Information Security Compliance & Audit Manager

Orange County, CA
Santa Ana, California United States  View Map
Posted: May 01, 2026
  • Salary: $127,878.40 - $177,132.80 Annually USD
  • Full Time
  • Accounting and Finance
  • Information Technology and Communication Services
  • Regulatory and Licensing
  • Job Description

    CAREER DESCRIPTION

    Information Security Compliance & Audit Manager


    (Technology Services Manager)

    Salary may be negotiable within the applicable range of the classification and successful candidate's qualifications, subject to appropriate authorization.

    OPEN TO THE PUBLIC
    This recruitment will establish an open eligible list that will be used to fill current and future Technology Services Manager positions. The eligible list established may also be used to fill positions in similar and/or lower classifications throughout the County of Orange.

    DEADLINE TO APPLY
    This recruitment will be open for a minimum of five (5) business days and will close on
    Sunday May 17, 2026 at 11:59pm (PST).

    ORANGE COUNTY INFORMATION TECHNOLOGY
    The mission of Orange County Information Technology (OCIT) is to provide innovative, reliable, and secure technology solutions that support County departments in the delivery of quality public services. OCIT provides IT solutions across County departments for voice communications, network services, application support, service desk, desktop support, as well as data center services.

    Click here for more information on OCIT.
    Click here for more information on the County of Orange.

    THE OPPORTUNITY
    The Orange County Information Technology (OCIT) Countywide Services is seeking an experienced and dynamic manager who will provide audit support, vendor security risk assessment, and PCI (Payment Card Industry) compliance management. The Information Security Compliance & Audit Manager (Technology Services Manager) serves as the enterprise owner of OCIT's centralized audit coordination services and is the County's primary liaison for IT audits, security assessment, external auditors, vendors, and internal stakeholders. This position requires strong analytical and comprehension skills with written and communication experience.

    The Information Security Compliance & Audit Manager's duties and responsibilities include the following:
    • Working in a multidisciplinary IT environment, including IT teams and coordinating efforts to meet audit requirements.
    • Serving as the primary audit liaison and advocate between internal stakeholders and OCIT, fostering strong partnerships and ensuring effective communication across organizations.
    • Leading audit planning and execution, communications and escalation paths.
    • Providing guidance and recommendations to County departments with PCI audit scoping, executing recurring vulnerability site scans and evaluating new device purchases.
    • Explaining and presenting executive-level audit status reporting, trend analysis, and lessons learned to drive continuous improvement.
    • Coordinating cross-functional review involving OCIT Security, OCIT Functional Services Team (Server, Desktop, Cloud), OCIT Business Relationship Management Team, Privacy, Legal, Procurement departments
    • Ensuring all new technologies and service providers align with County Information security, privacy, and procurement requirements.
    • Facilitating the Countywide Security Review & Approval (SRA) process for new technologies, cloud services, SaaS platforms, and third-party vendors.
    • Conducting security and privacy evaluations of vendor solutions to meet County security compliance.
    • Leading the development of training materials and facilitating training sessions and workshops.
    • Maintaining a centralized vendor risk inventory within the GRC (Governance, Risk and Compliance) platform, Optro.
    • Utilizing project organization management including scheduling, milestones, deliverables to achieve successful outcomes.
    • Making policy and business decisions using sound judgement and risk management.
    • Traveling throughout Orange County and attending staff meetings as needed, along with performing related duties as assigned.
    DESIRABLE QUALIFICATIONS AND CORE COMPETENCIES
    In addition to the minimum qualifications, the ideal candidate will possess at least three (3) years of work experience performing audit support, IT audits, IT compliance, PCI DSS (Payment Card Industry Data Security Standard), or a combination of the above.

    A certification in one of the following is preferred but not required:
    • CISA: Certified Information System Auditor
    • CISSP: Certified Information Systems Security Professional
    • CRISC: Certified in Risk and Information Systems Control
    • PCI ISA: Internal Security Assessor or equivalent
    The ideal candidate will have experience in the following competencies:

    Technical Knowledge | Technical Experience
    • Analyzing, administering, and maintaining information security architecture, information security technologies, tools, appliances, practices and controls
    • Understanding Information Technology and applying advanced methodologies, principles, and concepts to coordinate major projects
    • Understanding of audit coordination, audit readiness, and audit remediation management
    • Understanding of PCI (Payment Card Industry Data Security Standard) 4.0.1 requirements, assessment methodologies, and validation processes
    • Utilizing risk management and internal control frameworks applicable to public-sector and regulated environments
    • Utilizing technical project management methodology
    • Evaluating and monitoring Information Security Risk strategies to maintain efficiency, accuracy, and compliance
    • Utilizing GRC (Governance, Risk and Compliance) and service management platforms (i.e. Optro, ServiceNow), evidence repositories (i.e. SharePoint), and security tooling outputs (i.e. vulnerability management, SIEM)
    • Understanding payment technologies, cardholder data environments, and secure system architectures
    • Working knowledge and familiarity with HIPAA (Health Insurance Portability and Accountability Act), PCI DSS (Payment Card Industry Data Security Standard), CJIS Security Policy (Criminal Justice Information Services), NIST Cybersecurity Framework & NIST SP-800 Series
    Leadership Skills
    • Acting as a department liaison for Information Security Risk management best practices and security awareness
    • Working collaboratively and establishing rapport with staff, managers, and people across County departments
    • Acting as the department liaison and providing accurate information related to IT audits, IT security compliance, operations, and programs
    • Leading training sessions and workshops to non-IT business users
    • Building and maintaining positive forward focused customer-oriented work environments

    Oral | Written Communication Skills
    • Preparing and orally presenting program training and support information to various groups
    • Communicating, coordinating, and collaborating with County agencies to ensure effective service delivery
    • Translating and developing technical findings into clear, actionable reports and documentation for non-technical stakeholders
    LICENSE REQUIREMENT
    Possession of a California Class C Driver License is Required.

    MINIMUM QUALIFICATIONS
    Please click here for details on this classification, including the physical, mental, environmental and working conditions.

    SPECIAL REQUIREMENT | BACKGROUND INVESTIGATION
    Part of the selection process for positions within Orange County Information Technology (OCIT) requires that all candidates undergo an extensive background investigation process, to the satisfaction of the Department. Candidates must successfully clear prior to the start of their employment. All employment offers are contingent upon successful completion of a background investigation.

    RECRUITMENT PROCESS
    Human Resource Services (HRS) will screen all application materials to identify qualified applicants. After screening, qualified applicants will be referred to the next step and notified of all further procedures applicable to their status in the competition.

    Application Screening (Refer/Non-Refer)
    Applications and supplemental responses will be screened for qualifications that are highly desirable and most needed to successfully perform the duties of this job. Only those applicants that meet the qualifications as listed in the job bulletin will be referred to the next step.

    Structured Oral Interview | SOI (Weighted 100%)
    Applicants will be interviewed and rated by an oral interview panel of job knowledge experts. Each applicant's rating will be based on responses to a series of structured questions designed to elicit the applicant's qualifications for the job. Only the most successful candidates will be placed on the eligible list.

    Eligible List
    Once the assessment has been completed, HRS will establish an eligible list of candidates. Candidates placed on the eligible list may be referred to a selection interview to be considered for present and future vacancies.

    Based on the Department's needs, the selection procedure listed above may be modified. All candidates will be notified of any changes in the selection procedure.

    Veterans Employment Preference
    The County is committed to providing a mechanism to give preferential consideration in the employment process to veterans and their eligible spouses and will provide eligible participants the opportunity to receive interviews in the selection process for employment and paid internship openings. Please click here to review the policy.

    ADDITIONAL INFORMATION

    EMAIL NOTIFICATION
    Email is the primary form of notification during the recruitment process. Please ensure your correct email address is included in our application and use only one email account.

    NOTE: User accounts are established for one person only and should not be shared with another person. Multiple applications with multiple users may jeopardize your status in the recruitment process for any positions for which you apply.

    Candidates will be notified regarding their status as the recruitment proceeds via email through the GovernmentJobs.com site. Please check your email folders, including spam/junk folders, and/or accept emails ending with "governmentjobs.com" and "ocgov.com." If your email address should change, please update your profile at www.governmentjobs.com.

    FREQUENTLY ASKED QUESTIONS

    Click here for additional Frequently Asked Questions.

    For specific information pertaining to this recruitment, contact Joanna Xue at joanna.xue@ceo.oc.gov or (714)-834-7338.

    EEO INFORMATION

    Orange County, as an equal employment opportunity employer,
    encourages applicants from diverse backgrounds to apply.


    Administrative Management *
    In addition to the County's standard suite of benefits -- such as a variety of health plan options, sick and vacation time and paid holidays -- we also offer an excellent array of benefits such as:
    • Retirement: Benefits are provided through the Orange County Employees' Retirement System (OCERS). Please go to the following link to find out more about Defined Benefit Pensions and OCERS Plan Types/Benefits.
      http://www.ocers.org/active-member-information.
    • Paid Leave: Twelve holidays per year plus sick and vacation time
    • Health & Dependent Care Reimbursement Accounts
    • Dental Insurance: County pays 100% of employee and dependent premiums
    • Paid Life Insurance: $100,000 life insurance policy
    • Paid Accidental & Death and Dismemberment Insurance: $100,000 AD&D insurance policy
    • Paid Short & Long Term Disability insurance programs
    • 457 Defined Contribution Program


    *Effective 07/01/20, management employees who are sworn Public Safety Managers receive health insurance benefits through the AOCDS Medical Benefit Plans.

    Click here for information about benefits offered to County of Orange employees.

    Closing Date/Time: 5/17/2026 11:59 PM Pacific
  • ABOUT THE COMPANY

    • County of Orange
    • County of Orange

    Discover a Fulfilling Career at the County of Orange

    With a population of over 3 million residents and 34 cities, Orange County is a thriving community known for its beautiful beaches, diverse culture, and strong economy. As the third-largest employer in the county, the County of Orange offers over 18,000 employees the opportunity to make a difference in their community and build a fulfilling career in public service.

    As a County of Orange employee, you will have the chance to work in a variety of departments, each providing vital services to our community. From law enforcement and healthcare to public works and environmental protection, there is a wide range of career paths to explore. And with opportunities for advancement and professional growth, you can build a long and rewarding career with us.

    As a top employer in the region, the County of Orange is committed to providing our employees with excellent benefits, including a competitive salary, flexible work schedules, and outstanding healthcare coverage. We also offer opportunities for career development and training, ensuring that our employees have the skills and knowledge they need to succeed.

    Whether you're just starting your career or looking for a new challenge, the County of Orange is a great place to work. With a supportive and collaborative work environment, a commitment to excellence, and opportunities for growth and advancement, we invite you to join our team and make a difference in your community.

     

    Community Impact:

    Working for the County of Orange means you will have the opportunity to make a meaningful impact in your community. Whether you're providing critical services to residents, protecting the environment, or maintaining public safety, your work will make a difference in the lives of those around you.

    Employee Wellness:

    At the County of Orange, we prioritize our employees' well-being. We offer telecommuting options, generous health benefits, and wellness programs to promote work-life balance. We believe that by taking care of our employee’s health and well-being, we can help them excel in their careers while still enjoying their personal lives and taking care of their families.

    Innovation:

    The County of Orange is committed to embracing new technologies and innovative approaches to service delivery. We encourage our employees to think creatively and find ways to improve our processes and systems. If you're someone who loves to problem-solve and think outside the box, you'll find a supportive and dynamic environment here.

    Collaboration:

    Collaboration is key to our success at the County of Orange. We value teamwork, communication, and mutual support, and we work together across departments and functions to achieve our goals. If you're someone who enjoys collaborating with others and building strong relationships, you'll find a welcoming and inclusive community here.

    Equality:

    At the County of Orange, we are committed to creating a diverse and inclusive workplace where all employees feel valued and respected. Our Equity Policy reflects this commitment and guides our efforts to promote equity, diversity, and inclusion in everything we do.

    Career Advancement:

    The County of Orange is dedicated to helping our employees grow and advance in their careers. We offer a variety of training and development opportunities to help our employees reach their full potential. If you're looking for a place to build a long and fulfilling career, the County of Orange is an excellent choice.

     

    Show more

MORE JOBS

  • Men's Water Polo Assistant Coach

    • San Jose, California
    • Cal State University (CSU) San Jose
    • Mar 13, 2026
    • Accounting and Finance
    • Parks and Recreation
    • Water and Wastewater Treatment
  • PRINCIPAL INFORMATION SYSTEMS ANALYST / EMERGENCY APPOINTMENTS HOMELESSNESS

    • Los Angeles, California
    • LOS ANGELES COUNTY
    • Apr 05, 2026
    • Temporary
    • Administrative Analysis and Research
    • Emergency Management
    • Information Technology and Communication Services
    • Planning and Development
  • Water Quality and Environmental Compliance Specialist

    • Riverside, California
    • County of Riverside
    • Sep 20, 2025
    • Full Time
    • Water and Wastewater Treatment
  • IT Professional

    • Afton, Minnesota
    • U.S. Navy
    • May 01, 2026
    • Full Time
    • Information Technology and Communication Services
  • Senior Regulatory, Compliance & Policy Manager (Senior Power Resources Specialist) - Energy Dept.

    • San Jose, California
    • CITY OF SAN JOSE
    • Apr 01, 2026
    • Full Time
    • Administration and Management
    • Regulatory and Licensing
  • ASSOCIATE AGRICULTURAL/WEIGHTS AND MEASURES INSPECTOR

    • Los Angeles, California
    • LOS ANGELES COUNTY
    • Jun 10, 2025
    • Temporary
    • Agriculture / Farm / Ranch Related
Show More
Apply Now Please mention you found this employment opportunity on the CareersInGovernment.com Job Board.
Please mention you found this employment opportunity on the CareersInGovernment.com Job Board.