Senior IT Controls & Compliance Analyst (Hybrid)
Santa Ana, California
Who We AreJoin a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For® list for eight consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.
What We Do
Responsible for completing deliverables which support Audit workstreams for Lenders, Regulators, Cyber, SOX and SOC efforts. Provide support to management for SOX/SOC readiness assessments. Works with personnel across all levels of the organization. In-depth knowledge of IT general controls, IT audit fundamentals and process analysis are required.
This role is hybrid two days a week onsite in Santa Ana, CA.
What You'll Do:
- Assist in the creation of an IT risk assessment, and develop self-assessment programs to evaluate areas of risk or concern based on regulatory, customer, internal and best practice requirements across the enterprise
- Perform analysis of audit control gaps over processes and tools, analyze evidence, and provide recommendations to remediate findings and improve the control environment
- Advise management on the design and implementation of control activities that reduce risk, add value, and mature the control environment
- Assist in the development, maintenance and implementation of ITCC tools and processes to streamline and automate compliance and control activities
- Support the enterprise Information Security and IT compliance awareness, communication, and education programs
- Provide excellent customer service in support of program activities
- Develop and maintain an ongoing relationship with control owners and key stakeholders including Information Security, IT, business lines, Internal Audit, and external third parties
- Assist with the maintenance and update of ITCC program documents
- Maintain an understanding of Company and IT objectives and risks
- Assist with other Information Security and ITCC initiatives as needed
- Perform ongoing education and training in Information Security related areas
- Provide subject matter expertise related to IT General Controls and Information Security policies and standards
- Maintain data within system of record which tracks issues, engagements and metrics that gets communicated throughout the organization
- Required to perform duties outside of normal work hours based on business needs.
What You'll Bring:
- Bachelor’s Degree or equivalent experience
- Minimum 5 years relevant work experience in Information Security, IT Risk Management, IT Governance or IT Audit
- Effectively communicate IT compliance expectations to all levels of the organization including operational personnel executive management
- Gain support and consensus with multiple stakeholders and partners (internal and external)
- Manage multiple initiatives simultaneously, with strong ability to prioritize
- Respond appropriately to potential audit findings including vetting and assessment of risk
- Customer focused in the context of balancing risk reduction with business needs
- High attention to detail to manage, analyze and finalize artifacts and documents
- Highly developed oral and written communication skills; strong presentation skills
- Highly flexible, adapting to changes in priorities and requirements
- Development and maintenance program-related documentation (e.g., standard operating procedures)
- Ability to quickly learn, communicate and apply technical concepts
License or Certification
- Relevant, industry recognized security certification such as CISSP, CISA, CISM
Pay Range: $78,650 - $121,000 Annual
This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on a number of factors which may include job-related knowledge, skills, experience, business requirements and geographic location.