Information Security Compliance & Audit Manager
Salary
$127,878.40 - $177,132.80 Annually
Location
Santa Ana
Job Type
Full-Time
Job Number
8357MA-0426-017 (O)
Department
County Executive Office
Division/Service Area
CEO - OCIT Countywide Services
Opening Date
04/30/2026
Closing Date
5/17/2026 11:59 PM Pacific
CAREER DESCRIPTION
Information Security Compliance & Audit Manager
(Technology Services Manager)
Salary may be negotiable within the applicable range of the classification and successful candidates qualifications, subject to appropriate authorization.
OPEN TO THE PUBLIC
This recruitment will establish an open eligible list that will be used to fill current and future Technology Services Manager positions. The eligible list established may also be used to fill positions in similar and/or lower classifications throughout the County of Orange.
DEADLINE TO APPLY
This recruitment will be open for a minimum of five (5) business days and will close on
Sunday May 17, 2026 at 11:59pm (PST).
ORANGE COUNTY INFORMATION TECHNOLOGY
The mission of Orange County Information Technology (OCIT) is to provide innovative, reliable, and secure technology solutions that support County departments in the delivery of quality public services. OCIT provides IT solutions across County departments for voice communications, network services, application support, service desk, desktop support, as well as data center services.
Click here for more information on OCIT.
Click here for more information on the County of Orange.
THE OPPORTUNITY
The Orange County Information Technology (OCIT) Countywide Services is seeking an experienced and dynamic manager who will provide audit support, vendor security risk assessment, and PCI (Payment Card Industry) compliance management. The Information Security Compliance & Audit Manager (Technology Services Manager) serves as the enterprise owner of OCITs centralized audit coordination services and is the Countys primary liaison for IT audits, security assessment, external auditors, vendors, and internal stakeholders. This position requires strong analytical and comprehension skills with written and communication experience.
The Information Security Compliance & Audit Managers duties and responsibilities include the following:
DESIRABLE QUALIFICATIONS AND CORE COMPETENCIES
In addition to the minimum qualifications, the ideal candidate will possess at least three (3) years of work experience performing audit support, IT audits, IT compliance, PCI DSS (Payment Card Industry Data Security Standard), or a combination of the above.
A certification in one of the following is preferred but not required:
The ideal candidate will have experience in the following competencies:
Technical Knowledge | Technical Experience
Analyzing, administering, and maintaining information security architecture, information security technologies, tools, appliances, practices and controls
Understanding Information Technology and applying advanced methodologies, principles, and concepts to coordinate major projects
Understanding of audit coordination, audit readiness, and audit remediation management
Understanding of PCI (Payment Card Industry Data Security Standard) 4.0.1 requirements, assessment methodologies, and validation processes
Utilizing risk management and internal control frameworks applicable to public-sector and regulated environments
Utilizing technical project management methodology
Evaluating and monitoring Information Security Risk strategies to maintain efficiency, accuracy, and compliance
Utilizing GRC (Governance, Risk and Compliance) and service management platforms (i.e. Optro, ServiceNow), evidence repositories (i.e. SharePoint), and security tooling outputs (i.e. vulnerability management, SIEM)
Understanding payment technologies, cardholder data environments, and secure system architectures
Working knowledge and familiarity with HIPAA (Health Insurance Portability and Accountability Act), PCI DSS (Payment Card Industry Data Security Standard), CJIS Security Policy (Criminal Justice Information Services), NIST Cybersecurity Framework & NIST SP-800 Series
Leadership Skills
Oral | Written Communication Skills
LICENSE REQUIREMENT
Possession of a California Class C Driver License is Required.
MINIMUM QUALIFICATIONS
Please click here for details on this classification, including the physical, mental, environmental and working conditions.
SPECIAL REQUIREMENT | BACKGROUND INVESTIGATION
Part of the selection process for positions within Orange County Information Technology (OCIT) requires that all candidates undergo an extensive background investigation process, to the satisfaction of the Department. Candidates must successfully clear prior to the start of their employment. All employment offers are contingent upon successful completion of a background investigation.
RECRUITMENT PROCESS
Human Resource Services (HRS) will screen all application materials to identify qualified applicants. After screening, qualified applicants will be referred to the next step and notified of all further procedures applicable to their status in the competition.
Application Screening (Refer/Non-Refer)
Applications and supplemental responses will be screened for qualifications that are highly desirable and most needed to successfully perform the duties of this job. Only those applicants that meet the qualifications as listed in the job bulletin will be referred to the next step.
Structured Oral Interview | SOI (Weighted 100%)
Applicants will be interviewed and rated by an oral interview panel of job knowledge experts. Each applicants rating will be based on responses to a series of structured questions designed to elicit the applicants qualifications for the job. Only the most successful candidates will be placed on the eligible list.
Eligible List
Once the assessment has been completed, HRS will establish an eligible list of candidates. Candidates placed on the eligible list may be referred to a selection interview to be considered for present and future vacancies.
Based on the Departments needs, the selection procedure listed above may be modified. All candidates will be notified of any changes in the selection procedure.
Veterans Employment Preference
The County is committed to providing a mechanism to give preferential consideration in the employment process to veterans and their eligible spouses and will provide eligible participants the opportunity to receive interviews in the selection process for employment and paid internship openings. Please click here to review the policy.
ADDITIONAL INFORMATION
EMAIL NOTIFICATION
Email is the primary form of notification during the recruitment process. Please ensure your correct email address is included in our application and use only one email account.
NOTE: User accounts are established for one person only and should not be shared with another person. Multiple applications with multiple users may jeopardize your status in the recruitment process for any positions for which you apply.
Candidates will be notified regarding their status as the recruitment proceeds via email through the GovernmentJobs.com site. Please check your email folders, including spam/junk folders, and/or accept emails ending with "governmentjobs.com" and "ocgov.com." If your email address should change, please update your profile at www.governmentjobs.com.
FREQUENTLY ASKED QUESTIONS
Click here for additional Frequently Asked Questions.
For specific information pertaining to this recruitment, contact Joanna Xue at joanna.xue@ceo.oc.gov or (714)-834-7338.
EEO INFORMATION
Orange County, as an equal employment opportunity employer,
encourages applicants from diverse backgrounds to apply.
Administrative Management *
In addition to the Countys standard suite of benefits -- such as a variety of health plan options, sick and vacation time and paid holidays -- we also offer an excellent array of benefits such as:
http://www.ocers.org/active-member-information.
Click here for information about benefits offered to County of Orange employees.
01
INSTRUCTIONS: The information you provide on this questionnaire will be evaluated and used to determine your level of expertise during the recruitment process. Be as specific as possible and include all information requested. If you do not have experience in an area, please answer "N/A". Statements such as "see application" or "see resume", will not be accepted in lieu of a response. All employers referenced on this questionnaire must be listed on your application. Do you understand these instructions?
02
I understand that as part of the selection process for positions within OCIT, I will be required to undergo an extensive background investigation including but not limited to contacting my current and/or previous employers, reference checks, criminal searches, verification of credentials, review of credit history. Any falsification of information or failure to meet the standards listed above will result in my disqualification.
03
Please select the option that is most applicable to your experience as defined in the Technology Services Manager minimum qualifications. NOTE: If you are substituting education for experience to meet the minimum qualifications you will need to attach unofficial transcripts to your application. If you do not attach it to your application will be considered incomplete and will not be moving forward in the recruitment process.
04
Based on your response to question #3, if you are substituting relevant education for the required experience as defined in the Technology Services Manager minimum qualifications, you are acknowledging that you attached a copy of your unofficial transcripts to your application. Foreign degrees require an evaluation of U.S. equivalency by an agency that is a member of the National Association of Credential Services (N.A.C.E.S).
05
Please select the certifications you possess.
06
If you selected "Other" in question #5 please specify the certification you possess.
07
Please select from the following options which best describes your experience.
08
Based on your answer to question #7, please elaborate on your work experience performing audit support, IT audits, IT compliance, PCI DSS (Payment Card Industry Data Security Standard), or a combination of the above. Please include in your response, your years of experience, the scope of your responsibilities, and the organization you obtained this experience from. If none, please type "N/A".
09
Please describe your lead/supervisory experience related to this assignment. Please include in your response, your years of experience, the scope of your responsibilities, and the organization you obtained this experience from. If none, please type "N/A".
Required Question
Employer County of Orange
Address 400 W CIVIC CENTER DRIVE
Santa Ana, California, 92701
Phone 714-834-2555
Website https://hrs.oc.gov