Owns enterprise identity security architecture and multi-year strategy across workforce, customer, privileged, machine, workload, AI, cloud, SaaS, on-premises, and OT environments. Responsibilities include technology rationalization, reference architecture, authentication and authorization design, non-human identity, AI agent security, OT/ICS identity, PAM, cryptographic identity, security standards, threat detection collaboration, executive communication, and mentoring.
Work Location Type: Remote
Req Number 334336
About Grainger
W.W. Grainger, Inc. is a leading broad line distributor with operations primarily in North America and Japan. At Grainger, We Keep the World Working® by serving more than 4.6 million customers worldwide with maintenance, repair and operating (MRO) products and value-added solutions delivered through innovative technology and deep customer expertise. Known for its commitment to service and purpose-driven culture, the Company reported 2025 revenue of $17.9 billion. For more information, visit www.grainger.com.
Compensation
The anticipated base pay compensation range for this position is $135,400.00 - $225,600.00. This role is eligible for an incentive target of up to 20% or $, based on the achievement of individual and company performance objectives in accordance with the current terms of the incentive program which are subject to change.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
Rewards and Benefits
With benefits starting on day one, our programs provide choice and flexibility to meet team members' individual needs, including:
For additional information and details regarding Grainger's benefits, please click on the link below:
https://experience100.ehr.com/grainger/Home/Tools-Resources/Key-Resources/New-Hire
Grainger Benefits
The pay range provided above is not a guarantee of compensation. The range reflects the potential base pay for this role at the time of this posting based on the job grade for this position. Individual base pay compensation will depend, in part, on factors such as geographic work location and relevant experience and skills.
The anticipated compensation range described above is subject to change and the compensation ultimately paid may be higher or lower than the range described above.
Grainger reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion at any time, consistent with applicable law.
Position Details
The Information Security team protects all of Grainger, from our systems to our data across the global company. Our infrastructure is powered by cloud, on-premises, and SaaS platforms that keep Grainger, and our customers, working. We use modern tools and practices to stay ahead of evolving security challenges.
The mission of the Security Architecture team is to be the strategic security design partner for Grainger's technology systems. As the security architect responsible for Grainger's identity ecosystem, you will be responsible for architecting, advising on, and governing how every human, machine, workload, and AI agent authenticates and is authorized across our cloud, SaaS, on-premises, and operational technology environments. This role owns the architecture spanning workforce identity, customer identity, privileged access, non-human and machine identity, secrets, and certificate lifecycle management.
Grainger's identity landscape is broad: hybrid workforce directory and federation services, a distinct customer identity estate supporting global eCommerce, a rapidly expanding population of workload and machine identities across cloud and SaaS, an emerging portfolio of AI and agentic platforms, and a substantial operational technology footprint.
You will support the progressive needs of the business and provide timely, secure and cost-efficient solutions that elevate the company's identity security strategy. You will identity security architect will set multi-year identity strategy and reference architecture, rationalize a broad and overlapping portfolio of identity technologies into a defensible target state, and build the stakeholder alignment required to execute it. Success here depends as much on understanding why the business operates the way it does as on the depth of the technical design. You will be expected to translate business context into identity requirements and identity risk into business impact.
In this individual contributor role, you will report to the Director of Cybersecurity Architecture and may be based remotely or at our offices in the Chicago area.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
You will
You have
We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, protected veteran status or any other protected characteristic under federal, state, or local law. We are proud to be an equal opportunity workplace.
We are committed to fostering an inclusive, accessible work environment that includes both providing reasonable accommodations to individuals with disabilities during the application and hiring process as well as throughout the course of one's employment, should you need a reasonable accommodation during the application and selection process, including, but not limited to use of our website, any part of the application, interview or hiring process, please advise us so that we can provide appropriate assistance.
Req Number 334336
About Grainger
W.W. Grainger, Inc. is a leading broad line distributor with operations primarily in North America and Japan. At Grainger, We Keep the World Working® by serving more than 4.6 million customers worldwide with maintenance, repair and operating (MRO) products and value-added solutions delivered through innovative technology and deep customer expertise. Known for its commitment to service and purpose-driven culture, the Company reported 2025 revenue of $17.9 billion. For more information, visit www.grainger.com.
Compensation
The anticipated base pay compensation range for this position is $135,400.00 - $225,600.00. This role is eligible for an incentive target of up to 20% or $, based on the achievement of individual and company performance objectives in accordance with the current terms of the incentive program which are subject to change.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
Rewards and Benefits
With benefits starting on day one, our programs provide choice and flexibility to meet team members' individual needs, including:
- Medical, dental, vision, and life insurance plans with coverage starting on day one of employment and 6 free sessions each year with a licensed therapist to support your emotional wellbeing.
- 18 paid time off (PTO) days annually for full-time employees (accrual prorated based on employment start date) and 6 company holidays per year.
- 6% company contribution to a 401(k) Retirement Savings Plan each pay period, no employee contribution required.
- Employee discounts, tuition reimbursement, student loan refinancing and free access to financial counseling, education, and tools.
- Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents.
For additional information and details regarding Grainger's benefits, please click on the link below:
https://experience100.ehr.com/grainger/Home/Tools-Resources/Key-Resources/New-Hire
Grainger Benefits
The pay range provided above is not a guarantee of compensation. The range reflects the potential base pay for this role at the time of this posting based on the job grade for this position. Individual base pay compensation will depend, in part, on factors such as geographic work location and relevant experience and skills.
The anticipated compensation range described above is subject to change and the compensation ultimately paid may be higher or lower than the range described above.
Grainger reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion at any time, consistent with applicable law.
Position Details
The Information Security team protects all of Grainger, from our systems to our data across the global company. Our infrastructure is powered by cloud, on-premises, and SaaS platforms that keep Grainger, and our customers, working. We use modern tools and practices to stay ahead of evolving security challenges.
The mission of the Security Architecture team is to be the strategic security design partner for Grainger's technology systems. As the security architect responsible for Grainger's identity ecosystem, you will be responsible for architecting, advising on, and governing how every human, machine, workload, and AI agent authenticates and is authorized across our cloud, SaaS, on-premises, and operational technology environments. This role owns the architecture spanning workforce identity, customer identity, privileged access, non-human and machine identity, secrets, and certificate lifecycle management.
Grainger's identity landscape is broad: hybrid workforce directory and federation services, a distinct customer identity estate supporting global eCommerce, a rapidly expanding population of workload and machine identities across cloud and SaaS, an emerging portfolio of AI and agentic platforms, and a substantial operational technology footprint.
You will support the progressive needs of the business and provide timely, secure and cost-efficient solutions that elevate the company's identity security strategy. You will identity security architect will set multi-year identity strategy and reference architecture, rationalize a broad and overlapping portfolio of identity technologies into a defensible target state, and build the stakeholder alignment required to execute it. Success here depends as much on understanding why the business operates the way it does as on the depth of the technical design. You will be expected to translate business context into identity requirements and identity risk into business impact.
In this individual contributor role, you will report to the Director of Cybersecurity Architecture and may be based remotely or at our offices in the Chicago area.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
You will
- Own the enterprise identity security architecture and multi-year strategy across workforce, customer, third-party, privileged, machine, workload, and AI agent identities, spanning cloud, SaaS, on-premises, and OT
- Translate business context into identity requirements, sequencing, and investment priorities in partnership with various business leaders
- Lead identity technology rationalization: capability mapping, target-state platform selection, consolidation and retirement options, and proof-of-value evaluations
- Serve as the identity design authority in Grainger's architecture governance process, engaging early enough to shape design decisions
- Produce reference architectures and reusable authentication, authorization, federation, and entitlement patterns, and threat model identity designs with delivery teams
- Architect non-human identity at scale across issuance, attestation, rotation, and decommissioning
- Define authentication and authorization for AI and agentic systems, including OAuth 2.0/2.1 flows, token exchange, delegated authority, short-lived credentials, and identity enforcement at MCP and AI gateways
- Partner with machine learning and platform engineering on agent identity, agent-to-agent authorization, and downstream data access as AI moves into production
- Set the target architecture for OT/ICS identity, including IT/OT identity separation and vendor remote access under known OT/ICS constraints
- Advance customer identity architecture for digital commerce, including federation, authorization models, token security, and migration off legacy identity solutions
- Define privileged access and cryptographic identity architecture, advancing just-in-time and zero standing privilege, certificate lifecycle automation, mTLS, and secrets management
- Develop and enforce identity security standards and baselines aligned to NIST SP 800-63, NIST SP 800-207, NIST CSF, CIS Benchmarks, and IEC 62443
- Partner with detection and response teams on identity threat detection coverage, attack path mapping, and identity telemetry into the SIEM/SOAR platform
- Communicate identity posture and program progress to leadership through relevant metrics and KPIs
- Mentor peers and junior architects through design reviews, pattern development, and knowledge sharing
You have
- Deep expertise designing enterprise identity architectures for large, complex organizations, with ownership of the strategy and target state rather than platform administration or technology engineering
- 10+ years in information security or identity engineering, including 8+ years in security architecture with at least 6 years focused on identity
- Bachelor's degree preferred; equivalent professional experience accepted
- Preferred certifications: CISSP, CCSP, SABSA, IDPro CIDPRO, or vendor identity certifications
- Proven ability to align senior technology and business stakeholders behind multi-year identity direction amid competing priorities
- Experience rationalizing overlapping identity portfolios: capability mapping, build/buy/consolidate analysis, and migration strategy
- Expert understanding of OAuth 2.0/2.1, OIDC, SAML, SCIM, JWT, mTLS, token exchange, PKCE, and FIDO2/WebAuthn, including their common implementation failure modes
- Deep experience with workforce and customer identity platforms in hybrid environments (e.g., Okta, Microsoft Entra ID, Auth0, etc), Active Directory, conditional access, and passwordless authentication
- Strong cloud identity skills in AWS-primary environments: IAM policy and SCP design, permission boundaries, role assumption, and entitlements at scale
- Specialized expertise in non-human and machine identity: workload identity, secrets management, certificate lifecycle and PKI (e.g., Venafi, AWS Certificate Manager), and service mesh identity (e.g., Istio, SPIFFE)
- Working knowledge of AI and agentic identity: agent authentication patterns, delegated authority, scope minimization, MCP and AI gateway security, and frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI RMF
- Experience with IGA and PAM platforms (e.g., SailPoint, Saviynt, CyberArk): entitlement modeling, access certification, credential vaulting, and just-in-time cloud access
- Substantive understanding of OT/ICS identity, including shared operator accounts, vendor remote access, IT/OT identity separation, and IEC 62443 zone and conduit concepts
- Familiarity with identity threat detection and response , attack path analysis, and identity enforcement at edge and API layers
- Strong communication skills, including the ability to translate technical concepts for executives and defend architectural positions with evidence
We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, protected veteran status or any other protected characteristic under federal, state, or local law. We are proud to be an equal opportunity workplace.
We are committed to fostering an inclusive, accessible work environment that includes both providing reasonable accommodations to individuals with disabilities during the application and hiring process as well as throughout the course of one's employment, should you need a reasonable accommodation during the application and selection process, including, but not limited to use of our website, any part of the application, interview or hiring process, please advise us so that we can provide appropriate assistance.
Similar Jobs at Grainger
eCommerce • Information Technology • Retail • Industrial
Leads architecture, design, implementation, and evolution of scalable backend services and APIs for customer address data. Drives technical strategy, distributed systems standards, observability, reliability, incident response, and performance optimization. Partners across engineering, product, architecture, and business teams; establishes reusable platforms and engineering practices; mentors engineers; leads design and code reviews; and contributes hands-on to complex enterprise solutions.
Top Skills:
APIsAsynchronous MessagingContainersDatadogDistributed SystemsEvent-Driven SystemsInfrastructure AutomationJavaKafkaKubernetesMicroservicesObservability PlatformsPostgresRedisSlosSnowflakeSpring Boot
eCommerce • Information Technology • Retail • Industrial
Design, develop, test, deploy, and support scalable software services, APIs, and event-streaming applications using Java and Spring Boot. Collaborate with engineers, architects, analysts, stakeholders, and product managers on technical solutions. Apply CI/CD and engineering best practices, participate in pair programming and TDD, and mentor junior engineers while supporting full systems lifecycle delivery.
Top Skills:
Agile/ScrumAPIsCi/CdDatadogDevOpsDistributed SystemsJavaKafkaMongoDBPostgresSpring BootTddTerraform
eCommerce • Information Technology • Retail • Industrial
Manage a portfolio of national account agreements, ensuring contract compliance, profitable growth, customer performance, pricing, billing, and program adoption. Negotiate contract changes, recommend renewals or expansions, advise internal partners, coach sales teams, and monitor customer commitments. The role requires a bachelor's degree, at least three years of structured value-proposition sales experience, strong virtual selling skills, project management capabilities, and approximately 30% travel.
What you need to know about the San Francisco Tech Scene
San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.
Key Facts About San Francisco Tech
- Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Google, Apple, Salesforce, Meta
- Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
- Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
- Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
- Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

