Principal Identity Engineer - Cloud IAM / CIAM (Remote)

Posted 11 Days Ago
Be an Early Applicant
Hiring Remotely in Home Junction, CA, USA
In-Office or Remote
171K-228K Annually
Expert/Leader
Insurance • Real Estate
The Role
The Principal Identity Engineer will lead IAM strategy and architecture for cloud environments, focusing on security, Zero Trust frameworks, and identity automation to enhance security and compliance across systems.
Summary Generated by Built In
Who We AreJoin a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For® list for eleven consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.

What We DoWe are open to remote or hybrid candidates for this role.
As a Principal Identity Engineer, you will own the technical strategy, architecture, and engineering execution for enterprise Identity and Access Management (IAM) across First American’s cloud and hybrid environments. This role is central to strengthening our security posture by delivering secure, scalable identity capabilities across our cloud environments (Azure AD/AWS/GCP).
You will lead workforce IAM, partner/federation (B2B), and customer identity (CIAM) architecture where applicable; establish Zero Trust identity controls; and set enterprise standards for IAM-as-code using Terraform + GitHub with automation in Python/Bash/JSON. This is a hands-on principal role requiring deep technical expertise, cross-org influence, and the ability to build repeatable platforms and guardrails teams can safely self-serve.

What You’ll Do: 

 

  • Own the enterprise IAM strategy and target-state architecture across Microsoft Entra, AWS, and Google Cloud (OCI a plus). Define secure, scalable identity patterns for workforce, partner, and customer access that align with security, risk, and compliance requirements. 

 

  • Design and operationalize a Zero Trust identity model with continuous verification, risk-based access, and adaptive authentication. Reduce standing privilege through least privilege design, just-in-time (JIT) access, and standardized entitlement models. 

 

  • Hands-on design and delivery of IAM capabilities including SSO, MFA, identity lifecycle, federation, and privileged access across cloud and hybrid environments. Lead modernization efforts, including migration from hybrid Active Directory to Entra ID–based authentication. 
     

  • Design and evolve customer identity (CIAM) solutions supporting web, mobile, and API platforms. Balance security, privacy, performance, and customer experience while enabling scalable enterprise integrations. 
     

  • Establish IAM governance frameworks covering access lifecycle, RBAC/ABAC models, access reviews, and audit evidence. Define measurable controls, documentation standards, and recurring review processes to ensure audit readiness. 
     

  • Define and lead an enterprise IAM-as-Code program using Terraform and GitHub. Build reusable, versioned modules and establish PR-based workflows with auditability, approvals, and security guardrails. 
     

  • Engineer secure CI/CD pipelines for IAM deployments, including validation, testing, approvals, drift detection, and rollback strategies. Ensure reliable, auditable identity changes with operational monitoring and clear runbooks. 
     

  • Develop automation in Python, Bash, and JSON to scale identity operations and reduce manual risk. Support policy management, bulk changes, integrations, and identity-related incident response and diagnostics. 

 

What You’ll Bring: 

 

  • Deep hands-on experience designing and operating identity platforms at scale in complex environments. 

 

  • Advanced expertise across Microsoft Entra ID, AWS IAM, and Google Cloud IAM, with OCI experience a plus. 

 

  • Proven ability to design cloud-agnostic IAM models and implement them consistently across platforms. 

 

  • Strong background in IAM security architecture, governance, and risk-based access controls. 

 

  • Hands-on experience with least privilege design, JIT access, Zero Trust identity, and RBAC/ABAC models. 

 

  • Expert knowledge of OAuth 2.0, OpenID Connect, and SAML. 

 

  • Proven experience delivering enterprise-scale SSO and MFA solutions. 

 

  • Demonstrated experience establishing IAM-as-Code using Terraform with GitHub-based change control. 

 

  • Strong scripting and automation skills in Python, Bash, and JSON, including CI/CD and guardrail design. 

 

  • Experience architecting and operating customer identity platforms for portals, mobile apps, and APIs. (preferred) 

 

  • Ability to communicate complex identity concepts to both technical and non-technical audiences. 

 

  • Strong influence, documentation, and execution skills at the principal or senior architect level. 

 

  • Relevant security or identity certifications such as CISSP or identity-focused credentials. 

 

  • Bachelor’s degree or equivalent experience, with extensive background in enterprise security engineering. 

Pay Range: $170,900.00 - $227,900.00 Annually
This hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on a number of factors which may include job-related knowledge, skills, experience, business requirements and geographic location.

** Note that the following statements only apply to candidates who will be working from an unincorporated area within Los Angeles County. **

First American will consider for employment all qualified applicants, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws (e.g., the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act).

First American intends to conduct a review of an applicant’s criminal history in connection with a conditional offer. First American reasonably believes that a criminal history may have a direct, adverse and negative relationship with the following material job duties for this position potentially resulting in the withdrawal of the conditional offer of employment: handling of confidential, proprietary or trade secret information belonging to First American or its customers, administrating or facilitating financial transactions, and the ability to meet customer-imposed criminal history requirements.

What We OfferBy choice, we don’t simply accept individuality – we embrace it, we support it, and we thrive on it! Our People First Culture celebrates diversity, equity and inclusion not simply because it’s the right thing to do, but also because it’s the key to our success. We are proud to foster an authentic and inclusive workplace For All. You are free and encouraged to bring your entire, unique self to work. First American is an equal opportunity employer in every sense of the term.

Based on eligibility, First American offers a comprehensive benefits package including medical, dental, vision, 401k, PTO/paid sick leave and other great benefits like an employee stock purchase plan.

Skills Required

  • Deep hands-on experience designing and operating identity platforms at scale in complex environments.
  • Advanced expertise across Microsoft Entra ID, AWS IAM, and Google Cloud IAM, with OCI experience a plus.
  • Proven ability to design cloud-agnostic IAM models and implement them consistently across platforms.
  • Strong background in IAM security architecture, governance, and risk-based access controls.
  • Hands-on experience with least privilege design, JIT access, Zero Trust identity, and RBAC/ABAC models.
  • Expert knowledge of OAuth 2.0, OpenID Connect, and SAML.
  • Proven experience delivering enterprise-scale SSO and MFA solutions.
  • Demonstrated experience establishing IAM-as-Code using Terraform with GitHub-based change control.
  • Strong scripting and automation skills in Python, Bash, and JSON, including CI/CD and guardrail design.
  • Experience architecting and operating customer identity platforms for portals, mobile apps, and APIs.
  • Ability to communicate complex identity concepts to both technical and non-technical audiences.
  • Strong influence, documentation, and execution skills at the principal or senior architect level.
  • Relevant security or identity certifications such as CISSP or identity-focused credentials.
  • Bachelor's degree or equivalent experience, with extensive background in enterprise security engineering.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Santa Ana, CA
13,104 Employees
Year Founded: 1889

What We Do

First American provides financial services through its Title Insurance and Services segment and its Specialty Insurance segment. The First American Family of Companies’ core business lines include title insurance and closing/settlement services; title plant management services; title and other real property records and images; valuation products and services; home warranty products; property and casualty insurance; and banking, trust, and investment advisory services. First American Title Insurance Company provides comprehensive title insurance protection and professional settlement services for homebuyers and sellers, real estate agents and brokers, mortgage lenders, commercial property professionals, homebuilders and developers, title agencies and legal professionals to facilitate real estate purchases, construction, refinances or equity loans. First American's thorough title searches, title clearance and title insurance policies help to produce clear property titles and enable the efficient transfer of real estate. As one of the largest title insurance companies in the nation, First American offers title insurance and settlement services through its direct operations and an extensive network of agents throughout the United States and internationally. First American Title Insurance Company traces its history to 1889 and is the largest subsidiary of First American Financial Corporation (NYSE: FAF).

Similar Jobs

MetLife Logo MetLife

Customer Care Advocate Disability Service- Omaha NE 7.20.26

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Remote or Hybrid
United States
43000 Employees
42K-42K Annually

Airwallex Logo Airwallex

Data Science Director, Growth

Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
Remote or Hybrid
San Francisco, CA, USA
2000 Employees

Airwallex Logo Airwallex

Customer Insights Lead

Artificial Intelligence • Fintech • Payments • Business Intelligence • Financial Services • Generative AI
Remote or Hybrid
San Francisco, CA, USA
2000 Employees

Nexthink Logo Nexthink

Client Director- West

Artificial Intelligence • Big Data • Cloud • Information Technology • Machine Learning • Software
Remote or Hybrid
San Diego, CA, USA
1200 Employees
113K-176K Annually

Similar Companies Hiring

MassMutual India Thumbnail
Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana
Agora RE Thumbnail
Fintech • Real Estate • PropTech
Tel Aviv, IL
200 Employees
Granted Thumbnail
Mobile • Insurance • Healthtech • Financial Services • Artificial Intelligence
New York, New York
23 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account