Information Security Operations Manager

First AmericanSanta Ana, CA

About The Position

The Information Security Operations Manager will manage the day-to-day services and/or delivery related to the First American Information Security Operations programs.

Requirements

  • Must have hands-on working knowledge of security incident response tools such as SIEM, SOAR, EDR/XDR, Identity Threat Detection, and Network Threat Detection technologies.
  • Experience leading a Security Operations Center (SOC) environment, analyzing alerts from various systems such as SIEM, Cloud Services, Email Security Gateways, Endpoint Security.
  • Deep analytical skills and capabilities
  • Proven leadership skills and is results focused
  • Ability to organize, plan and carry out assignments with minimal supervision/direction.
  • Experience in implementing Information Security technologies and/or processes
  • Experience in product evaluations and analysis
  • Excellent written and verbal communication skills up to and including executive leadership
  • Excellent interpersonal, relationship-building and teamwork skills
  • Generally, requires a BS Degree in Computer Science, Information Technology, Cybersecurity, or equivalent work experience
  • 5+ years of consecutive hands-on experience working in a SOC environment, utilizing industry leading network security monitoring technologies, application, web, database and Security Event and Information Management (SIEM), IDS/IPS, endpoint, email security gateways and DLP technologies.

Nice To Haves

  • GIAC, CEH, OSCP, CISSP, CISM preferred

Responsibilities

  • Acting as the top technical manager for the people, processes, and technology related to First American’s Security Operations Center (SOC).
  • Responsible for developing and maturing processes to proactively monitor, detect, and respond to security threats, including the ongoing refinement and enhancements of security controls and configurations for security monitoring systems.
  • Maintains ownership of the Security Operations Center service delivery including the SOC operating model, services, 24/7 coverage, severity criteria, escalation paths, quality assurance, staffing, budget requests, vendors, roadmap, and outcomes.
  • Oversee the monitoring of information security systems, alerts and indicators of compromise used to protect the enterprise from attacks and identify compromised systems.
  • Leads incident response actions as Incident Commander, with incident-declaration authority, to protect the company and address cyber threats while ensuring proper adherence to policies and procedures.
  • Accountable and responsible for determining scope, severity, urgency, and business impact; setting containment and recovery priorities; maintaining decision logs; coordinating business and technical workstreams; and providing executive updates.
  • Organizes and, where necessary, participates in an on-call rotation to ensure 24/7 monitoring and incident response.
  • Provides leadership by instructing, mentoring, and training team members as they learn processes, develop their skills, and grow their knowledge.
  • Works proactively to identify, develop, and implement incident response processes and procedures to mitigate security risks including enhancing the incident response plan and associated incident response playbooks.
  • Manages relationships with Security Services Providers to monitor, detect, and respond to security incidents and is accountable for service definitions, SLAs, KPIs, analyst quality, escalation, privileged access, data handling, incident-notification obligations, exercise participation, and corrective actions.
  • Leads efforts to tune threat detection logic and prioritize alerts to ensure security related events are properly identified.
  • Leads and manages the execution of activities in the areas of incident response, risk identification, analysis, classification, and mitigation strategies.
  • Leads and/or participates in capacity planning, role expectations, hiring, training plans, readiness assessments, career paths, succession, retention, sustainable on-call design, and workload health.
  • Creates reports; researches and analyzes data, report trends and vital information to senior management/business partner.
  • Researches and stays abreast of emerging technologies, new vulnerabilities and exploits that may compromise internal systems.
  • Tracks, analyzes, and reports security metrics and proposes counter measures to address security trends that are not in line with company’s desire risk profile.
  • Develops and maintains a holistic view of Information Technology and business acumen to align pragmatic and forward-looking information security practices and architectural design to advance business goals.
  • Contribute to the evaluation, testing and implementation of new security systems and processes.
  • Assist internal and external auditing entities and disaster recovery activities as needed.

Benefits

  • medical
  • dental
  • vision
  • 401k
  • PTO/paid sick leave
  • employee stock purchase plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service