428,564open jobs
14,652companies
61,154added this week
Browse all
Salary
$129k – $172k per year
Location
In office (Santa Ana)
Seniority
Senior · 5+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
First American Financial Corporation is a premier provider of title, settlement and risk solutions for real estate transactions. With its combination of financial strength and stability built over more than 130 years, innovative proprietary technologies, and unmatched data assets, the company is leading the digital transformation of its industry. First American also provides data products to the title industry and other third parties; valuation products and services; mortgage subservicing; home warranty products; banking, trust and wealth management services; and other related products and services.

Who We Are

Join a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For® list for eleven consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.

What We Do

The Information Security Operations Manager will manage the day-to-day services and/or delivery related to the First American Information Security Operations programs.

What You'll Do:

  • Acting as the top technical manager for the people, processes, and technology related to First American’s Security Operations Center (SOC). Responsible for developing and maturing processes to proactively monitor, detect, and respond to security threats, including the ongoing refinement and enhancements of security controls and configurations for security monitoring systems.
  • Maintains ownership of the Security Operations Center service delivery including the SOC operating model, services, 24/7 coverage, severity criteria, escalation paths, quality assurance, staffing, budget requests, vendors, roadmap, and outcomes.
  • Oversee the monitoring of information security systems, alerts and indicators of compromise used to protect the enterprise from attacks and identify compromised systems.
  • Leads incident response actions as Incident Commander, with incident-declaration authority, to protect the company and address cyber threats while ensuring proper adherence to policies and procedures.
  • Accountable and responsible for determining scope, severity, urgency, and business impact; setting containment and recovery priorities; maintaining decision logs; coordinating business and technical workstreams; and providing executive updates.
  • Organizes and, where necessary, participates in an on-call rotation to ensure 24/7 monitoring and incident response.
  • Provides leadership by instructing, mentoring, and training team members as they learn processes, develop their skills, and grow their knowledge.
  • Works proactively to identify, develop, and implement incident response processes and procedures to mitigate security risks including enhancing the incident response plan and associated incident response playbooks.
  • Manages relationships with Security Services Providers to monitor, detect, and respond to security incidents and is accountable for service definitions, SLAs, KPIs, analyst quality, escalation, privileged access, data handling, incident-notification obligations, exercise participation, and corrective actions.
  • Leads efforts to tune threat detection logic and prioritize alerts to ensure security related events are properly identified.
  • Leads and manages the execution of activities in the areas of incident response, risk identification, analysis, classification, and mitigation strategies.
  • Leads and/or participates in capacity planning, role expectations, hiring, training plans, readiness assessments, career paths, succession, retention, sustainable on-call design, and workload health.
  • Creates reports; researches and analyzes data, report trends and vital information to senior management/business partner.
  • Researches and stays abreast of emerging technologies, new vulnerabilities and exploits that may compromise internal systems.
  • Tracks, analyzes, and reports security metrics and proposes counter measures to address security trends that are not in line with company’s desire risk profile.
  • Develops and maintains a holistic view of Information Technology and business acumen to align pragmatic and forward-looking information security practices and architectural design to advance business goals.
  • Contribute to the evaluation, testing and implementation of new security systems and processes.
  • Assist internal and external auditing entities and disaster recovery activities as needed.

What You'll Bring:

  • Must have hands-on working knowledge of security incident response tools such as SIEM, SOAR, EDR/XDR, Identity Threat Detection, and Network Threat Detection technologies.
  • Experience leading a Security Operations Center (SOC) environment, analyzing alerts from various systems such as SIEM, Cloud Services, Email Security Gateways, Endpoint Security.
  • Deep analytical skills and capabilities
  • Proven leadership skills and is results focused
  • Ability to organize, plan and carry out assignments with minimal supervision/direction.
  • Experience in implementing Information Security technologies and/or processes
  • Experience in product evaluations and analysis
  • Excellent written and verbal communication skills up to and including executive leadership
  • Excellent interpersonal, relationship-building and teamwork skills
  • Generally, requires a BS Degree in Computer Science, Information Technology, Cybersecurity, or equivalent work experience
  • 5+ years of consecutive hands-on experience working in a SOC environment, utilizing industry leading network security monitoring technologies, application, web, database and Security Event and Information Management (SIEM), IDS/IPS, endpoint, email security gateways and DLP technologies.
  • GIAC, CEH, OSCP, CISSP, CISM preferred
Pay Range: $129,300.00 - $172,300.00 AnnuallyThis hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on a number of factors which may include job-related knowledge, skills, experience, business requirements and geographic location.

** Note that the following statements only apply to candidates who will be working from an unincorporated area within Los Angeles County. **

First American will consider for employment all qualified applicants, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws (e.g., the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act).

First American intends to conduct a review of an applicant’s criminal history in connection with a conditional offer. First American reasonably believes that a criminal history may have a direct, adverse and negative relationship with the following material job duties for this position potentially resulting in the withdrawal of the conditional offer of employment: handling of confidential, proprietary or trade secret information belonging to First American or its customers, administrating or facilitating financial transactions, and the ability to meet customer-imposed criminal history requirements.

What We Offer

By choice, we don’t simply accept individuality - we embrace it, we support it, and we thrive on it! Our People First culture is inclusive for all employees - not just because it's the right thing to do, but because it's the key to our success. We are proud to foster an authentic and inclusive workplace For All. You are free and encouraged to bring your entire, unique self to work. First American is an equal opportunity employer in every sense of the term.Based on eligibility, First American offers a comprehensive benefits package including medical, dental, vision, 401k, PTO/paid sick leave and other great benefits like an employee stock purchase plan.
Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
428,564 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Santa Ana
$101k – $205k per year (Estimated) • Equity • In office • Full-Time • 10+ years exp • Bachelor's Degree • Austin • Santa Clara
JavaScript
Node JS
Node JS
Commander.js
AI/ML
Copilot
ChatGPT
Cybersecurity
MITRE ATT&CK
Apply
$135k – $221k per year (Estimated) • Equity • Remote • Full-Time • 10+ years exp • Bachelor's Degree • United States
JavaScript
Node JS
Node JS
Commander.js
Apply
$176k – $264k per year • Equity • In office • Full-Time • 8+ years exp • Bachelor's Degree • San Francisco
Go
JavaScript
Rust
Kotlin
SQL
Node JS
Databases
MySQL
PostgreSQL
Redis
AI/ML
AI Agents
Perplexity
Frontend
GraphQL
DevOps
GCP
Azure
AWS
Kubernetes
Cybersecurity
Least Privilege
Apply
$8.5k – $15k per year (Estimated) • In office • Internship • Bachelor's Degree • Batu Kawan
Python
JavaScript
SQL
Databases
Oracle
Analytics
Power BI
ETL/ELT
Apply
$65k – $190k per year (Estimated) • In office • Internship • Bachelor's Degree • Chicago
JavaScript
TypeScript
Frontend
Angular
Cybersecurity
Least Privilege
Apply
$46k – $62k per year • Equity • Remote • Full-Time • 2+ years exp • High School Diploma • United States
Apply
$60k – $82k per year • Equity • Remote • Full-Time • 3+ years exp • High School Diploma • United States
Management
SharePoint
Apply
Title Examiner 2 days ago
$46k – $62k per year • Equity • Remote • Full-Time • 2+ years exp • High School Diploma • United States
Apply
$36k – $76k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 1+ year exp • High School Diploma • Madison
Apply
$112k – $150k per year • Equity • In office • Full-Time • 8+ years exp • High School Diploma • United States
Apply
$72k – $163k per year (Estimated) • Remote/Hybrid • 5+ years exp • Bachelor's Degree • Santa Ana
DevOps
SLI/SLO/SLA
Apply
$26k – $62k per year (Estimated) • In office • Full-Time • Santa Ana
Apply
$129k – $172k per year • Equity • Remote/Hybrid • Full-Time • 5+ years exp • Bachelor's Degree • Santa Ana
DevOps
GCP
Azure
AWS
Cybersecurity
ISO 27001
Zero Trust
Apply
$197k – $263k per year • Equity • Remote • Full-Time • 10+ years exp • Santa Ana
Apply
$37k – $66k per year (Estimated) • Equity • In office • Full-Time • 3+ years exp • Bachelor's Degree • Santa Ana
Apply
See all jobs
This is one of many
428,564 more open roles from verified company boards, updated every day.