What You'll Do:
- Acting as the top technical manager for the people, processes, and technology related to First American’s Security Operations Center (SOC). Responsible for developing and maturing processes to proactively monitor, detect, and respond to security threats, including the ongoing refinement and enhancements of security controls and configurations for security monitoring systems.
- Maintains ownership of the Security Operations Center service delivery including the SOC operating model, services, 24/7 coverage, severity criteria, escalation paths, quality assurance, staffing, budget requests, vendors, roadmap, and outcomes.
- Oversee the monitoring of information security systems, alerts and indicators of compromise used to protect the enterprise from attacks and identify compromised systems.
- Leads incident response actions as Incident Commander, with incident-declaration authority, to protect the company and address cyber threats while ensuring proper adherence to policies and procedures.
- Accountable and responsible for determining scope, severity, urgency, and business impact; setting containment and recovery priorities; maintaining decision logs; coordinating business and technical workstreams; and providing executive updates.
- Organizes and, where necessary, participates in an on-call rotation to ensure 24/7 monitoring and incident response.
- Provides leadership by instructing, mentoring, and training team members as they learn processes, develop their skills, and grow their knowledge.
- Works proactively to identify, develop, and implement incident response processes and procedures to mitigate security risks including enhancing the incident response plan and associated incident response playbooks.
- Manages relationships with Security Services Providers to monitor, detect, and respond to security incidents and is accountable for service definitions, SLAs, KPIs, analyst quality, escalation, privileged access, data handling, incident-notification obligations, exercise participation, and corrective actions.
- Leads efforts to tune threat detection logic and prioritize alerts to ensure security related events are properly identified.
- Leads and manages the execution of activities in the areas of incident response, risk identification, analysis, classification, and mitigation strategies.
- Leads and/or participates in capacity planning, role expectations, hiring, training plans, readiness assessments, career paths, succession, retention, sustainable on-call design, and workload health.
- Creates reports; researches and analyzes data, report trends and vital information to senior management/business partner.
- Researches and stays abreast of emerging technologies, new vulnerabilities and exploits that may compromise internal systems.
- Tracks, analyzes, and reports security metrics and proposes counter measures to address security trends that are not in line with company’s desire risk profile.
- Develops and maintains a holistic view of Information Technology and business acumen to align pragmatic and forward-looking information security practices and architectural design to advance business goals.
- Contribute to the evaluation, testing and implementation of new security systems and processes.
- Assist internal and external auditing entities and disaster recovery activities as needed.
What You'll Bring:
- Must have hands-on working knowledge of security incident response tools such as SIEM, SOAR, EDR/XDR, Identity Threat Detection, and Network Threat Detection technologies.
- Experience leading a Security Operations Center (SOC) environment, analyzing alerts from various systems such as SIEM, Cloud Services, Email Security Gateways, Endpoint Security.
- Deep analytical skills and capabilities
- Proven leadership skills and is results focused
- Ability to organize, plan and carry out assignments with minimal supervision/direction.
- Experience in implementing Information Security technologies and/or processes
- Experience in product evaluations and analysis
- Excellent written and verbal communication skills up to and including executive leadership
- Excellent interpersonal, relationship-building and teamwork skills
- Generally, requires a BS Degree in Computer Science, Information Technology, Cybersecurity, or equivalent work experience
- 5+ years of consecutive hands-on experience working in a SOC environment, utilizing industry leading network security monitoring technologies, application, web, database and Security Event and Information Management (SIEM), IDS/IPS, endpoint, email security gateways and DLP technologies.
- GIAC, CEH, OSCP, CISSP, CISM preferred
This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on a number of factors which may include job-related knowledge, skills, experience, business requirements and geographic location.
** Note that the following statements only apply to candidates who will be working from an unincorporated area within Los Angeles County. **
First American will consider for employment all qualified applicants, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws (e.g., the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act).
First American intends to conduct a review of an applicant’s criminal history in connection with a conditional offer. First American reasonably believes that a criminal history may have a direct, adverse and negative relationship with the following material job duties for this position potentially resulting in the withdrawal of the conditional offer of employment: handling of confidential, proprietary or trade secret information belonging to First American or its customers, administrating or facilitating financial transactions, and the ability to meet customer-imposed criminal history requirements.
What We OfferBy choice, we don’t simply accept individuality – we embrace it, we support it, and we thrive on it! Our People First culture is inclusive for all employees - not just because it's the right thing to do, but because it's the key to our success. We are proud to foster an authentic and inclusive workplace For All. You are free and encouraged to bring your entire, unique self to work. First American is an equal opportunity employer in every sense of the term.Based on eligibility, First American offers a comprehensive benefits package including medical, dental, vision, 401k, PTO/paid sick leave and other great benefits like an employee stock purchase plan.Skills Required
- Hands-on experience with security incident response tools, including SIEM, SOAR, EDR/XDR, Identity Threat Detection, and Network Threat Detection technologies
- Experience leading a Security Operations Center environment
- Experience analyzing alerts from SIEM, cloud services, email security gateways, and endpoint security systems
- Experience implementing information security technologies and processes
- Experience in product evaluations and analysis
- Strong analytical, leadership, organizational, written communication, verbal communication, interpersonal, and teamwork skills
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or equivalent work experience
- At least 5 years of consecutive hands-on experience working in a SOC environment
- Experience with network security monitoring, application, web, database, SIEM, IDS/IPS, endpoint, email security gateway, and DLP technologies
- GIAC, CEH, OSCP, CISSP, or CISM certification
First American Title Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about First American Title and has not been reviewed or approved by First American Title.
-
Healthcare Strength — Health coverage includes medical, dental, vision, telehealth, and healthcare advocacy services, and is often described as a strong point. Low‑cost options in some cases help overall compensation feel more reasonable.
-
Retirement Support — A 401(k) savings plan with a company match is part of the package. This retirement support is highlighted as helping to offset base‑pay concerns in several roles.
-
Equity Value & Accessibility — An employee stock purchase plan is available and viewed favorably. Access to discounted equity contributes to the perceived competitiveness of total rewards.
First American Title Insights
What We Do
First American provides financial services through its Title Insurance and Services segment and its Specialty Insurance segment. The First American Family of Companies’ core business lines include title insurance and closing/settlement services; title plant management services; title and other real property records and images; valuation products and services; home warranty products; property and casualty insurance; and banking, trust, and investment advisory services. First American Title Insurance Company provides comprehensive title insurance protection and professional settlement services for homebuyers and sellers, real estate agents and brokers, mortgage lenders, commercial property professionals, homebuilders and developers, title agencies and legal professionals to facilitate real estate purchases, construction, refinances or equity loans. First American's thorough title searches, title clearance and title insurance policies help to produce clear property titles and enable the efficient transfer of real estate. As one of the largest title insurance companies in the nation, First American offers title insurance and settlement services through its direct operations and an extensive network of agents throughout the United States and internationally. First American Title Insurance Company traces its history to 1889 and is the largest subsidiary of First American Financial Corporation (NYSE: FAF).








