POSITION SUMMARY
The Cloud and Identity Administrator II administers, secures, and improves the Association’s cloud, identity, and related infrastructure environments. This hybrid role combines cloud administration, systems administration, security operations, identity management, and identity governance across Microsoft 365, Entra ID, Azure/AWS cloud platforms, endpoint management, directory services, authentication, privileged access, and related security controls. This role also participates in an after-hours on-call rotation and may be required to respond to urgent operational and security events outside normal business hours.
PRINCIPAL DUTIES & RESPONSIBILITIES
- Administer, secure, and improve Microsoft 365, Entra ID, Azure, AWS, Active Directory, Intune, Exchange Online, SharePoint, OneDrive, Teams, endpoint management, and related cloud, identity, and enterprise services.
- Manage identity and access controls across the user and application lifecycle,
- Administer privileged access and PAM-related processes, including privileged account management, approval workflows, service account governance, privileged session monitoring, and periodic validation.
- Perform advanced systems and cloud administration for hybrid infrastructure, including servers, directory services, cloud workloads, patching, vulnerability remediation, configuration management, and operational controls.
- Support security operations by reviewing alerts, logs, access activity, cloud events, and vulnerability findings.
- Recommend and implement remediation or compensating controls as appropriate.
- Lead assigned cloud, identity, infrastructure, security, and automation initiatives
- Develop and maintain standards, procedures, technical documentation, runbooks, configuration records, access review evidence, and operational artifacts to support reliable, audit-defensible IT and security operations.
- Partner with business stakeholders and vendors to resolve complex issues, improve reliability and controls, and participate in after-hours on-call responses
EDUCATION & EXPERIENCE
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or related field preferred; equivalent advanced technical experience may be considered.
- Minimum of 5 years of progressive experience in systems administration, cloud administration, identity administration, security administration, or a related technical role.
- Advanced knowledge of Microsoft 365, Entra ID, Active Directory, Azure, AWS, Intune, Autopilot, Exchange Online, SharePoint, OneDrive, Teams, hybrid identity, endpoint management, and related cloud and enterprise services.
- Strong understanding of identity, access, and privileged access management practices, including SSO, MFA, conditional access, RBAC, service account governance, credential vaulting, just-in-time access, and access reviews.
- Experience supporting cloud security, endpoint security, vulnerability remediation, logging, monitoring, backup, disaster recovery, configuration management, and operational controls in hybrid environments.
- Working knowledge of scripting, PowerShell, automation, reporting, workflow automation, audit evidence collection, application provisioning, SAML/OIDC, SCIM, API-based account lifecycle management, and infrastructure as code concepts such as Terraform preferred.
- Working knowledge of CIS, NIST, SOC 2, ISO 27001, or similar control frameworks and relevant certifications preferred.
Skills Required
- Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent advanced technical experience
- Minimum 5 years of progressive experience in systems administration, cloud administration, identity administration, security administration, or a related technical role
- Advanced knowledge of Microsoft 365, Entra ID, Active Directory, Azure, AWS, Intune, Autopilot, Exchange Online, SharePoint, OneDrive, Teams, hybrid identity, endpoint management, and related cloud and enterprise services
- Strong understanding of identity, access, and privileged access management, including SSO, MFA, conditional access, RBAC, service account governance, credential vaulting, just-in-time access, and access reviews
- Experience supporting cloud security, endpoint security, vulnerability remediation, logging, monitoring, backup, disaster recovery, configuration management, and operational controls in hybrid environments
- Working knowledge of scripting, PowerShell, automation, reporting, workflow automation, audit evidence collection, application provisioning, SAML/OIDC, SCIM, API-based account lifecycle management, and infrastructure as code concepts such as Terraform
- Working knowledge of CIS, NIST, SOC 2, ISO 27001, or similar control frameworks
- Relevant certifications
What We Do
The California FAIR Plan is a private association comprised of all insurers authorized to write property insurance in California. The FAIR Plan was established in July 1968 following the 1960s brush fires and riots as the state’s insurer of last resort, created to ensure access to basic property insurance for California homeowners who have been unable to obtain homeowners insurance from the voluntary market for reasons outside of their control. The FAIR Plan will write fire insurance coverage for these homeowners, regardless of a property’s wildfire risk. The FAIR Plan is committed to strengthening consumer choices in the voluntary insurance market, while ensuring that all homeowners, including those who live in areas threatened by wildfires, can obtain basic property coverage and the peace of mind they deserve







