Demo

Information Security - Risk Analyst (SOC-2)

PENNYMAC
Westlake Village, CA Full Time
POSTED ON 11/7/2025
AVAILABLE BEFORE 12/6/2025
PENNYMAC

Pennymac (NYSE: PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integrated business focused on the production and servicing of U.S. mortgage loans and the management of investments related to the U.S. mortgage market.

At Pennymac, our people are the foundation of our success and at the heart of our dynamic work culture. Together, we work towards a unified goal of helping millions of Americans achieve aspirations of homeownership through the complete mortgage journey.

A Typical Day

We are seeking a highly motivated and experienced Technology Risk Analyst to join our IT Risk and Compliance team. In this critical role, you will be responsible for overseeing technology risk within our Cybersecurity domain area. As a key member of the 1st Line of Defense, you will play a pivotal role in developing and maintaining robust policies and procedures, ensuring the effectiveness of our control environment through quality assurance, and supporting our compliance initiatives spanning internal and regulatory audits and SOC2 examinations. This position requires a strong understanding of risk management principles, a keen eye for detail, and the ability to collaborate effectively across various teams.

The Technology Risk Analyst Will

  • Design and execute comprehensive QA controls testing against established policies and procedures, across the technology environment to validate the effectiveness of security controls and identify control deficiencies.
  • Act as a proactive member of the 1st Line of Defense, identifying, assessing, and monitoring technology risks associated with cybersecurity processes.
  • Lead and coordinate all regulatory examinations, investor questionnaires, and internal/external audits (including SOX/SOC compliance) for the Cybersecurity domain, acting as the primary liaison and ensuring comprehensive evidence submission
  • Perform technology vendor risk assessments and due diligence reviews to evaluate third-party security posture and adherence to organizational policies and regulatory standards.
  • Support and maintain the Cybersecurity Policy and Procedure framework, ensuring alignment with industry best practices, regulatory requirements (e.g., SOC 2, ISO 27001, NIST CSF), and organizational risk tolerance.
  • Manage the policy exception process, reviewing, analyzing, and documenting all requests for exceptions to security policies, ensuring appropriate compensating controls and risk acceptance are in place.
  • Develop and oversee Cyber Risk Assessments based on Pennymac’s ERM framework.
  • Stay current with emerging technology risks, regulatory changes, and industry trends related to cybersecurity.

Required

What You’ll Bring

  • Deep understanding of cybersecurity risk management frameworks and standards (e.g., NIST CSF, ISO 27001, COBIT, CIS Controls).
  • Expertise in designing and performing IT/Cybersecurity controls testing and assurance activities, including control gap analysis and remediation planning.
  • Strong knowledge of relevant regulations and reporting standards (e.g., NYDFS, GLBA, NIST CSF, CRI Profile, GDPR, CCPA, SOC 2, various financial/sector-specific regulations).
  • Proven ability to manage regulatory/client audit processes, including evidence gathering, response coordination, and interaction with external parties.
  • Excellent analytical and critical thinking skills for evaluating complex technical controls, assessing vendor security, and determining appropriate risk mitigation strategies.
  • Exceptional written and verbal communication skills for drafting clear policies and procedures, communicating risk to non-technical stakeholders, and articulating complex risk concepts to both technical and non-technical audiences.
  • Experience supporting internal audits and SOX/SOC compliance initiatives.
  • Must be highly proficient in GSuite or Microsoft Excel, Word, and PowerPoint.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Must be a team player with strong attention to detail and able to work independently.
  • Ability to manage multiple priorities, and meet deadlines in a fast-paced environment.

Highly Desired

  • Experience with Governance, Risk, and Compliance (GRC) programs and methodologies.
  • Experience using risk, issue and compliance management tools such as Jira, Confluence, AuditBoard, and ServiceNow.
  • Financial Services and, if possible, mortgage industry experience preferred.
  • Relevant professional certifications such as CRISC, CISM, CISSP, or CISA are highly desirable.

Education & Experience

  • Bachelor’s Degree from an accredited college or equivalent work experience.
  • 3 years of relevant work experience in IT Risk and Compliance and/or Audit.

Why You Should Join

As one of the top mortgage lenders in the country, Pennymac has helped over 4 million lifetime homeowners achieve and sustain their aspirations of home. Our vision is to be the most trusted partner for home. Together, 4,000 Pennymac team members across the country are guided by our core values: to be Accountable, Reliable and Ethical in all that we do. Pennymac is committed to conducting a business that makes positive contributions and promotes long-term sustainable growth and to fostering an equitable and inclusive environment, where all employees and customers feel valued, respected and supported.

Benefits That Bring It Home: Whether you're looking for flexible benefits for today, setting up short-term goals for tomorrow, or planning for long-term success and retirement, Pennymac's benefits have you covered. Some key benefits include:

  • Comprehensive Medical, Dental, and Vision
  • Paid Time Off Programs including vacation, holidays, illness, and parental leave
  • Wellness Programs, Employee Recognition Programs, and onsite gyms and cafe style dining (select locations)
  • Retirement benefits, life insurance, 401k match, and tuition reimbursement
  • Philanthropy Programs including matching gifts, volunteer grants, charitable grants and corporate sponsorships

To learn more about our benefits visit: https://pennymacnews.page.link/benefits

For residents with state required benefit information, additional information can be found at: https://www.pennymac.com/additional-benefits-information

Compensation: Individual salary may vary based on multiple factors including specific role, geographic location / market data, and skills and experience as defined below:

  • Lower in range - Building skills and experience in the role
  • Mid-range - Experience and skills align with proficiency in the role
  • Higher in range - Experience and skills add value above typical requirements of the role

Some roles may be eligible for performance-based compensation and/or stock-based incentives awarded to employees based on company and individual performance.

Salary

$95,000 - $155,000

Work Model

REMOTE

Salary : $95,000 - $155,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Information Security - Risk Analyst (SOC-2)?

Sign up to receive alerts about other jobs on the Information Security - Risk Analyst (SOC-2) career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$58,470 - $77,272
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$99,138 - $133,641
Income Estimation: 
$75,905 - $103,047
Income Estimation: 
$74,367 - $98,680
Income Estimation: 
$74,367 - $98,680
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$99,138 - $133,641
Income Estimation: 
$94,973 - $125,755
Income Estimation: 
$96,228 - $129,772
Income Estimation: 
$96,228 - $129,772
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$121,926 - $164,179
Income Estimation: 
$124,413 - $154,875
Income Estimation: 
$87,128 - $112,557
Income Estimation: 
$161,616 - $208,121
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$105,243 - $143,011
Income Estimation: 
$101,446 - $138,837
Income Estimation: 
$87,128 - $112,557
Income Estimation: 
$58,470 - $77,272
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$99,138 - $133,641
Income Estimation: 
$75,905 - $103,047
Income Estimation: 
$74,367 - $98,680
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at PENNYMAC

PENNYMAC
Hired Organization Address Phoenix, AZ Full Time
PENNYMAC Pennymac (NYSE: PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integra...
PENNYMAC
Hired Organization Address Phoenix, AZ Full Time
PENNYMAC Pennymac (NYSE: PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integra...
PENNYMAC
Hired Organization Address Franklin, TN Full Time
PENNYMAC Pennymac (NYSE: PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integra...
PENNYMAC
Hired Organization Address St. Louis, MO Full Time
PENNYMAC Pennymac (NYSE: PFSI) is a specialty financial services firm with a comprehensive mortgage platform and integra...

Not the job you're looking for? Here are some other Information Security - Risk Analyst (SOC-2) jobs in the Westlake Village, CA area that may be a better fit.

Information Security Risk Officer

Pennymac, Westlake, CA

Information Security Risk Officer

Pennymac, Westlake, CA

AI Assistant is available now!

Feel free to start your new journey!