Security Architect, Identity and Access Management
$135.4k - $225.6kW.W. Grainger Corporate Office
Work Location Type: RemoteWork Location Type: RemoteReq Number 334336 About Grainger W.W. Grainger, Inc. is a leading broad line distributor with operations primarily in North America and Japan. At Grainger, We Keep the World Working by serving more than 4.6 million customers worldwide with maintenance, repair and operating (MRO) products and value-added solutions delivered through innovative technology and deep customer expertise. Known for its commitment to service and purpose-driven culture, the Company reported 2025 revenue of $17.9 billion. For more information, visit Compensation The anticipated base pay compensation range for this position is $135,400.00 – $225,600.00. This role is eligible for an incentive target of up to 20% or $, based on the achievement of individual and company performance objectives in accordance with the current terms of the incentive program which are subject to change. This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position. Rewards and Benefits With benefits starting on day one, our programs provide choice and flexibility to meet team members' individual needs, including: Medical, dental, vision, and life insurance plans with coverage starting on day one of employment and 6 free sessions each year with a licensed therapist to support your emotional wellbeing. 18 paid time off (PTO) days annually for full-time employees (accrual prorated based on employment start date) and 6 company holidays per year. 6% company contribution to a 401(k) Retirement Savings Plan each pay period, no employee contribution required. Employee discounts, tuition reimbursement, student loan refinancing and free access to financial counseling, education, and tools. Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents. For additional information and details regarding Grainger’s benefits, please click on the link below: Grainger Benefits The pay range provided above is not a guarantee of compensation. The range reflects the potential base pay for this role at the time of this posting based on the job grade for this position. Individual base pay compensation will depend, in part, on factors such as geographic work location and relevant experience and skills. The anticipated compensation range described above is subject to change and the compensation ultimately paid may be higher or lower than the range described above. Grainger reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion at any time, consistent with applicable law. Position Details The Information Security team protects all of Grainger, from our systems to our data across the global company. Our infrastructure is powered by cloud, on-premises, and SaaS platforms that keep Grainger, and our customers, working. We use modern tools and practices to stay ahead of evolving security challenges. The mission of the Security Architecture team is to be the strategic security design partner for Grainger’s technology systems. As the security architect responsible for Grainger’s identity ecosystem, you will be responsible for architecting, advising on, and governing how every human, machine, workload, and AI agent authenticates and is authorized across our cloud, SaaS, on-premises, and operational technology environments. This role owns the architecture spanning workforce identity, customer identity, privileged access, non-human and machine identity, secrets, and certificate lifecycle management. Grainger’s identity landscape is broad: hybrid workforce directory and federation services, a distinct customer identity estate supporting global eCommerce, a rapidly expanding population of workload and machine identities across cloud and SaaS, an emerging portfolio of AI and agentic platforms, and a substantial operational technology footprint. You will support the progressive needs of the business and provide timely, secure and cost-efficient solutions that elevate the company’s identity security strategy. You will identity security architect will set multi-year identity strategy and reference architecture, rationalize a broad and overlapping portfolio of identity technologies into a defensible target state, and build the stakeholder alignment required to execute it. Success here depends as much on understanding why the business operates the way it does as on the depth of the technical design. You will be expected to translate business context into identity requirements and identity risk into business impact. In this individual contributor role, you will report to the Director of Cybersecurity Architecture and may be based remotely or at our offices in the Chicago area. This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position. You will Own the enterprise identity security architecture and multi-year strategy across workforce, customer, third-party, privileged, machine, workload, and AI agent identities, spanning cloud, SaaS, on-premises, and OT Translate business context into identity requirements, sequencing, and investment priorities in partnership with various business leaders Lead identity technology rationalization: capability mapping, target-state platform selection, consolidation and retirement options, and proof-of-value evaluations Serve as the identity design authority in Grainger’s architecture governance process, engaging early enough to shape design decisions Produce reference architectures and reusable authentication, authorization, federation, and entitlement patterns, and threat model identity designs with delivery teams Architect non-human identity at scale across issuance, attestation, rotation, and decommissioning Define authentication and authorization for AI and agentic systems, including OAuth 2.0/2.1 flows, token exchange, delegated authority, short-lived credentials, and identity enforcement at MCP and AI gateways Partner with machine learning and platform engineering on agent identity, agent-to-agent authorization, and downstream data access as AI moves into production Set the target architecture for OT/ICS identity, including IT/OT identity separation and vendor remote access under known OT/ICS constraints Advance customer identity architecture for digital commerce, including federation, authorization models, token security, and migration off legacy identity solutions Define privileged access and cryptographic identity architecture, advancing just-in-time and zero standing privilege, certificate lifecycle automation, mTLS, and secrets management Develop and enforce identity security standards and baselines aligned to NIST SP 800-63, NIST SP 800-207, NIST CSF, CIS Benchmarks, and IEC 62443 Partner with detection and response teams on identity threat detection coverage, attack path mapping, and identity telemetry into the SIEM/SOAR platform Communicate identity posture and program progress to leadership through relevant metrics and KPIs Mentor peers and junior architects through design reviews, pattern development, and knowledge sharing You have Deep expertise designing enterprise identity architectures for large, complex organizations, with ownership of the strategy and target state rather than platform administration or technology engineering 10+ years in information security or identity engineering, including 8+ years in security architecture with at least 6 years focused on identity Bachelor’s degree preferred; equivalent professional experience accepted Preferred certifications: CISSP, CCSP, SABSA, IDPro CIDPRO, or vendor identity certifications Proven ability to align senior technology and business stakeholders behind multi-year identity direction amid competing priorities Experience rationalizing overlapping identity portfolios: capability mapping, build/buy/consolidate analysis, and migration strategy Expert understanding of OAuth 2.0/2.1, OIDC, SAML, SCIM, JWT, mTLS, token exchange, PKCE, and FIDO2/WebAuthn, including their common implementation failure modes Deep experience with workforce and customer identity platforms in hybrid environments (e.g., Okta, Microsoft Entra ID, Auth0, etc), Active Directory, conditional access, and passwordless authentication Strong cloud identity skills in AWS-primary environments: IAM policy and SCP design, permission boundaries, role assumption, and entitlements at scale Specialized expertise in non-human and machine identity: workload identity, secrets management, certificate lifecycle and PKI (e.g., Venafi, AWS Certificate Manager), and service mesh identity (e.g., Istio, SPIFFE) Working knowledge of AI and agentic identity: agent authentication patterns, delegated authority, scope minimization, MCP and AI gateway security, and frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI RMF Experience with IGA and PAM platforms (e.g., SailPoint, Saviynt, CyberArk): entitlement modeling, access certification, credential vaulting, and just-in-time cloud access Substantive understanding of OT/ICS identity, including shared operator accounts, vendor remote access, IT/OT identity separation, and IEC 62443 zone and conduit concepts Familiarity with identity threat detection and response , attack path analysis, and identity enforcement at edge and API layers Strong communication skills, including the ability to translate technical concepts for executives and defend architectural positions with evidence We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, protected veteran status or any other protected characteristic under federal, state, or local law. We are proud to be an equal opportunity workplace.We are committed to fostering an inclusive, accessible work environment that includes both providing reasonable accommodations to individuals with disabilities during the application and hiring process as well as throughout the course of one’s employment, should you need a reasonable accommodation during the application and selection process, including, but not limited to use of our website, any part of the application, interview or hiring process, please advise us so that we can provide appropriate assistance.
$135.4k - $225.6k
...loan refinancing and free access to financial counseling,... ...Details The Information Security team protects all of... ...systems. As the security architect responsible for Grainger’s identity ecosystem, you will be responsible... ...certificate lifecycle management. Grainger’s identity...SuggestedFull timeH1bLocal areaRemote workWorldwide- ...The Application & Platform Security Architect is a member of the Information... ...-level risks, session management, securing configuration files... ...CD. Advanced knowledge of Identity Security concepts, least-privilege... ..., incident management, access control, application vulnerability...SuggestedWork experience placementWork at office
$125k
...delivers end-to-end IT services across Managed Services, Cloud, Cyber Security, Audio-Visual, Physical Security... ...skilled Cyber Security Solutions Architect to design and implement robust... ...or GCP). ~ Strong knowledge of identity and access management, encryption, PKI,...SuggestedPermanent employment- ...Senior IT Security Engineer Corporate Headquarters 12575 Uline... ...the U.S. From designing and managing security solutions, to guiding... ...Responsibilities Partner with architects, developers and leadership to... ...with a focus on user access that ensures network safety....Suggested
- ...Senior IT Security Engineer Corporate Headquarters 12575 Uline... ...the U.S. From designing and managing security solutions, to guiding... ...Responsibilities Partner with architects, developers and leadership to... ...with a focus on user access that ensures network safety....Suggested
$90 - $110 per hour
...Description* The AI Enterprise Architect is responsible for... ...AI engineering, data, security, cloud platforms,... ...reasoning, memory, state management, delegation, and human... ...enterprise knowledge access. Define patterns for... ...enterprise cloud, data, identity, security, integration...Contract workTemporary work- Senior IT Security EngineerCorporate Headquarters12575 Uline Drive,... ...the U.S. From designing and managing security solutions, to guiding... ...Responsibilities Partner with architects, developers and leadership to... ...with a focus on user access that ensures network safety.Manage...Full time
$141.5k
...team that develops AI agents to solve hard security problems -- and you will be tackling the... ...is a hands-on, senior IC role. You will architect, build, and ship agentic AI systems that... ..., tested, and secured. This is not a management role and not a pure research role. You...Local area- ...an experienced Senior Cyber Security Engineer to join the Walgreens... ..., develops solutions to data access, modification, disclosure, destruction... ...languages and security management suites, penetration testing... ...with security engineering, identity engineering security applications...Hourly payRemote work
$122.8k - $184.2k
...teams to design and implement security controls, defenses, and... ...perimeter controls, Zero Trust access patterns, design recommendations... ...segmentation, secure connectivity, and identity-based access approaches for... ...to technical teams, management stakeholders, and security leadership...Full timeSummer workLocal areaFlexible hours- ...Instagram , X and YouTube. Job Description The Data Domain Architect, Operations and Finance is responsible for defining and... ...relevant. ~ Ensure solutions align with enterprise standards, security, governance, compliance, and architectural guardrails. ~...Full timeLocal area
- ...with an inclusive and collaborative technology team. As a Senior Security Engineer – Cybersecurity Posture, Hygiene & AI Enablement in... ...in the U.S. As a member of the Information Security Risk Management (ISRM) Architecture team, the Senior Security Engineer plays a...Full timeTemporary workLocal area
- ...with an inclusive and collaborative technology team. As a Senior Security Engineer – Cybersecurity Posture, Hygiene & AI Enablement in... ...in the U.S. As a member of the Information Security Risk Management (ISRM) Architecture team, the Senior Security Engineer plays a...Temporary workLocal area
- ...Technical Architect Position Overview: Hands on technical and strategic mindset of working with the business. Most EAs were high level on strategic side but not technical enough. Ex engineers, 15-20% of time hands on coding, proof of concepts (aspirational), work on...
$75k - $90k
...days a week on-site at our Northbrook, IL Office. As a Cyber Security Engineer, you are under supervision responsible for evaluating... ...to race, color, age, sex or gender, sexual orientation, gender identity, gender expression, transgender status, religion, creed, national...Full timeWork at office3 days per week- ...Facebook , Instagram , X and YouTube. Job Description We are building a team that develops AI agents to solve real security problems -- detection, triage, response, risk assessment, and policy enforcement. This is a hands-on engineering role. You will design...Full timeLocal area
- Security Engineer The Security Engineer is expected to perform a combination of cyber security functions such as deployment, maintenance... ..., intrusion detection/prevention systems, vulnerability management, SIEM, and anti-virus software. Monitors and reports on security...Hourly payWork from homeFlexible hours
- ...Job Description Become a key player in our Information Security team as a Junior Application Security Engineer, where you will... ...Implementing and maintaining Application Security Posture Management (ASPM) tools to centralize and deduplicate findings from multiple...Full timeTemporary workLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Architect, Identity and Access Management. Be the first to apply!
- international management trainee Lake Forest, IL
- asset management intern Lake Forest, IL
- test data management Lake Forest, IL
- management team Lake Forest, IL
- entry level management training Lake Forest, IL
- management development program Lake Forest, IL
- director management consulting Lake Forest, IL
- identity & access management Lake Forest, IL
- events management graduate Lake Forest, IL
- emergency management director Lake Forest, IL


