Please mention DailyRemote when applying
Match your resume skills with our AI powered skill match!
Upload your resume and we draft a letter for this exact role, tailored to what it asks for.
The Security Architect will design and govern the enterprise identity ecosystem, covering workforce, customer, machine, and AI agent authentication. This role involves setting multi-year identity strategies, rationalizing technology portfolios, and ensuring secure access across cloud, SaaS, and operational technology environments.
Work Location Type: Remote
Req Number 334336
About Grainger
W.W. Grainger, Inc. is a leading broad line distributor with operations primarily in North America and Japan. At Grainger, We Keep the World Working® by serving more than 4.6 million customers worldwide with maintenance, repair and operating (MRO) products and value-added solutions delivered through innovative technology and deep customer expertise. Known for its commitment to service and purpose-driven culture, the Company reported 2025 revenue of $17.9 billion. For more information, visit www.grainger.com.
Compensation
The anticipated base pay compensation range for this position is $135,400.00 – $225,600.00. This role is eligible for an incentive target of up to 20% or $, based on the achievement of individual and company performance objectives in accordance with the current terms of the incentive program which are subject to change.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
Rewards and Benefits
With benefits starting on day one, our programs provide choice and flexibility to meet team members' individual needs, including:
For additional information and details regarding Grainger’s benefits, please click on the link below:
https://experience100.ehr.com/grainger/Home/Tools-Resources/Key-Resources/New-Hire
Grainger Benefits
The pay range provided above is not a guarantee of compensation. The range reflects the potential base pay for this role at the time of this posting based on the job grade for this position. Individual base pay compensation will depend, in part, on factors such as geographic work location and relevant experience and skills.
The anticipated compensation range described above is subject to change and the compensation ultimately paid may be higher or lower than the range described above.
Grainger reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion at any time, consistent with applicable law.
Position Details
The Information Security team protects all of Grainger, from our systems to our data across the global company. Our infrastructure is powered by cloud, on-premises, and SaaS platforms that keep Grainger, and our customers, working. We use modern tools and practices to stay ahead of evolving security challenges.
The mission of the Security Architecture team is to be the strategic security design partner for Grainger’s technology systems. As the security architect responsible for Grainger’s identity ecosystem, you will be responsible for architecting, advising on, and governing how every human, machine, workload, and AI agent authenticates and is authorized across our cloud, SaaS, on-premises, and operational technology environments. This role owns the architecture spanning workforce identity, customer identity, privileged access, non-human and machine identity, secrets, and certificate lifecycle management.
Grainger’s identity landscape is broad: hybrid workforce directory and federation services, a distinct customer identity estate supporting global eCommerce, a rapidly expanding population of workload and machine identities across cloud and SaaS, an emerging portfolio of AI and agentic platforms, and a substantial operational technology footprint.
You will support the progressive needs of the business and provide timely, secure and cost-efficient solutions that elevate the company’s identity security strategy. You will identity security architect will set multi-year identity strategy and reference architecture, rationalize a broad and overlapping portfolio of identity technologies into a defensible target state, and build the stakeholder alignment required to execute it. Success here depends as much on understanding why the business operates the way it does as on the depth of the technical design. You will be expected to translate business context into identity requirements and identity risk into business impact.
In this individual contributor role, you will report to the Director of Cybersecurity Architecture and may be based remotely or at our offices in the Chicago area.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
You will
Own the enterprise identity security architecture and multi-year strategy across workforce, customer, third-party, privileged, machine, workload, and AI agent identities, spanning cloud, SaaS, on-premises, and OT
Translate business context into identity requirements, sequencing, and investment priorities in partnership with various business leaders
Lead identity technology rationalization: capability mapping, target-state platform selection, consolidation and retirement options, and proof-of-value evaluations
Serve as the identity design authority in Grainger’s architecture governance process, engaging early enough to shape design decisions
Produce reference architectures and reusable authentication, authorization, federation, and entitlement patterns, and threat model identity designs with delivery teams
Architect non-human identity at scale across issuance, attestation, rotation, and decommissioning
Define authentication and authorization for AI and agentic systems, including OAuth 2.0/2.1 flows, token exchange, delegated authority, short-lived credentials, and identity enforcement at MCP and AI gateways
Partner with machine learning and platform engineering on agent identity, agent-to-agent authorization, and downstream data access as AI moves into production
Set the target architecture for OT/ICS identity, including IT/OT identity separation and vendor remote access under known OT/ICS constraints
Advance customer identity architecture for digital commerce, including federation, authorization models, token security, and migration off legacy identity solutions
Define privileged access and cryptographic identity architecture, advancing just-in-time and zero standing privilege, certificate lifecycle automation, mTLS, and secrets management
Develop and enforce identity security standards and baselines aligned to NIST SP 800-63, NIST SP 800-207, NIST CSF, CIS Benchmarks, and IEC 62443
Partner with detection and response teams on identity threat detection coverage, attack path mapping, and identity telemetry into the SIEM/SOAR platform
Communicate identity posture and program progress to leadership through relevant metrics and KPIs
Mentor peers and junior architects through design reviews, pattern development, and knowledge sharing
You have
Deep expertise designing enterprise identity architectures for large, complex organizations, with ownership of the strategy and target state rather than platform administration or technology engineering
10+ years in information security or identity engineering, including 8+ years in security architecture with at least 6 years focused on identity
Bachelor’s degree preferred; equivalent professional experience accepted
Preferred certifications: CISSP, CCSP, SABSA, IDPro CIDPRO, or vendor identity certifications
Proven ability to align senior technology and business stakeholders behind multi-year identity direction amid competing priorities
Experience rationalizing overlapping identity portfolios: capability mapping, build/buy/consolidate analysis, and migration strategy
Expert understanding of OAuth 2.0/2.1, OIDC, SAML, SCIM, JWT, mTLS, token exchange, PKCE, and FIDO2/WebAuthn, including their common implementation failure modes
Deep experience with workforce and customer identity platforms in hybrid environments (e.g., Okta, Microsoft Entra ID, Auth0, etc), Active Directory, conditional access, and passwordless authentication
Strong cloud identity skills in AWS-primary environments: IAM policy and SCP design, permission boundaries, role assumption, and entitlements at scale
Specialized expertise in non-human and machine identity: workload identity, secrets management, certificate lifecycle and PKI (e.g., Venafi, AWS Certificate Manager), and service mesh identity (e.g., Istio, SPIFFE)
Working knowledge of AI and agentic identity: agent authentication patterns, delegated authority, scope minimization, MCP and AI gateway security, and frameworks such as the OWASP Top 10 for LLM Applications, MITRE ATLAS, and the NIST AI RMF
Experience with IGA and PAM platforms (e.g., SailPoint, Saviynt, CyberArk): entitlement modeling, access certification, credential vaulting, and just-in-time cloud access
Substantive understanding of OT/ICS identity, including shared operator accounts, vendor remote access, IT/OT identity separation, and IEC 62443 zone and conduit concepts
Familiarity with identity threat detection and response , attack path analysis, and identity enforcement at edge and API layers
Strong communication skills, including the ability to translate technical concepts for executives and defend architectural positions with evidence
We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, protected veteran status or any other protected characteristic under federal, state, or local law. We are proud to be an equal opportunity workplace.
We are committed to fostering an inclusive, accessible work environment that includes both providing reasonable accommodations to individuals with disabilities during the application and hiring process as well as throughout the course of one’s employment, should you need a reasonable accommodation during the application and selection process, including, but not limited to use of our website, any part of the application, interview or hiring process, please advise us so that we can provide appropriate assistance.
Stop the endless job search. Our AI finds and applies to the best jobs for you.
Featuring 217,613+ Jobs in Security Architect
Answer easy questions
217,613+ jobs across 15+ categories
Get your best job matches
Only hand-screened, legit jobs
Find a remote job faster
No ads, scams, or junk
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”