Cloud Security Architect
Listed on 2026-04-23
-
IT/Tech
Cybersecurity, Systems Engineer, Cloud Computing
Position Details
The Information Security team protects all of Grainger, from our systems to our data across the global company. Our infrastructure is powered by cloud, on-premises, and SaaS platforms that keep Grainger and our customers working. We use modern tools and practices to stay ahead of evolving security challenges. The mission of the Security Architecture team is to be the strategic security design partner for Grainger’s technology.
As the security architect responsible for Grainger’s cloud platforms, you will be responsible for architecting, advising on, and governing a secure cloud infrastructure supporting business needs.
You will support the progressive needs of the business and provide timely, secure and cost-efficient solutions that elevate the company’s cloud security posture. An advanced role, the cloud architect will deliver resilient architectures at scale to support business initiatives. The role requires deep technical knowledge of cloud computing architecture, security principles, and cybersecurity best practices.
This individual contributor role reports to the Director of Cybersecurity Architecture and may be based remotely or at our offices in the Chicago area.
CompensationThe anticipated base pay range for this position is $146,200 – $243,600
. This role is eligible for an incentive target of up to 20 % based on achievement of individual and company performance objectives.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g., OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
You Will- Plan, research, and develop security architecture for cloud solutions (SaaS, PaaS, and IaaS), which may include custom in-house solutions and third-party solutions
- Define strategies and roadmaps to support security and company technology goals
- Communicate the state of cloud security posture to cybersecurity leaders, IT leaders, and other stakeholders through metrics and KPI-driven messages
- Develop, maintain, and enforce cloud security policies and procedures using best practices such as Cloud Security Alliance Cloud Controls Matrix, CIS Benchmarks, and cloud provider Well-Architected Framework security pillars
- Work with teams to define requirements, evaluate architecture, analyze trade-offs, and recommend solutions
- Create conceptual and logical architecture designs, including cloud security reference architectures and secure landing zone designs
- Assess risks through threat modeling and white‑boarding exercises with teams
- Evaluate products and tools through Proof of Value exercises
- Advise product teams on security implications of their roadmaps
- Partner with engineering teams, cloud platform teams, and peer architecture teams to embed security in technical decisions from design through implementation
- Define and maintain cloud account and subscription governance, including organizational unit structure, service control policies, and permission boundaries
- Design and advise on security architectures for CI/CD pipelines, including secrets management, IaC scanning, container image scanning, and artifact integrity
- Architect cloud-native security monitoring and logging strategies, including integration with Grainger’s SIEM/SOAR platform
- Evaluate and mature cloud-native security tooling to support detection, prevention, and compliance objectives
- Mentor peers and junior architects through design reviews, knowledge sharing, and technical leadership across the security architecture team
- 5+ years of architecture experience, with at least 3 years focused on cloud environments
- 8+ years of information security experience
- Bachelor’s degree preferred or equivalent work experience
- Deep expertise in designing cloud security architectures that support the business needs of large enterprises, primarily in AWS and functional in Microsoft Azure and Google Cloud
- Proven experience with zero‑trust architecture principles, encryption and key management, web application firewalls, data protection, vulnerability management, API…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).