Logo
First American

Senior Information Security Architect - Cloud IAM

First American, Santa Ana, California, United States, 92725

Save Job

Join a team that puts its People First! Since 1889, First American (NYSE: FAF) has believed in its people. We foster an environment where everyone feels welcome, supported, and empowered to innovate and reach their full potential. Our inclusive culture has earned us numerous accolades, including being named to the Fortune 100 Best Companies to Work For list for ten consecutive years. We are committed to being a great place to work for all. For more information, visit

www.careers.firstam.com .

What We Do We are seeking a highly skilled Senior IAM Security Architect to join our security architecture team. This role requires expertise in designing, implementing, and managing IAM security controls, focusing on identity protection in cloud environments. The ideal candidate will have a strong background in AWS, Azure, and Entra ID (formerly Azure AD), with at least 5 years of experience in IAM security risk assessment and threat modeling. Responsibilities include managing user and non-human identities, access controls, security policies, establishing a Zero Trust identity posture, implementing behavioral risk assessments, and driving automation for identity security. Knowledge of SSO, MFA, and modern authentication protocols is essential.

What You'll Do

Design secure IAM architectures across platforms (AWS, Azure, Entra ID) in line with best practices.

Develop security controls for IAM, including authentication, authorization, role management, identity federation, and privilege management.

Establish and maintain a Zero Trust security model for IAM, ensuring continuous verification of access requests.

Integrate Zero Trust principles with cloud-native security tools and IAM platforms for seamless, secure access control.

Automate risk-based access controls and adaptive authentication based on behavioral signals.

Enforce least privilege access principles across cloud and on-prem environments.

Design and implement Just-in-Time (JIT) access control mechanisms.

Design SSO solutions for seamless and secure access to enterprise applications.

Lead the adoption of modern authentication protocols (OAuth 2.0, OpenID Connect, SAML).

Implement and manage MFA solutions with risk-based policies.

Develop and integrate IAM security controls with cloud platforms like AWS, Azure, and Entra ID.

Collaborate with cloud engineers to align IAM security with best practices and compliance standards.

Leverage native security features of cloud platforms to design scalable, secure, and automated IAM solutions.

Lead migration from Hybrid Active Directory to Entra-ID based authentication, ensuring minimal disruption.

Develop security governance frameworks for IAM, focusing on identity lifecycle management, RBAC, and least privilege enforcement.

Conduct regular identity governance and access reviews, documenting changes for compliance.

Work with cross-functional teams to incorporate IAM security best practices across systems.

Stay updated on IAM trends, threats, and technological advancements.

Implement automation tools to enhance efficiency in identity management and access control.

What You'll Bring

Bachelor's degree in computer science, Information Security, or related field.

Relevant certifications such as CISSP or CIAM preferred.

7+ years in IAM security, with at least 5 years in risk assessment, threat modeling, and security control design.

Proven experience with IAM solutions in cloud environments (AWS, Azure, Entra ID).

Deep knowledge of IAM security best practices, governance, and policies.

Experience with IAM protocols like SSO, MFA, OAuth, SAML, OpenID Connect, and federation.

Hands-on risk assessment and threat modeling experience for IAM systems.

Experience establishing least privilege and JIT access controls.

Expertise in Zero Trust security posture, identity validation, and continuous authentication.

Strong skills with Microsoft Entra ID (Azure AD), AWS IAM, Azure Active Directory.

Experience integrating IAM with cloud security and hybrid environments.

Understanding of RBAC, ABAC, policy enforcement, and JIT provisioning.

Proficiency with SSO and MFA implementation, and familiarity with OAuth 2.0, OpenID Connect, SAML.

This role is hybrid, with three days per week in Santa Ana, CA, and may be remote for out-of-area candidates.

Pay Range: $145,000.00 - $193,325.00 annually. Compensation depends on factors including experience, skills, and location.

What We Offer Our People First Culture celebrates diversity, equity, and inclusion. We support your authentic self at work and are proud to be an equal opportunity employer. We also consider applicants' criminal history in accordance with applicable laws, such as the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act.

Our benefits include medical, dental, vision, 401k, PTO, sick leave, and other perks like an employee stock purchase plan.

#J-18808-Ljbffr