Talent.com
Information Security - Risk Analyst (SOC-2)
Information Security - Risk Analyst (SOC-2)PennyMac • Westlake Village, CA, United States
Information Security - Risk Analyst (SOC-2)

Information Security - Risk Analyst (SOC-2)

PennyMac • Westlake Village, CA, United States
14 days ago
Job type
  • Full-time
Job description

PENNYMAC

Pennymac (NYSE : PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integrated business focused on the production and servicing of U.S. mortgage loans and the management of investments related to the U.S. mortgage market.

At Pennymac, our people are the foundation of our success and at the heart of our dynamic work culture. Together, we work towards a unified goal of helping millions of Americans achieve aspirations of homeownership through the complete mortgage journey.

A Typical Day

We are seeking a highly motivated and experienced Technology Risk Analyst to join our IT Risk and Compliance team. In this critical role, you will be responsible for overseeing technology risk within our Cybersecurity domain area. As a key member of the 1st Line of Defense, you will play a pivotal role in developing and maintaining robust policies and procedures, ensuring the effectiveness of our control environment through quality assurance, and supporting our compliance initiatives spanning internal and regulatory audits and SOC2 examinations. This position requires a strong understanding of risk management principles, a keen eye for detail, and the ability to collaborate effectively across various teams.

The Technology Risk Analyst will :

  • Design and execute comprehensive QA controls testing against established policies and procedures, across the technology environment to validate the effectiveness of security controls and identify control deficiencies.
  • Act as a proactive member of the 1st Line of Defense, identifying, assessing, and monitoring technology risks associated with cybersecurity processes.
  • Lead and coordinate all regulatory examinations, investor questionnaires, and internal / external audits (including SOX / SOC compliance) for the Cybersecurity domain, acting as the primary liaison and ensuring comprehensive evidence submission
  • Perform technology vendor risk assessments and due diligence reviews to evaluate third-party security posture and adherence to organizational policies and regulatory standards.
  • Support and maintain the Cybersecurity Policy and Procedure framework, ensuring alignment with industry best practices, regulatory requirements (e.g., SOC 2, ISO 27001, NIST CSF), and organizational risk tolerance.
  • Manage the policy exception process, reviewing, analyzing, and documenting all requests for exceptions to security policies, ensuring appropriate compensating controls and risk acceptance are in place.
  • Develop and oversee Cyber Risk Assessments based on Pennymac's ERM framework.
  • Stay current with emerging technology risks, regulatory changes, and industry trends related to cybersecurity.

What You'll Bring

Required :

  • Deep understanding of cybersecurity risk management frameworks and standards (e.g., NIST CSF, ISO 27001, COBIT, CIS Controls).
  • Expertise in designing and performing IT / Cybersecurity controls testing and assurance activities, including control gap analysis and remediation planning.
  • Strong knowledge of relevant regulations and reporting standards (e.g., NYDFS, GLBA, NIST CSF, CRI Profile, GDPR, CCPA, SOC 2, various financial / sector-specific regulations).
  • Proven ability to manage regulatory / client audit processes, including evidence gathering, response coordination, and interaction with external parties.
  • Excellent analytical and critical thinking skills for evaluating complex technical controls, assessing vendor security, and determining appropriate risk mitigation strategies.
  • Exceptional written and verbal communication skills for drafting clear policies and procedures, communicating risk to non-technical stakeholders, and articulating complex risk concepts to both technical and non-technical audiences.
  • Experience supporting internal audits and SOX / SOC compliance initiatives.
  • Must be highly proficient in GSuite or Microsoft Excel, Word, and PowerPoint.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Must be a team player with strong attention to detail and able to work independently.
  • Ability to manage multiple priorities, and meet deadlines in a fast-paced environment.
  • Highly Desired :

  • Experience with Governance, Risk, and Compliance (GRC) programs and methodologies.
  • Experience using risk, issue and compliance management tools such as Jira, Confluence, AuditBoard, and ServiceNow.
  • Financial Services and, if possible, mortgage industry experience preferred.
  • Relevant professional certifications such as CRISC, CISM, CISSP, or CISA are highly desirable.
  • Education & Experience :

  • Bachelor's Degree from an accredited college or equivalent work experience.
  • 3+ years of relevant work experience in IT Risk and Compliance and / or Audit.
  • Why You Should Join

    As one of the top mortgage lenders in the country, Pennymac has helped over 4 million lifetime homeowners achieve and sustain their aspirations of home. Our vision is to be the most trusted partner for home. Together, 4,000 Pennymac team members across the country are guided by our core values : to be Accountable, Reliable and Ethical in all that we do. Pennymac is committed to conducting a business that makes positive contributions and promotes long-term sustainable growth and to fostering an equitable and inclusive environment, where all employees and customers feel valued, respected and supported.

    Benefits That Bring It Home : Whether you're looking for flexible benefits for today, setting up short-term goals for tomorrow, or planning for long-term success and retirement, Pennymac's benefits have you covered. Some key benefits include :

  • Comprehensive Medical, Dental, and Vision
  • Paid Time Off Programs including vacation, holidays, illness, and parental leave
  • Wellness Programs, Employee Recognition Programs, and onsite gyms and cafe style dining (select locations)
  • Retirement benefits, life insurance, 401k match, and tuition reimbursement
  • Philanthropy Programs including matching gifts, volunteer grants, charitable grants and corporate sponsorships
  • To learn more about our benefits visit :

    For residents with state required benefit information, additional information can be found at :

    Compensation : Individual salary may vary based on multiple factors including specific role, geographic location / market data, and skills and experience as defined below :

  • Lower in range - Building skills and experience in the role
  • Mid-range - Experience and skills align with proficiency in the role
  • Higher in range - Experience and skills add value above typical requirements of the role
  • Some roles may be eligible for performance-based compensation and / or stock-based incentives awarded to employees based on company and individual performance.

    #TPO

    Salary

    $95,000 - $155,000

    Work Model

    REMOTE

    Create a job alert for this search

    Information Security Analyst • Westlake Village, CA, United States

    Related jobs
    Identity & Access Management (IAM) Engineer

    Identity & Access Management (IAM) Engineer

    Medtronic • Northridge, California, USA
    Full-time
    We anticipate the application window for this opening will close on - 5 Dec 2025.At Medtronic you can begin a life-long career of exploration and innovation while helping champion healthcare access...Show more
    Last updated: 8 days ago • Promoted
    Security Specialist Northridge CA

    Security Specialist Northridge CA

    Msccn • Northridge, California, USA
    Full-time
    ATTENTION MILITARY AFFILIATED JOB SEEKERS.Our organization works with partner companies to source qualified talent for their open roles. The following position is available to.Veterans Transitioning...Show more
    Last updated: 19 days ago • Promoted
    Research and Development Analyst III

    Research and Development Analyst III

    Logix Federal Credit Union • Valencia, CA, US
    Full-time
    Research & Development Analyst III.The Research & Development Analyst III conducts primary and secondary research, analysis, and reporting of the competitive landscape, credit union programs and se...Show more
    Last updated: 13 days ago • Promoted
    Sr. Director IT Security Engineering

    Sr. Director IT Security Engineering

    Zenith • Woodland Hills, CA, United States
    Full-time
    This role is eligible to participate in Zenith's hybrid work schedule which provides the flexibility to work from home on select days of the week according to the in-office schedule established by ...Show more
    Last updated: 4 days ago • Promoted
    Security Officer - Westlake Village Triunfo

    Security Officer - Westlake Village Triunfo

    University of California - Los Angeles Health • Westlake Village, CA, United States
    Full-time
    Serving at UCLA Health will give you the opportunity to use your specialized abilities to help improve the lives of our patients, their families, and your fellow UCLA Health team members.You'll pro...Show more
    Last updated: 30+ days ago • Promoted
    EPIC COGITO & RADAR Analyst (100% REMOTE / NO C2C) (Santa Clarita)

    EPIC COGITO & RADAR Analyst (100% REMOTE / NO C2C) (Santa Clarita)

    Amerit Consulting • Santa Clarita, CA, US
    Remote
    Part-time +1
    Our client, a Medical Center facility under the aegis of a California Public Ivy university and one of largest health delivery systems in California, seeks an accomplished.NOTE- THIS IS REMOTE ROLE...Show more
    Last updated: 7 days ago • Promoted
    Information Security Engineer

    Information Security Engineer

    Regal Medical Group • Northridge, CA, United States
    Full-time
    The Information Security Engineer will focus on protecting Regal Medical Group's digital infrastructure and act as a Security Incident Responder should a security event or incident occur.The ideal ...Show more
    Last updated: 12 days ago • Promoted
    Sr System Analyst

    Sr System Analyst

    E-Solutions • Westlake Village, CA, United States
    Full-time
    L2 - Sonata technical interview.Client is looking Senior System analyst with strong Mortgage or BFSI clients exp.Candidate should be technically proficient in skills such as.Bachelor's degree in co...Show more
    Last updated: 8 days ago • Promoted
    Information Security Analyst

    Information Security Analyst

    TradeJobsWorkForce • 91335 Los Angeles, CA, US
    Full-time
    Monitor their organization’s networks for security breaches and investigate a violation when one occurs Install and use software, such as firewalls and data encryption programs, to protect sensitiv...Show more
    Last updated: 30+ days ago • Promoted
    Project Specialist II

    Project Specialist II

    bostonscientific • Valencia, California, USA
    Temporary
    US-CA-Carlsbad; US-MN-Arden Hills; US-MN-Maple Grove.Diversity - Innovation - Caring - Global Collaboration - Winning Spirit- High Performance. At Boston Scientific well give you the opportunity to ...Show more
    Last updated: 7 days ago • Promoted
    Sr. Regional Security Manager (US, West)

    Sr. Regional Security Manager (US, West)

    Corebridge Financial • Woodland Hills, California, USA
    Full-time
    At Corebridge Financial we believe action is everything.Thats why every day we partner with financial professionals and institutions to make it possible for more people to take action in their fina...Show more
    Last updated: 13 days ago • Promoted
    Compliance Director - Diabetes

    Compliance Director - Diabetes

    Medtronic Plc • Northridge, CA, US
    Full-time
    At Medtronic you can begin a life-long career of exploration and innovation, while helping champion healthcare access and equity for all. You'll lead with purpose, breaking down barriers to innovati...Show more
    Last updated: 5 hours ago • Promoted • New!
    Systems Analysis & Integration, Sr Specialist

    Systems Analysis & Integration, Sr Specialist

    L3Harris • Canoga Park, CA, United States
    Full-time
    L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do.Our employees are unified in a shared dedication to our customers' mission and quest ...Show more
    Last updated: 18 days ago • Promoted
    IT Business Sys Analyst II

    IT Business Sys Analyst II

    Zenith • Woodland Hills, CA, United States
    Full-time
    The IT Business Systems Analyst must elicit, analyze and synthesize information to validate solutions that meet business needs, goals and objectives. The IT Business Systems Analyst is responsible f...Show more
    Last updated: 30+ days ago • Promoted
    Imports Systems and Data Analyst - Remote

    Imports Systems and Data Analyst - Remote

    Harbor Freight Tools • Calabasas, CA, United States
    Remote
    Full-time
    The Imports Systems and Data Analyst will provide strong operations templates, business modeling, trade analysis and management tools for optimal performance in key Import Department functions, dec...Show more
    Last updated: 14 days ago • Promoted
    Business System Analyst

    Business System Analyst

    Maintec Technologies • Santa Clarita, CA, United States
    Full-time
    Refer to Job Description Below.Support the migration of the HR system and its integration with the Beeline tool.Provide day-to-day support for the Beeline application. Conduct user acceptance testin...Show more
    Last updated: 16 days ago • Promoted
    Director of Technology and Digital Integration

    Director of Technology and Digital Integration

    Child Care Resource Center • Chatsworth, CA, United States
    Full-time
    CCRC prides itself as a workplace of choice for passionate talent, driven by our mission to cultivate child, family and community well-being. Whether the position works directly with the public or s...Show more
    Last updated: 30+ days ago • Promoted
    Sr Principal Program Cost and Schedule Control Analyst

    Sr Principal Program Cost and Schedule Control Analyst

    Northrop Grumman • Northridge, CA, US
    Full-time
    Principal Program Cost, Schedule, and Control Analyst.At Northrop Grumman, our employees have incredible opportunities to work on revolutionary systems that impact people's lives around the world t...Show more
    Last updated: 9 days ago • Promoted