Skip to content

Open nowPosted 78 days ago

Director, Identity Security

Ecolab32 open roles

Pay
$137,400 – $206,200 a year
Where
USA Minnesota Saint Paul
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector, Identity SecurityEcolab · USA Minnesota Saint Paul
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Ecolab's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Ecolab postings stay open a median of 1 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 78 days ago

Ecolab median: 1 days open

The posting

Job Summary: The Director of Identity is responsible for maturing the enterprise Identity and Access Management (IAM) program across strategy, engineering, operations, architecture, and emerging identity security capabilities. This role provides leadership for a global IAM function supporting a large-scale internal and external identity environment and is accountable for advancing identity governance, privileged access, authentication, lifecycle management, and secrets and cryptography capabilities in alignment with business, risk, and compliance requirements.

The role combines strategic direction, operational accountability, organizational leadership, and program execution. The Director of Identity will lead mature identity services while driving transformation initiatives such as IAM governance maturation, role-based access control, PAM modernization, passwordless authentication, certificate lifecycle automation, and enterprise secrets management.

What You Will Do:

Strategy, Governance, and Leadership

  • Define and own the enterprise IAM strategy, roadmap, and operating model aligned to cybersecurity, compliance, and business objectives.
  • Mature the IAM program through formal governance, policies, standards, controls, metrics, and leadership reporting.
  • Present IAM program status, risks, priorities, and investment needs to security leadership and executive stakeholders.
  • Lead prioritization decisions across operations, platform engineering, architecture, and project-based identity initiatives.
  • Establish and monitor KPIs, service performance, maturity goals, and program outcomes.

IAM Program Delivery

  • Lead delivery of enterprise IAM capabilities including identity lifecycle management, joiner/mover/leaver processes, access provisioning, access requests, access reviews, privileged access, authentication, federation, and directory services.
  • Oversee transformation initiatives such as IGA expansion, RBAC governance, PAM modernization, passwordless authentication, and identity security posture improvements.
  • Ensure IAM services meet operational expectations for reliability, resilience, scalability, and user support.
  • Partner with application, infrastructure, cloud, HR, audit, and security teams to implement identity controls and integration patterns across the enterprise.

Compliance, Risk, and Control Effectiveness

  • Ensure IAM processes and controls support audit, regulatory, and internal compliance requirements, including SOX-related controls where applicable.
  • Oversee audit readiness, remediation activities, control evidence, and policy enforcement across identity-related processes.
  • Align identity capabilities to recognized frameworks and standards such as NIST CSF 2.0, NIST 800-63, and enterprise security policies.
  • Reduce identity-related risk by strengthening governance, control automation, privileged access protections, and secrets management practices.

Architecture and Emerging Identity Security Capabilities

  • Provide leadership across identity architecture, platform standards, and integration patterns for workforce, privileged, and customer identity environments.
  • Lead the development of enterprise secrets and cryptography capabilities, including certificate lifecycle management, PKI modernization, vault strategy, and operational controls.
  • Support modern identity approaches across hybrid and cloud environments, including federation, conditional access, and non-human/service identity considerations.
  • Drive decisions on tooling, architectural direction, and strategic vendor partnerships that improve security, scalability, and operational efficiency.

Organizational and People Leadership

  • Lead and develop a distributed IAM organization consisting of managers, architects, engineers, and operations personnel.
  • Build organizational clarity across operations, engineering, architecture, and new capability areas.
  • Provide leadership in talent development, succession planning, coaching, performance management, and team engagement.
  • Manage staffing strategy across full-time employees, partners, and contingent resources to meet delivery needs.
  • Oversee third-party vendors and consulting partners supporting IAM programs and services.

Minimum Qualifications:

  • Bachelor's degree in Information Technology, Information Security, Computer Science, Engineering, or a related discipline; equivalent experience may be considered.
  • 12+ years of progressive experience in Identity and Access Management, cybersecurity, or security engineering.
  • 5+ years of leadership experience managing multi-team IAM functions at the Senior Manager or Director level.
  • Demonstrated success leading enterprise IAM programs across strategy, operations, engineering, governance, and transformation initiatives.
  • Experience owning IAM governance, policy development, audit response, executive reporting, and control maturity efforts.
  • Experience building or standing up new security capabilities, teams, or services.

Technical and Functional Qualifications:

  • Strong knowledge of Identity Governance and Administration platforms; Saviynt preferred. Experience with SailPoint or One Identity is also relevant.
  • Strong knowledge of Privileged Access Management concepts and platforms; BeyondTrust preferred, with CyberArk or Delinea also relevant.
  • Experience with Microsoft identity services including Active Directory, Entra ID, B2C, federation, and conditional access.
  • Knowledge of authentication and federation standards such as SAML, OAuth 2.0, and OpenID Connect.
  • Understanding of hybrid and cloud IAM patterns across Azure, AWS, and GCP environments.
  • Knowledge of secrets management, PKI, certificate lifecycle management, and key management technologies such as HashiCorp Vault or Azure Key Vault.
  • Familiarity with IAM maturity frameworks, security governance models, and regulatory or control expectations.

Preferred Qualifications

  • Experience in a Fortune 500, global, manufacturing, or industrial environment.
  • Experience with SOX-related IAM controls and certification processes.
  • Experience with ServiceNow-based access workflows and Workday-driven provisioning processes.
  • Relevant certifications such as CISSP, CISM, or identity-platform specific certifications.

Leadership Competencies

  • Strategic thinker with the ability to set direction and translate strategy into execution.
  • Strong decision-maker who operates effectively in complex, matrixed environments.
  • Delivery-oriented leader with a strong focus on accountability, outcomes, and service quality.
  • Effective communicator able to translate complex identity and security topics for executives, audit stakeholders, and technical teams.
  • Strong collaborator with the ability to influence across cybersecurity, infrastructure, cloud, HR, audit, and application teams.
  • Proven people leader with the ability to coach talent, build teams, and develop future leaders.

Additional Information

The role may require coordination across global teams, including off-hours support for key initiatives, escalations, or major incidents.

Annual or Hourly Compensation Range

The base salary range for this position is $137,400.00 - $206,200.00. This position is eligible for annual bonus and long-term incentives based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.

Benefits

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. Click here to see our benefits.

If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.

Potential Customer Requirements Notice

To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:

- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.

Americans with Disabilities Act (ADA)

Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Ecolab's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Ecolab's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Ecolab's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.