Skip to content

Open nowPosted 78 days ago

Director of Security Engineering

Ecolab32 open roles

Pay
$137,400 – $206,200 a year
Where
USA Minnesota Saint Paul
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowDirector of Security EngineeringEcolab · USA Minnesota Saint Paul
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Ecolab's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Ecolab postings stay open a median of 1 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.5%3 days
  3. 7.8%7 days
  4. 14.6%14 days
  5. 34.0%30 days
This job: posted 78 days ago

Ecolab median: 1 days open

The posting

Job Summary: The Director of Security Engineering is responsible for leading enterprise security architecture, engineering, and exposure management programs. This role provides leadership for the technical security posture of a global Fortune 500 environment, owning the proactive side of security: architecture decisions, platform engineering, security standards enforcement, vulnerability and exposure management, and the initiatives that harden the environment before threats land.

The Director of Security Engineering leads architecture and engineering teams across endpoint, cloud, network, data protection, collaboration, and OT security while building a new Continuous Threat Exposure Management (CTEM) capability. The role combines strategic direction, platform and tooling decisions, cross-functional initiative delivery, and organizational leadership to drive measurable posture improvement across the enterprise.

What You Will Do:

Technical Security Posture and Architecture

  • Own security architecture standards, benchmarks, and compliance posture for the enterprise aligned to CIS Benchmarks, NIST CSF 2.0, and platform hardening requirements.
  • Make platform and tooling decisions across the security technology stack including endpoint, cloud, network, data protection, and collaboration security.
  • Lead security solution selection, evaluation, and implementation for new capabilities across multi-cloud, on-premises, and OT environments.
  • Guide zero-trust architecture implementation including network segmentation, conditional access enforcement, and least-privilege design patterns.
  • Drive security configuration standards and compliance across Azure, AWS, GCP, on-premises infrastructure, and industrial control system environments.

Exposure Management and CTEM

  • Stand up and operationalize the Continuous Threat Exposure Management function, directing a team of exposure analysts across infrastructure, cloud, application, and external attack surface domains.
  • Define and operationalize the CTEM cycle: discovery, prioritization (exploitability-weighted), mobilization, validation, and remediation tracking.
  • Establish and enforce vulnerability remediation SLAs with infrastructure, platform, and application teams across the enterprise.
  • Build executive-facing exposure reporting and risk quantification tied to business outcomes.
  • Drive convergence of vulnerability scanning, cloud security posture management, and attack surface management into a unified exposure view.

Engineering Operations and Platform Management

  • Oversee day-to-day security engineering including platform maintenance, incident support, approval workflows, and operational stability across the security tooling portfolio.
  • Manage the solution review and re-attestation process for enterprise technology including vendor evaluations and M&A security assessments.
  • Drive automation of manual security processes including approvals, compliance checks, and configuration auditing.
  • Partner with Observability and Automation teams on SIEM integration, security automation playbooks, and compliance dashboards.
  • Translate governance and compliance requirements from GRC into implemented technical controls, deploying and configuring security platforms to monitor and enforce policy compliance across the enterprise.
  • Oversee OT security assessments across global manufacturing sites, ensure regulatory compliance (NIS2, CFATS), and drive network segmentation programs for industrial environments.

Initiative Delivery and Cross-Functional Leadership

  • Organize and prioritize work across multiple concurrent workstreams spanning endpoint hardening, cloud exposure remediation, network benchmarking, data protection, and OT security.
  • Use modern tools including AI assistants (Claude, Copilot) to accelerate planning, analysis, documentation, and decision-making across the team.
  • Present program status, roadmaps, and investment cases to executive leadership with clarity and confidence.
  • Drive cross-functional initiatives requiring coordination across infrastructure, networking, cloud platforms, and application teams.

Organizational and People Leadership

  • Lead and develop a distributed security organization consisting of managers, architects, and engineers across multiple technical domains.
  • Build organizational clarity across architecture, engineering, and the new exposure management function.
  • Provide leadership in talent development, succession planning, coaching, performance management, and team engagement.
  • Manage staffing strategy across full-time employees, partners, and contingent resources to meet delivery needs.
  • Oversee third-party vendors and consulting partners supporting security programs and services.

Minimum Qualifications:

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline; equivalent experience may be considered.
  • 12+ years of progressive experience in cybersecurity, security architecture, security engineering, or vulnerability management.
  • 5+ years of leadership experience managing multi-team security functions at the Senior Manager or Director level.
  • Demonstrated success delivering security initiatives through teams: hardening programs, platform deployments, and posture improvements completed on schedule.
  • Experience managing 15+ person organizations including managers, architects, and engineers with varied technical specializations.
  • Experience building new functions or teams, particularly in exposure management, vulnerability operations, or CTEM disciplines.
  • Background in cross-functional program delivery, driving remediation and compliance outcomes through teams not under direct reporting authority.

Technical and Functional Qualifications:

  • Strong knowledge of cloud security architecture across Azure, AWS, and GCP including CSPM/CNAPP platforms, container security, and cloud-native controls.
  • Strong knowledge of network security including next-generation firewalls, secure web gateways, network segmentation, DNS security, and zero-trust network access.
  • Experience with endpoint security platforms (EDR), endpoint hardening, and CIS benchmark implementation at enterprise scale.
  • Knowledge of data protection platforms (DLP), data classification, insider threat programs, and unstructured data controls.
  • Strong knowledge of vulnerability and exposure management: scanning platforms, CTEM frameworks, attack surface management, exposure prioritization, and remediation SLA governance. Qualys experience strongly preferred.
  • Knowledge of OT/ICS security including network segmentation for industrial environments, asset discovery, and regulatory frameworks (NIS2).
  • Familiarity with security architecture frameworks: CIS Benchmarks (multi-platform), NIST CSF 2.0, and zero-trust architecture principles.
  • Comfort with security automation platforms (SOAR) and AI-assisted workflows for accelerating team productivity and decision-making.

Preferred Qualifications:

  • Experience in a Fortune 500, global, manufacturing, or industrial environment with complex, heterogeneous technology estates.
  • Prior experience standing up a CTEM, exposure management, or vulnerability operations function.
  • Familiarity with M&A security assessment processes and integrating acquisitions.
  • Background in OT/ICS security for manufacturing environments.
  • Familiarity with platforms such as Wiz, Zscaler, Palo Alto, Elastic, Armis, Qualys, or Swimlane.
  • Relevant certifications such as CISSP, CISM, or technical certifications in cloud security, network security, or vulnerability management.

Leadership Competencies

  • Organized and decisive leader who manages multiple concurrent workstreams and makes priority calls under competing demands.
  • Delivery-oriented with a track record of driving initiatives to completion through teams: milestones hit, SLAs enforced, projects closed.
  • Strong presenter who communicates technical security posture, risk, and investment needs to executive audiences clearly and confidently.
  • Skilled at influencing without authority, driving remediation and compliance outcomes through infrastructure, platform, and application teams.
  • Builder mentality: energized by standing up new capabilities while keeping existing operations running smoothly.

Additional Information

  • Travel up to 10% may be required for site assessments, team collaboration, and vendor engagements.
  • The role may require coordination across global teams, including off-hours support for key initiatives, escalations, or major incidents.

Annual or Hourly Compensation Range

The base salary range for this position is $137,400.00 - $206,200.00. This position is eligible for annual bonus and long-term incentives based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.

Benefits

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. Click here to see our benefits.

If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working-here.

Potential Customer Requirements Notice

To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:

- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.

Americans with Disabilities Act (ADA)

Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Ecolab's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Ecolab's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Ecolab's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.