Hungry, Stay Humble" mindset that strives to continuously learn and share new skills with others, and embraces a steep learning curve to understand our business and technology drivers to get the job done
- "Anything Is Possible" attitude that is highly organized and results-driven to solve our most important challenges
- Comfortable navigating shifting priorities in a fast-paced environment, with the ability to work independently with minimal supervision while also as an exceptional team player that excels at cultivating relationships and promoting collaboration and cohesiveness to fulfill our "We Are One Team" principle
- Strong IT & security risk domain knowledge of technology and cybersecurity best practices, principles, tools, and industry control frameworks (e.g., GLI-33b, GLI-19, NIST 800-53, NIST CSF, SOX, SOC2, PCI)
- Knowledge of qualitative and quantitative risk management methodologies (e.g., NIST RMF / 800-37 / 800-30, FAIR)
- Ability to translate risk/control standards into functional business requirements
- Strong written and verbal communication skills to articulate GRC insights to both technical and non-technical stakeholders
- Proficient working with Microsoft Office, GRC and project management tools (e.g., Optro, Anecdotes, Jira, Sharepoint)
- Experience working as a consultant in the risk, compliance, or audit space is a plus
- Relevant professional certifications such as CISA, CISM, CISSP, CRISC, CGEIT, CCSK/CCSP, PCI ISA/QSA, Security+ are preferred
ABOUT FANDUEL
FanDuel Group is the premier mobile gaming company in the United States and Canada. FanDuel Group consists of a portfolio of leading brands across mobile wagering including: America's #1 Sportsbook, FanDuel Sportsbook; its leading iGaming platform, FanDuel Casino; the industry's unquestioned leader in horse racing and advance-deposit wagering, FanDuel Racing; and its daily fantasy sports product.
In addition, FanDuel Group operates FanDuel TV, its broadly distributed linear cable television network and FanDuel TV+, its leading direct-to-consumer OTT platform. FanDuel Group has a presence across all 50 states, Canada, and Puerto Rico.
The company is based in New York with US offices in Los Angeles, Atlanta, and Jersey City, as well as global offices in Canada and Scotland. The company's affiliates have offices worldwide, including in Ireland, Portugal, Romania, and Australia.
FanDuel Group is a subsidiary of Flutter Entertainment, the world's largest sports betting and gaming operator with a portfolio of globally recognized brands and traded on the New York Stock Exchange (NYSE: FLUT).
PLAYER BENEFITS
We treat our team right
We offer amazing benefits above and beyond the basics. We have an array of health plans to choose from (some as low as $0 per paycheck) that include programs for fertility and family planning, mental health support, and fitness benefits. We offer generous paid time off (PTO & sick leave), annual bonus and long-term incentive opportunities (based on performance), 401k with up to a 5% match, commuter benefits, pet insurance, and more - check out all our benefits here: FanDuel Total Rewards. Benefits differ across location, role, and level.
FanDuel is an equal opportunities employer and we believe, as one of our principles states, "We are One Team!". As such, we are committed to equal employment opportunity regardless of race, color, ethnicity, ancestry, religion, creed, sex, national origin, sexual orientation, age, citizenship status, marital status, disability, gender identity, gender expression, veteran status, or any other characteristic protected by state, local or federal law. We believe FanDuel is strongest and best able to compete if all employees feel valued, respected, and included.
FanDuel is committed to providing reasonable accommodations for qualified individuals with disabilities. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please email Benefits@fanduel.com.
The applicable salary range for this position is $138,000 - $173,000 USD, which is dependent on a variety of factors including relevant experience, location, business needs and market demand. This role may offer the following benefits: medical, vision, and dental insurance; life insurance; disability insurance; a 401(k) matching program; among other employee benefits. This role may also be eligible for short-term or long-term incentive compensation, including, but not limited to, cash bonuses and stock program participation. This role includes paid personal time off and 14 paid company holidays. FanDuel offers paid sick time in accordance with all applicable state and federal laws.
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
LI-Hybrid
See all E-3 Visa Governance Risk And Compliance Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new E-3 Visa Governance Risk And Compliance Jobs.
Get Access To All JobsTips for Finding E-3 Visa Sponsorship in Governance Risk And Compliance
Align your credentials to specialty occupation
GRC roles require a direct connection between your degree and the position. A finance or law degree maps cleanly to compliance analyst roles. If your degree is in a broader field, document how your coursework and credentials specifically support the GRC function you're being hired for.
Target regulated industries with dedicated compliance teams
Financial services, healthcare, and energy companies maintain large in-house GRC functions and file E-3 visas regularly. Focus your search on employers in these sectors who have existing compliance departments, since they understand the LCA and sponsorship process better than general employers.
Search for E-3 sponsorship roles on Migrate Mate
Migrate Mate filters GRC roles by E-3 visa sponsorship history, saving you from approaching employers unfamiliar with the visa. Use Migrate Mate's E-3 filing service to handle your LCA and visa paperwork once you receive an offer.
Address Australian credential equivalency early
U.S. employers often don't recognize Australian three-year bachelor's degrees as equivalent to U.S. four-year degrees. Request a credential evaluation from a NACES-approved evaluator before interviews so your qualifications are confirmed as meeting USCIS specialty occupation standards.
Confirm your offer letter specifies specialty occupation duties
The DOL requires the LCA to reflect a genuine specialty occupation position. Your offer letter should describe GRC duties that require at minimum a bachelor's degree in a specific field, not just general business experience. Vague job descriptions are a common reason LCA certification is challenged.
Start the LCA filing immediately after accepting an offer
The DOL typically certifies LCAs within seven business days, but your employer must post the LCA notice at the worksite for ten consecutive business days before filing. Build this into your start date timeline so you don't delay your consulate appointment.
E-3 Visa Governance Risk And Compliance: Frequently Asked Questions
How do I find Governance, Risk, and Compliance jobs that offer E-3 sponsorship?
Migrate Mate is built specifically for Australian professionals seeking E-3 sponsorship and lets you filter GRC roles by employers with sponsorship history. Because the E-3 requires employer action (an LCA filing with the DOL), targeting companies already familiar with the process significantly improves your chances of a smooth offer and filing experience.
How much does it cost to get an E-3 visa?
Migrate Mate's E-3 filing service covers the entire process for $499, including the Labor Condition Application, visa document preparation, and consulate appointment guidance. Traditional immigration lawyers charge $2,000–$5,000+ for the same work. The E-3 has less paperwork than most work visas, so paying thousands for legal help is usually unnecessary.
Do GRC roles qualify as specialty occupations under the E-3 visa?
Yes, most GRC positions qualify when the role requires a bachelor's degree or higher in a specific field such as finance, law, accounting, or business administration. Roles like compliance analyst, risk manager, and governance officer consistently meet the USCIS specialty occupation definition, provided the employer's job description reflects that degree-level requirement.
How does the E-3 compare to the H-1B for Australian compliance professionals?
The E-3 is available exclusively to Australian citizens and has no lottery, unlike the H-1B visa which is subject to an annual cap and random selection. GRC professionals on the E-3 can start the process after receiving a job offer without waiting for a lottery result, and the visa renews in two-year increments indefinitely as long as employment continues.
Can I transfer my E-3 visa to a new GRC employer if I change jobs?
Yes, but the new employer must file a fresh LCA with the DOL and you'll need to obtain a new E-3 visa stamp at a U.S. consulate. There's no portability provision equivalent to H-1B AC21 protections, so plan for a gap between roles and avoid resigning from your current position until the new LCA is certified.