Principal Identity Engineer Job at Ecolab Inc., Saint Paul, MN

dnZ3bGxrZG5vdDdIVWZTTXhVZXNWc3RiZmc9PQ==
  • Ecolab Inc.
  • Saint Paul, MN

Job Description

Job Description

Principal Identity Engineer:

Ecolab is seeking a highly skilled Principal Identity Engineer to lead our identity management strategy in a complex hybrid environment. This role will oversee and own the architecture, implementation, and training other members around operational management of critical systems, including BeyondTrust, Microsoft Entra ID (formerly Azure AD), Active Directory (AD), internal Certificate Authority (Active Directory Certificate Services - ADCS), and external Certificate Authorities such as Sectigo.

What’s in it For You: 

As a lead team member, you’ll influence our strategy and direction, drive project success, and help shape the future for digital growth

  • Assist with identity technical solution design across Identity Access Management Platforms.
  • Lead the design and implementation of enterprise-grade Identity Management solutions, including BeyondTrust, Active Directory (AD), Entra ID, and Certificate Management.
  • Develop scalable architectures for hybrid environments that integrate on-premises and cloud-based systems.
  • Evolve and optimize a hybrid environment combining managed and exchange services across domains.
  • Ensure seamless integration of identity solutions with existing infrastructure, including Entra ID and other third-party platforms.
  • Provide technical leadership and mentorship to engineers within the team.
  • Oversee and provide recommendations of identity management tools, including monitoring, troubleshooting, and performance optimization.
  • Playing a key role in developing standards for the identity team in relation to implementation, maintenance, and support while additionally participating in our team’s on-call rotation.
  • Optimize a hybrid environment combining managed and exchange services across domains.

What You Will Do:  

Key Responsibilities:

  • Design and Implementation: Lead the design and implementation of robust identity management solutions that integrate seamlessly across on-premises and cloud environments. Ensuring a stable and secure environment that is evaluated across aligned to KPIs.
  • Identity Governance: Lead lifecycle management and governance processes ensuring compliance with regulatory standards.
  • Threat Detection: Integrate identity systems with SIEM for proactive threat detection and response.
  • Passwordless Strategy: Drive adoption of modern authentication methods such as FIDO2 and passwordless technologies.
  • Metrics: Establish KPIs for identity security posture and operational efficiency.
  • BeyondTrust Integration: Lead and own the BeyondTrust platform ensuring secure access for servers, admin users, and supply chain isolated networks.
  • Microsoft Entra ID & Active Directory: Design a cloud first architecture and train core members in Microsoft Entra ID for managing user identities, still ensuring alignment with AD on-premises systems.
  • Certificate Management: Design and manage public key infrastructure (PKI), including both internal ADCS and external Certificate Authorities like Sectigo, to ensure secure communication channels and compliance with security standards.
  • Collaborate with Security Architecture, Infrastructure and Cloud delivery teams to achieve business objectives
  • Partner with Enterprise Architecture and business teams to achieve strategic outcomes for Digital Initiatives

Minimum Qualifications :

  • Bachelor's degree and 10 years of relevant experience in Identity Field similar roles.
  • 8 years of experience with BeyondTrust,or, Active Directory (AD) and Microsoft Entra ID (formerly Azure or external Certificate Authorities such as Sectigo, internal Certificate Authority (Active Directory Certificate Services - ADCS)
  • Strong understanding of Identity principles including but not limited to SCIM, OIDC SAML, least privilege, Kerberos, certificate-based auth.
  • Excellent analytical skills, with the ability to use data and data analytics tools to drive decisions.
  • 3 years' experience with Agile methodologies and tools such as ADO or GitHub.
  • Ability to think strategically while managing day-to-day product details.
  • Strong communication, and interpersonal skills – the ability to collaborate and deliver effectively with diverse teams.
  • Expert in EntraID integration and Microsoft 365 identity management solutions.
  • Knowledge of scripting or automation technologies such as PowerShell, Terraform, REST, JSON for automating identity-related tasks.
  • Experience performing SQL, EQL query analysis to build a case for a new process or to take action based on the data.
  • Excellent problem-solving skills and attention to detail.
  • Ability to adapt to changing priorities and manage multiple tasks effectively
  • Immigration sponsorship and relocation are not available for this position.

Preferred Qualifications:

  • Previous experience in building and architecting using infrastructure as code with terraform.
  • Desire to be in a fast-moving, agile environment with willingness to adjust quickly 
  • Certifications such as CISSP, CISA, or relevant Microsoft, BeyondTrust certifications in Identity & Access
  • Experience architecting and designing multi-cloud identity platforms
  • Project management experience
  • Experience in CIAM(Customer Identity and Access Management)
  • Experience in Protocols & APIs: Deep understanding of federation protocols (SAML, OAuth2.0, OIDC), SCIM, and RESTful APIs.
  • Security Frameworks: Solid foundation in Zero Trust architecture and contemporary security standards.

Annual or Hourly Compensation Range

The base salary range for this position is $153,900.00 - $230,800.00. This position is eligible for annual bonus pay based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.

Benefits  

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. Click here to see our benefits. 

If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working -here.  

Potential Customer Requirements Notice

To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:

- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.

- Be fully vaccinated for COVID-19, including a booster if eligible, unless a religious or medical accommodation is requested by the applicant and approved by Ecolab.

 

Americans with Disabilities Act (ADA)  

Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.  

Our Commitment to a Culture of Inclusion & Belonging
\nAt Ecolab, we believe the best teams are inclusive. We are on a journey to create a workplace where every associate can grow and achieve their best. We are committed to fair and equal treatment of associates and applicants and recruit, hire, promote, transfer and provide opportunities for advancement based on individual qualifications and job performance. In all matters affecting employment, compensation, benefits, working conditions, and opportunities for advancement, we will not discriminate against any associate or applicant for employment because of race, religion, color, creed, national origin, citizenship status, sex, sexual orientation, gender identity and expressions, genetic information, marital status, age, disability, or status as a covered veteran.

\n

In addition, we are committed to furthering the principles of Equal Employment Opportunity (EEO) through Affirmative Action (AA).

\n

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act.

Job Tags

Hourly pay, Minimum wage, Local area, Relocation,

Similar Jobs

Good Samaritan

Senior Nursing Assistant, Certified, Long Term Care (LTC) Job at Good Samaritan

 ...organization that has provided over 100 years of housing and services to seniors with a commitment to quality care and service in a Christian...  ...offers an attractive benefits package for qualifying full-time and part-time employees. Depending on eligibility, a variety of... 

Waiter.com

Portland Delivery Driver Rider Job at Waiter.com

The Portland branch of Waiter.comis focused on sustainable catering and food delivery to Portland's downtown offices. Utilizing a mixture of Electrified Cargo bikes and Car based deliveries, we create and design custom menus and restaurant rotations for our corporate ...

HRUCKUS

Activity Security Representative III (Beale AFB) (Beale Air Force Base) Job at HRUCKUS

 ...Technical and Cleared Recruiting for the Department of Defense (DoD), the Intelligence Community (IC), and other advanced defense...  ...miscellaneous administrative support functions as directed by the contractor site lead and/or the Senior Security Representative Review,... 

The Judge Group

Oncology Nurse Practitioner Job at The Judge Group

 ...Oncology Nurse Practitioner Day Shift: M-F (or 4 10 hour days) - Weekend call requirement on a rotating basis - Outpatient Summary The Oncology Nurse Practitioner (ONP) is an Advanced Practice Registered Nurse (APRN) specializing in comprehensive cancer care... 

Express Employment

Mining Technician Job at Express Employment

Job Description Job Description Located in Grand Forks, ND Salary: 20.00 Mining Technician Location: Grand Forks North Dakota Pay Rate: $20.00/hr. $1.00/hr shift differential overnight Shift Times: Front Half Sun - Wed Rotate Sun Off/Back Half Wed ...