Who We Are
Join a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For® list for eleven consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.What We Do
The Information Security Operations Manager will manage the day-to-day services and/or delivery related to the First American Information Security Operations programs.What You'll Do:
- Acting as the top technical manager for the people, processes, and technology related to First American’s Security Operations Center (SOC). Responsible for developing and maturing processes to proactively monitor, detect, and respond to security threats, including the ongoing refinement and enhancements of security controls and configurations for security monitoring systems.
- Maintains ownership of the Security Operations Center service delivery including the SOC operating model, services, 24/7 coverage, severity criteria, escalation paths, quality assurance, staffing, budget requests, vendors, roadmap, and outcomes.
- Oversee the monitoring of information security systems, alerts and indicators of compromise used to protect the enterprise from attacks and identify compromised systems.
- Leads incident response actions as Incident Commander, with incident-declaration authority, to protect the company and address cyber threats while ensuring proper adherence to policies and procedures.
- Accountable and responsible for determining scope, severity, urgency, and business impact; setting containment and recovery priorities; maintaining decision logs; coordinating business and technical workstreams; and providing executive updates.
- Organizes and, where necessary, participates in an on-call rotation to ensure 24/7 monitoring and incident response.
- Provides leadership by instructing, mentoring, and training team members as they learn processes, develop their skills, and grow their knowledge.
- Works proactively to identify, develop, and implement incident response processes and procedures to mitigate security risks including enhancing the incident response plan and associated incident response playbooks.
- Manages relationships with Security Services Providers to monitor, detect, and respond to security incidents and is accountable for service definitions, SLAs, KPIs, analyst quality, escalation, privileged access, data handling, incident-notification obligations, exercise participation, and corrective actions.
- Leads efforts to tune threat detection logic and prioritize alerts to ensure security related events are properly identified.
- Leads and manages the execution of activities in the areas of incident response, risk identification, analysis, classification, and mitigation strategies.
- Leads and/or participates in capacity planning, role expectations, hiring, training plans, readiness assessments, career paths, succession, retention, sustainable on-call design, and workload health.
- Creates reports; researches and analyzes data, report trends and vital information to senior management/business partner.
- Researches and stays abreast of emerging technologies, new vulnerabilities and exploits that may compromise internal systems.
- Tracks, analyzes, and reports security metrics and proposes counter measures to address security trends that are not in line with company’s desire risk profile.
- Develops and maintains a holistic view of Information Technology and business acumen to align pragmatic and forward-looking information security practices and architectural design to advance business goals.
- Contribute to the evaluation, testing and implementation of new security systems and processes.
- Assist internal and external auditing entities and disaster recovery activities as needed.
What You'll Bring:
- Must have hands-on working knowledge of security incident response tools such as SIEM, SOAR, EDR/XDR, Identity Threat Detection, and Network Threat Detection technologies.
- Experience leading a Security Operations Center (SOC) environment, analyzing alerts from various systems such as SIEM, Cloud Services, Email Security Gateways, Endpoint Security.
- Deep analytical skills and capabilities
- Proven leadership skills and is results focused
- Ability to organize, plan and carry out assignments with minimal supervision/direction.
- Experience in implementing Information Security technologies and/or processes
- Experience in product evaluations and analysis
- Excellent written and verbal communication skills up to and including executive leadership
- Excellent interpersonal, relationship-building and teamwork skills
- Generally, requires a BS Degree in Computer Science, Information Technology, Cybersecurity, or equivalent work experience
- 5+ years of consecutive hands-on experience working in a SOC environment, utilizing industry leading network security monitoring technologies, application, web, database and Security Event and Information Management (SIEM), IDS/IPS, endpoint, email security gateways and DLP technologies.
- GIAC, CEH, OSCP, CISSP, CISM preferred
** Note that the following statements only apply to candidates who will be working from an unincorporated area within Los Angeles County. **
First American will consider for employment all qualified applicants, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws (e.g., the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act).
First American intends to conduct a review of an applicant’s criminal history in connection with a conditional offer. First American reasonably believes that a criminal history may have a direct, adverse and negative relationship with the following material job duties for this position potentially resulting in the withdrawal of the conditional offer of employment: handling of confidential, proprietary or trade secret information belonging to First American or its customers, administrating or facilitating financial transactions, and the ability to meet customer-imposed criminal history requirements.

