Senior Information Security Analyst (Hybrid)
Santa Ana, California
Company SummaryJoin a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For® list for seven consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.
Responsible for performing self-assessments of IT controls and processes in support of management’s internal risk assessment process. Provides ongoing information, guidance and support to assists with continuous improvement and maturity of IT controls and processes. Works with personnel across all levels of the organization. In-depth knowledge of IT general controls, IT audit fundamentals and process analysis are required.
- Assist in the creation of an IT risk assessment, and develop self-assessment programs to evaluate areas of risk or concern based on regulatory, customer, internal and best practice requirements across the enterprise
- Perform ITCC self-assessments over IT controls and processes, analyze evidence, and provide recommendations to remediate findings and improve the control environment
- Advise management on the design and implementation of control activities that reduce risk, add value, and mature the control environment
- Assist in the development, maintenance and implementation of ITCC tools and processes to streamline and automate compliance and control activities
- Support the enterprise Information Security and IT compliance awareness, communication, and education programs
- Provide excellent customer service in support of program activities
- Develop and maintain an ongoing relationship with control owners and key stakeholders including Information Security, IT, business lines, Internal Audit, and external third parties
- Assist with the maintenance and update of ITCC program documents
- Maintain an understanding of Company and IT objectives and risks
- Assist with other Information Security and ITCC initiatives as needed
- Perform ongoing education and training in Information Security related areas
- Provide subject matter expertise related to IT General Controls and Information Security policies and standards
- Required to perform duties outside of normal work hours based on business needs.
Knowledge and Skills/Technology Used
- In-depth knowledge of IT and Information Security control standards and frameworks (COBIT, ISO27001, SSAE16/SOC1/SOC2, etc.)
- Familiarity with governance, risk, and compliance tools (Archer, etc.)
- In-depth knowledge of MS Excel
- Team player with positive energy and good customer service skills
- Ability to work independently, demonstrates initiative, and is a self-starter
- Ability to work effectively with all levels of the organization
- Bachelor’s Degree or equivalent experience
Typical Range of Experience
- Minimum 5 years relevant work experience in Information Security, IT Risk Management, IT Governance or IT Audit
- Effectively communicate IT compliance expectations to all levels of the organization including operational personnel executive management
- Gain support and consensus with multiple stakeholders and partners (internal and external)
- Manage multiple initiatives simultaneously, with strong ability to prioritize
- Respond appropriately to potential audit findings including vetting and assessment of risk
- Customer focused in the context of balancing risk reduction with business needs
- High attention to detail to manage, analyze and finalize artifacts and documents
- Highly developed oral and written communication skills; strong presentation skills
- Highly flexible, adapting to changes in priorities and requirements
- Development and maintenance program-related documentation (e.g., standard operating procedures)
- Ability to quickly learn, communicate and apply technical concepts
License or Certification
- Relevant, industry recognized security certification such as CISSP, CISA, CISM
Pay Range: $78,650 – $145,200 annually
This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on a number of factors which may include job-related knowledge, skills, experience, business requirements and geographic location.
#TCORPITFirst American invests in its employees' development and well-being, empowers them to provide superior customer service and encourages them to serve the communities where they live and work. First American is committed to diversity and inclusion. We are an equal opportunity employer.Based on eligibility, First American offers a comprehensive benefits package including medical, dental, vision, 401k, PTO/paid sick leave and other great benefits like an employee stock purchase plan.
No jobs have been viewed recently.
The REconomy Podcast
First American’s economic podcast examining the forces that influence real estate, housing and affordability, featuring First American Chief Economist Mark Fleming, Ph.D. and Deputy Chief Economist Odeta Kushi.Learn More
Fortune 100 List for 7 Straight Years
Proud to be ranked number 50 out of Fortune 100 2022 list.Learn More
Great Place To Work
We Are Proud to be a Great Place to Work Certified Company for 7 years straight.Learn More