WW Grainger

Security Architect, Identity and Access Management

WW Grainger$135K — $225K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Deep expertise in enterprise identity architectures for large organizations with a strategic focus rather than just administration.
  • 10+ years in information security or identity engineering, including 8+ years in security architecture with a focus on identity.
  • Preferred Bachelor's degree or equivalent professional experience.
  • Preferred certifications include CISSP, CCSP, SABSA, and vendor-specific identity certifications.
  • Proven ability to align technology and business stakeholders on long-term identity strategies amidst competing priorities.
  • Experience in rationalizing overlapping identity portfolios and developing migration strategies.
  • Expertise in OAuth 2.0/2.1, OIDC, and SAML protocols, along with understanding their common implementation failures.

Responsibilities

  • Own the enterprise identity security architecture and develop a multi-year strategy.
  • Translate business context into identity requirements and investment priorities with leaders.
  • Lead identity technology rationalization, including capability mapping and platform selection.
  • Serve as the identity design authority within Grainger's architecture governance process.
  • Produce reference architectures and reusable authentication and authorization patterns.
  • Architect non-human identity management at scale across various environments.
  • Define authentication and authorization strategies for AI systems and operational technology.

Benefits

  • Medical, dental, vision, and life insurance plans starting on day one.
  • 18 paid time off (PTO) days per year plus 6 company holidays.
  • 6% company contribution to a 401(k) with no employee contribution required.
  • Employee discounts, tuition reimbursement, and access to financial counseling.
  • Maternity support programs and up to 14 weeks paid leave for birth parents.
Full Job Description
Work Location Type: Remote

Req Number 334336

Compensation

The anticipated base pay compensation range for this position is $135,400.00 - $225,600.00. This role is eligible for an incentive target of up to 20% or $, based on the achievement of individual and company performance objectives in accordance with the current terms of the incentive program which are subject to change.

This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.

Rewards and Benefits

With benefits starting on day one, our programs provide choice and flexibility to meet team members' individual needs, including:
  • Medical, dental, vision, and life insurance plans with coverage starting on day one of employment and 6 free sessions each year with a licensed therapist to support your emotional wellbeing.
  • 18 paid time off (PTO) days annually for full-time employees (accrual prorated based on employment start date) and 6 company holidays per year.
  • 6% company contribution to a 401(k) Retirement Savings Plan each pay period, no employee contribution required.
  • Employee discounts, tuition reimbursement, student loan refinancing and free access to financial counseling, education, and tools.
  • Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents.


For additional information and details regarding Grainger's benefits, please click on the link below:

https://experience100.ehr.com/grainger/Home/Tools-Resources/Key-Resources/New-Hire

Grainger Benefits

The pay range provided above is not a guarantee of compensation. The range reflects the potential base pay for this role at the time of this posting based on the job grade for this position. Individual base pay compensation will depend, in part, on factors such as geographic work location and relevant experience and skills.

The anticipated compensation range described above is subject to change and the compensation ultimately paid may be higher or lower than the range described above.

Grainger reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion at any time, consistent with applicable law.

Position Details

The Information Security team protects all of Grainger, from our systems to our data across the global company. Our infrastructure is powered by cloud, on-premises, and SaaS platforms that keep Grainger, and our customers, working. We use modern tools and practices to stay ahead of evolving security challenges.

The mission of the Security Architecture team is to be the strategic security design partner for Grainger's technology systems. As the security architect responsible for Grainger's identity ecosystem, you will be responsible for architecting, advising on, and governing how every human, machine, workload, and AI agent authenticates and is authorized across our cloud, SaaS, on-premises, and operational technology environments. This role owns the architecture spanning workforce identity, customer identity, privileged access, non-human and machine identity, secrets, and certificate lifecycle management.

Grainger's identity landscape is broad: hybrid workforce directory and federation services, a distinct customer identity estate supporting global eCommerce, a rapidly expanding population of workload and machine identities across cloud and SaaS, an emerging portfolio of AI and agentic platforms, and a substantial operational technology footprint.

You will support the progressive needs of the business and provide timely, secure and cost-efficient solutions that elevate the company's identity security strategy. You will identity security architect will set multi-year identity strategy and reference architecture, rationalize a broad and overlapping portfolio of identity technologies into a defensible target state, and build the stakeholder alignment required to execute it. Success here depends as much on understanding why the business operates the way it does as on the depth of the technical design. You will be expected to translate business context into identity requirements and identity risk into business impact.

In this individual contributor role, you will report to the Director of Cybersecurity Architecture and may be based remotely or at our offices in the Chicago area.

This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.

You will

  • Own the enterprise identity security architecture and multi-year strategy across workforce, customer, third-party, privileged, machine, workload, and AI agent identities, spanning cloud, SaaS, on-premises, and OT

  • Translate business context into identity requirements, sequencing, and investment priorities in partnership with various business leaders

  • Lead identity technology rationalization: capability mapping, target-state platform selection, consolidation and retirement options, and proof-of-value evaluations

  • Serve as the identity design authority in Grainger's architecture governance process, engaging early enough to shape design decisions

  • Produce reference architectures and reusable authentication, authorization, federation, and entitlement patterns, and threat model identity designs with delivery teams

  • Architect non-human identity at scale across issuance, attestation, rotation, and decommissioning

  • Define authentication and authorization for AI and agentic systems, including OAuth 2.0/2.1 flows, token exchange, delegated authority, short-lived credentials, and identity enforcement at MCP and AI gateways


  • Partner with machine learning and platform engineering on agent identity, agent-to-agent authorization, and downstream data access as AI moves into production

  • Set the target architecture for OT/ICS identity, including IT/OT identity separation and vendor remote access under known OT/ICS constraints

  • Advance customer identity architecture for digital commerce, including federation, authorization models, token security, and migration off legacy identity solutions

  • Define privileged access and cryptographic identity architecture, advancing just-in-time and zero standing privilege, certificate lifecycle automation, mTLS, and secrets management

  • Develop and enforce identity security standards and baselines aligned to NIST SP 800-63, NIST SP 800-207, NIST CSF, CIS Benchmarks, and IEC 62443

  • Partner with detection and response teams on identity threat detection coverage, attack path mapping, and identity telemetry into the SIEM/SOAR platform

  • Communicate identity posture and program progress to leadership through relevant metrics and KPIs

  • Mentor peers and junior architects through design reviews, pattern development, and knowledge sharing


You have

  • Deep expertise designing enterprise identity architectures for large, complex organizations, with ownership of the strategy and target state rather than platform administration or technology engineering

  • 10+ years in information security or identity engineering, including 8+ years in security architecture with at least 6 years focused on identity

  • Bachelor's degree preferred; equivalent professional experience accepted

  • Preferred certifications: CISSP, CCSP, SABSA, IDPro CIDPRO, or vendor identity certifications

  • Proven ability to align senior technology and business stakeholders behind multi-year identity direction amid competing priorities

  • Experience rationalizing overlapping identity portfolios: capability mapping, build/buy/consolidate analysis, and migration strategy

  • Expert understanding of OAuth 2.0/2.1, OIDC, SAML, SCIM, JWT, mTLS, token exchange, PKCE, and FIDO2/WebAuthn, including their common implementation failure modes

  • Deep experience with workforce and customer identity platforms in hybrid environments (e.g., Okta, Microsoft Entra ID, Auth0, etc), Active Directory, conditional access, and passwordless authentication

  • Strong cloud identity skills in AWS-primary environments: IAM policy and SCP design, permission boundaries, role assumption, and entitlements at scale

  • Specialized expertise in non-human and machine identity: workload identity, secrets management, certificate lifecycle and PKI (e.g., Venafi, AWS Certificate Manager), and service mesh identity (e.g., Istio, SPIFFE)

  • Working knowledge of AI and agentic identity: agent authentication patterns, delegated authority, scope minimization, MCP and AI gateway security, and frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI RMF


  • Experience with IGA and PAM platforms (e.g., SailPoint, Saviynt, CyberArk): entitlement modeling, access certification, credential vaulting, and just-in-time cloud access

  • Substantive understanding of OT/ICS identity, including shared operator accounts, vendor remote access, IT/OT identity separation, and IEC 62443 zone and conduit concepts

  • Familiarity with identity threat detection and response , attack path analysis, and identity enforcement at edge and API layers

  • Strong communication skills, including the ability to translate technical concepts for executives and defend architectural positions with evidence

}

About WW Grainger

W.W. Grainger (NYSE: GWW), with 2008 sales of $6.9 billion, is the leading broad-line supplier of facilities maintenance products serving businesses and institutions in the United States, Canada, Mexico, China, India and Panama. Through a highly integrated network including nearly 600 branches, 18 distribution centers and multiple Web sites, Grainger's employees help customers get the job done, saving them time and money by having the right products to keep their facilities running.

WW Grainger Careers

Join the dynamic team at WW Grainger, a leading broad line supplier of maintenance, repair, and operating products, where job opportunities abound in an environment ripe with innovation and leadership. At WW Grainger, we are committed to fostering an inclusive culture that values diversity and encourages professional growth through comprehensive diversity training and leadership development.

Work You’ll Do

At WW Grainger, you’ll be part of a robust team that’s dedicated to excellence. Whether you’re looking to start your career through our internship programs or seeking to advance as a seasoned professional, WW Grainger offers a path filled with opportunities for growth and learning. Our team members are equipped with the skills needed to lead industries and drive innovation at every level of the company.

Explore Job Opportunities and Employment

WW Grainger is not just hiring; we are building a future. Explore the numerous job opportunities across various departments where you can put your skills to test and contribute to our mission. From positions in supply chain management to customer service, technology to sales, WW Grainger seeks passionate, curious, and solution-driven team players.

Innovate and Lead

Join a company where innovation is at the core of our business strategy. WW Grainger’s leadership in the industry is enhanced by our commitment to innovation and continuous improvement. Our employees are encouraged to think big and act boldly, driving change that influences the entire market.

Career Development and Benefits

Invest in your future with WW Grainger’s unmatched career development programs. Go as far as your ambition takes you with near-limitless opportunities to advance your career supported by extensive training, development, and certification support. Enjoy a comprehensive benefits package that supports the health, well-being, and financial security of our employees and their families.

Internship Programs and Entry-Level Positions

Kickstart your career with WW Grainger through our internship programs or entry-level positions. Gain hands-on experience, build your resume, and make invaluable networking connections that will pave the way for a successful career. Our internships provide a unique insight into the workings of a major company and serve as a gateway to full-time employment.

Join Our Team

Search open positions that match your skills and interests. We look for individuals who are eager to drive their own career path while contributing to a team that values hard work and creativity.

Stay Connected

Keep up to date with career tips, insider perspectives, and industry-leading insights you can put to use today—all from the people who work here. Personalize your subscription to receive job alerts, latest news, and insider tips tailored to your preferences. Discover the exciting and rewarding opportunities that await at WW Grainger.

Interview and Resume Tips

Prepare for your interview at WW Grainger with resources that help you stand out. Learn what we look for in potential hires and how to effectively highlight your experiences and skills on your resume. At WW Grainger, we are more than a company—we are a community. We are dedicated to maintaining an environment where every team member feels valued and has the opportunity to excel. Join us in our mission to help professionals keep their operations running and their people safe.
Learn more about WW Grainger
Size
22,700 employees
Market Cap
$28.3 billion
Industry
Net Income
$695 million
Founded
1927
5 Year Trend
+5.1%
Revenue
$11.7 billion
NASDAQ

Similar Jobs

More Jobs at WW Grainger

More Information Technology Jobs

Find similar Security Architect, Identity and Access Management jobs: