Network Security Architect (Hybrid)

firstam

Santa Ana (CA)

On-site

USD 129,000 - 172,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental insurance
Vision
401k
PTO
Stock purchase plan

Job summary

First American is seeking a Network Security Architect to define and govern enterprise security architectures that align with business goals, risk management, and modernization efforts. You will collaborate with IT teams, vendors, and auditors to deliver secure architectural solutions and drive secure adoption across the organization.

The role requires strong leadership, hands-on expertise with firewalls, VPNs, MFA, PKI, and cloud connectivity across on-premises, cloud, and hybrid environments.

Qualifications

  • Minimum 5 years of experience designing, implementing, and governing enterprise network security architectures in large-scale, complex environments.
  • Proven experience leading architecture and design of network security solutions including firewalls, secure remote access, network segmentation, Zero Trust, and cloud connectivity.
  • Experience integrating network security architectures with enterprise identity, directory, and infrastructure services.
  • Experience evaluating security products, conducting PoC assessments, and managing vendor/partner relationships.
  • Strong hands-on knowledge of firewalls, VPNs, ACLs, IDS/IPS, MFA, PKI, and cloud connectivity.
  • Deep understanding of WAN/LAN, Internet protocols, and hybrid infrastructure environments.
  • Knowledge of ISO 27001/27002, NIST, CIS Controls, COBIT, and governance frameworks.
  • Excellent communication and consulting skills to translate security concepts for stakeholders.
  • Ability to develop and communicate security policies, standards, and architectural guidelines.
  • Experience designing modern network security architectures (Zero Trust, SASE/SSE, ZTNA, CASB, SD-WAN, micro-segmentation).
  • Proven track record designing and governing enterprise network security in large environments.
  • Extensive experience with Palo Alto Networks technologies (NGFW, Panorama, GlobalProtect, Prisma Access).
  • Experience securing cloud network architectures across Azure, AWS, and Google Cloud.
  • Bachelor's degree in related field; advanced security training/certs preferred

Responsibilities

  • Define and maintain the enterprise network security architecture roadmap aligned with objectives and risk requirements.
  • Serve as technical authority for network security architecture decisions and provide design governance.
  • Lead architecture, design, and deployment of network security solutions for enterprise infrastructure and applications.
  • Lead design and governance of firewall architectures, segmentation, secure remote access, Zero Trust initiatives.
  • Architect and review secure network connectivity across on-premises, cloud, hybrid, and third-party environments.
  • Establish architectural standards and reference designs for security technologies (firewalls, VPNs, NAC, cloud security).
  • Conduct risk assessments and security exposure analyses across systems, networks, and applications.
  • Lead security design reviews for new applications and infrastructure.
  • Advise IT/business teams on security risks of technology changes.
  • Promote information security policies, standards, best practices, and regulatory requirements.
  • Lead audits of controls and ensure compliance with standards
  • Research and recommend emerging security technologies and industry best practices.
  • Drive continuous improvement of security processes and departmental practices.
  • Provide technical leadership and mentorship within Information Security.
  • Offer after-hours coverage to support critical business needs

Skills

Network security architecture
Zero Trust
Palo Alto Networks
Cloud connectivity
Firewall design
Risk assessment
Regulatory standards
Vendor management
Communication skills
Mentorship

Education

Bachelor's degree in CS/IS/Engineering

Tools

Panorama
GlobalProtect
Prisma Access
PKI
IDS/IPS

Job description

Who We Are

Join a team that puts its People First! Since 1889, First American (NYSE: FAF) has held an unwavering belief in its people. They are passionate about what they do, and we are equally passionate about fostering an environment where all feel welcome, supported, and empowered to be innovative and reach their full potential. Our inclusive, people-first culture has earned our company numerous accolades, including being named to the Fortune 100 Best Companies to Work For® list for eleven consecutive years. We have also earned awards as a best place to work for women, diversity and LGBTQ+ employees, and have been included on more than 50 regional best places to work lists. First American will always strive to be a great place to work, for all. For more information, please visit www.careers.firstam.com.

What We Do

The Network Security Architect is responsible for defining, designing, and governing enterprise network security architectures that support business objectives, technology modernization initiatives, and risk management requirements. This role collaborates closely with internal IT teams, client managers, business stakeholders, third-party partners, vendors, and auditors to ensure effective security outcomes. Working alongside Security Engineers, the Security Architect develops secure architectural solutions and provides guidance for successful implementation and operational adoption by Security Engineers and Analysts.

What You’ll Do
  • Define and maintain the enterprise network security architecture roadmap, ensuring alignment with business objectives, risk management requirements, and technology strategies.
  • Serve as the technical authority for network security architecture decisions and provide design governance across enterprise technology initiatives.
  • Lead the architecture, design, and deployment of network security solutions supporting enterprise infrastructure and business applications.
  • Lead the design and governance of enterprise firewall architectures, network segmentation strategies, secure remote access solutions, and Zero Trust initiatives.
  • Architect, design, and review secure network and connectivity solutions across on-premises, cloud, hybrid, and third‑party environments.
  • Establish architectural standards and reference designs for network security technologies, including firewalls, VPNs, network access controls, and cloud‑delivered security services.
  • Conduct and oversee technical risk assessments and security exposure analyses across systems, networks, and applications.
  • Lead security design reviews for new applications, infrastructure, and technology initiatives.
  • Serve as a trusted advisor to IT and business teams by assessing and communicating security risks associated with technology changes.
  • Recommend and promote information security policies, standards, best practices, and regulatory compliance requirements.
  • Lead initiatives to audit security controls, address policy violations, and ensure compliance with established security standards and procedures.
  • Research, evaluate, and recommend emerging security technologies and industry best practices to strengthen the organization’s security posture and support strategic technology decisions.
  • Drive continuous improvement of security processes, operational procedures, and departmental practices to enhance efficiency and effectiveness.
  • Provide technical leadership and mentorship within the Information Security function, acting as a security subject matter expert.
  • Support critical business needs by providing after‑hours coverage when required.
Job Complexities & Impact
  • Maintains a comprehensive understanding of information technology, cybersecurity, and business operations to align security architecture and strategic initiatives with organizational objectives.
  • Applies advanced professional expertise and deep industry knowledge to address complex security, operational, and business challenges.
  • Provides architectural guidance for the resolution of complex network security challenges and mentors engineers on security design and implementation best practices.
  • Exercises sound judgment when making decisions, recognizing that actions and errors at this level can have significant operational, financial, regulatory, and reputational impact.
What You’ll Bring
  • Minimum 5 years of experience designing, implementing, and governing enterprise network security architectures in large-scale, complex environments.
  • Demonstrated experience leading the architecture and design of network security solutions, including enterprise firewalls, secure remote access, network segmentation, Zero Trust, and cloud connectivity.
  • Must have experience integrating network security architectures with enterprise identity, directory, and infrastructure services.
  • Must have experience evaluating security products, conducting proof‑of‑concept assessments, and managing vendor and strategic partner relationships.
  • Must have a strong hands‑on knowledge of network and security technologies, including firewalls, routers, network segmentation, access control lists (ACLs), intrusion detection/prevention systems (IDS/IPS), virtual private networks (VPNs), multifactor authentication (MFA), and public key infrastructure (PKI).
  • Must have a deep understanding of networking concepts, including WAN, LAN, cloud connectivity, Internet protocols, network services, and hybrid infrastructure environments.
  • Must have working knowledge of information security frameworks, standards, and regulatory requirements, including ISO 27001/27002, NIST, CIS Controls, COBIT, and related governance frameworks.
  • Must have excellent communication and consulting skills, with the ability to translate technical security concepts into business‑focused recommendations for stakeholders at all organizational levels.
  • Has proven ability to develop and communicate security policies, standards, procedures, and architectural guidelines.
  • Demonstrated ability to balance business objectives, operational requirements, and security priorities to enable secure business outcomes.
  • Must have experience designing modern network security architectures, including Zero Trust, SASE/SSE, ZTNA, CASB, SD-WAN, network segmentation, and micro segmentation strategies.
  • Must have proven experience designing and governing enterprise network security architectures in large‑scale, complex environments.
  • Must have extensive experience with Palo Alto Networks technologies, including Next‑Generation Firewalls, Panorama, GlobalProtect, and Prisma Access.
  • Must have experience securing cloud network architectures and hybrid connectivity models across Azure, AWS, and/or Google Cloud environments.
  • Bachelor's degree in Computer Science, Information Systems, Information Security, Engineering, or a related field, or equivalent combination of education and experience.
  • Advanced security training, professional certifications, and continuing education in cybersecurity, networking, and cloud technologies are preferred.
Preferred Certifications
  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CCSP (Certified Cloud Security Professional)
  • PCNSE (Palo Alto Networks Certified Network Security Engineer)
  • CCSK (Certificate of Cloud Security Knowledge)
  • CCNP Security
  • AWS Certified Security – Specialty

Pay Range: $129,300.00 - $172,300.00 AnnuallyThis hiring range is a reasonable estimate of the base pay range for this position at the time of posting. Pay is based on a number of factors which may include job‑related knowledge, skills, experience, business requirements and geographic location.

** Note that the following statements only apply to candidates who will be working from an unincorporated area within Los Angeles County. **

First American will consider for employment all qualified applicants, including those with arrest or conviction records, in a manner consistent with the requirements of applicable state and local laws (e.g., the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act).

First American intends to conduct a review of an applicant’s criminal history in connection with a conditional offer. First American reasonably believes that a criminal history may have a direct, adverse and negative relationship with the following material job duties for this position potentially resulting in the withdrawal of the conditional offer of employment: handling of confidential, proprietary or trade secret information belonging to First American or its customers, administrating or facilitating financial transactions, and the ability to meet customer‑imposed criminal history requirements.

What We Offer

By choice, we don’t simply accept individuality – we embrace it, we support it, and we thrive on it! Our People First culture is inclusive for all employees - not just because it's the right thing to do, but because it's the key to our success. We are proud to foster an authentic and inclusive workplace For All. You are free and encouraged to bring your entire, unique self to work. First American is an equal opportunity employer in every sense of the term.

Based on eligibility, First American offers a comprehensive benefits package including medical, dental, vision, 401k, PTO/paid sick leave and other great benefits like an employee stock purchase plan.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Operations Manager
Information Security Operations Manager

firstam • Santa Ana (CA)

On-site
USD 129,000 - 172,000
Medical benefits
Dental benefits
Vision benefits
+3
Cloud Security Solution Architect (Remote)
Cloud Security Solution Architect (Remote)

First American • Charlotte (NC)

Remote
USD 120,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+2
Engineering Manager (AI-Native Platform) - Remote
Engineering Manager (AI-Native Platform) - Remote

firstam • Santa Ana (CA)

Remote
USD 149,000 - 198,000
Medical benefits
Dental benefits
Vision benefits
+2
Staff Software Engineer (AI-Native Platform) - Remote
Staff Software Engineer (AI-Native Platform) - Remote

firstam • Santa Ana (CA)

Remote
USD 149,000 - 198,000
Medical benefits
401(k) plan
PTO / Paid time off
+1
Engineering Manager (AI-Native Platform) - Remote
Engineering Manager (AI-Native Platform) - Remote

First American • United States

Remote
USD 149,000 - 198,000
Employee stock purchase plan
Medical, dental, vision benefits
PTO & paid sick leave
Staff Software Engineer (AI-Native Platform)
Staff Software Engineer (AI-Native Platform)

First American • United States

Remote
USD 149,000 - 198,000
Medical insurance
Dental insurance
Vision insurance
+3
Engineering Director - Remote
Engineering Director - Remote

firstam • Santa Ana (CA)

Remote
USD 197,000 - 263,000
401k
Paid time off
Employee stock purchase plan
ServiceNow Senior Software Engineer
ServiceNow Senior Software Engineer

firstam • California (MO)

On-site
USD 129,000 - 172,000
HRIS Architect
HRIS Architect

firstam • Santa Ana (CA)

On-site
USD 85,000 - 113,000
Medical insurance
Dental insurance
Vision insurance
+2
Risk Analyst (Hybrid)
Risk Analyst (Hybrid)

firstam • Santa Ana (CA)

Hybrid
USD 64,000 - 86,000
Medical coverage
Dental coverage
Vision coverage
+3