Principal Identity Engineer Job at Ecolab Inc., Saint Paul, MN

dnZ3bGxrZG5vdDdIVWZTTXhVZXNWc3RiZmc9PQ==
  • Ecolab Inc.
  • Saint Paul, MN

Job Description

Job Description

Principal Identity Engineer:

Ecolab is seeking a highly skilled Principal Identity Engineer to lead our identity management strategy in a complex hybrid environment. This role will oversee and own the architecture, implementation, and training other members around operational management of critical systems, including BeyondTrust, Microsoft Entra ID (formerly Azure AD), Active Directory (AD), internal Certificate Authority (Active Directory Certificate Services - ADCS), and external Certificate Authorities such as Sectigo.

What’s in it For You: 

As a lead team member, you’ll influence our strategy and direction, drive project success, and help shape the future for digital growth

  • Assist with identity technical solution design across Identity Access Management Platforms.
  • Lead the design and implementation of enterprise-grade Identity Management solutions, including BeyondTrust, Active Directory (AD), Entra ID, and Certificate Management.
  • Develop scalable architectures for hybrid environments that integrate on-premises and cloud-based systems.
  • Evolve and optimize a hybrid environment combining managed and exchange services across domains.
  • Ensure seamless integration of identity solutions with existing infrastructure, including Entra ID and other third-party platforms.
  • Provide technical leadership and mentorship to engineers within the team.
  • Oversee and provide recommendations of identity management tools, including monitoring, troubleshooting, and performance optimization.
  • Playing a key role in developing standards for the identity team in relation to implementation, maintenance, and support while additionally participating in our team’s on-call rotation.
  • Optimize a hybrid environment combining managed and exchange services across domains.

What You Will Do:  

Key Responsibilities:

  • Design and Implementation: Lead the design and implementation of robust identity management solutions that integrate seamlessly across on-premises and cloud environments. Ensuring a stable and secure environment that is evaluated across aligned to KPIs.
  • Identity Governance: Lead lifecycle management and governance processes ensuring compliance with regulatory standards.
  • Threat Detection: Integrate identity systems with SIEM for proactive threat detection and response.
  • Passwordless Strategy: Drive adoption of modern authentication methods such as FIDO2 and passwordless technologies.
  • Metrics: Establish KPIs for identity security posture and operational efficiency.
  • BeyondTrust Integration: Lead and own the BeyondTrust platform ensuring secure access for servers, admin users, and supply chain isolated networks.
  • Microsoft Entra ID & Active Directory: Design a cloud first architecture and train core members in Microsoft Entra ID for managing user identities, still ensuring alignment with AD on-premises systems.
  • Certificate Management: Design and manage public key infrastructure (PKI), including both internal ADCS and external Certificate Authorities like Sectigo, to ensure secure communication channels and compliance with security standards.
  • Collaborate with Security Architecture, Infrastructure and Cloud delivery teams to achieve business objectives
  • Partner with Enterprise Architecture and business teams to achieve strategic outcomes for Digital Initiatives

Minimum Qualifications :

  • Bachelor's degree and 10 years of relevant experience in Identity Field similar roles.
  • 8 years of experience with BeyondTrust,or, Active Directory (AD) and Microsoft Entra ID (formerly Azure or external Certificate Authorities such as Sectigo, internal Certificate Authority (Active Directory Certificate Services - ADCS)
  • Strong understanding of Identity principles including but not limited to SCIM, OIDC SAML, least privilege, Kerberos, certificate-based auth.
  • Excellent analytical skills, with the ability to use data and data analytics tools to drive decisions.
  • 3 years' experience with Agile methodologies and tools such as ADO or GitHub.
  • Ability to think strategically while managing day-to-day product details.
  • Strong communication, and interpersonal skills – the ability to collaborate and deliver effectively with diverse teams.
  • Expert in EntraID integration and Microsoft 365 identity management solutions.
  • Knowledge of scripting or automation technologies such as PowerShell, Terraform, REST, JSON for automating identity-related tasks.
  • Experience performing SQL, EQL query analysis to build a case for a new process or to take action based on the data.
  • Excellent problem-solving skills and attention to detail.
  • Ability to adapt to changing priorities and manage multiple tasks effectively
  • Immigration sponsorship and relocation are not available for this position.

Preferred Qualifications:

  • Previous experience in building and architecting using infrastructure as code with terraform.
  • Desire to be in a fast-moving, agile environment with willingness to adjust quickly 
  • Certifications such as CISSP, CISA, or relevant Microsoft, BeyondTrust certifications in Identity & Access
  • Experience architecting and designing multi-cloud identity platforms
  • Project management experience
  • Experience in CIAM(Customer Identity and Access Management)
  • Experience in Protocols & APIs: Deep understanding of federation protocols (SAML, OAuth2.0, OIDC), SCIM, and RESTful APIs.
  • Security Frameworks: Solid foundation in Zero Trust architecture and contemporary security standards.

Annual or Hourly Compensation Range

The base salary range for this position is $153,900.00 - $230,800.00. This position is eligible for annual bonus pay based on performance, per plan terms. Many factors are taken into consideration when determining compensation, such as experience, education, training, geography, etc. We comply with all minimum wage and overtime laws.

Benefits  

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. Click here to see our benefits. 

If you are viewing this posting on a site other than our Ecolab Career website, view our benefits at jobs.ecolab.com/working -here.  

Potential Customer Requirements Notice

To meet customer requirements and comply with local or state regulations, applicants for certain customer-facing roles may need to:

- Undergo additional background screens and/or drug/alcohol testing for customer credentialing.

- Be fully vaccinated for COVID-19, including a booster if eligible, unless a religious or medical accommodation is requested by the applicant and approved by Ecolab.

 

Americans with Disabilities Act (ADA)  

Ecolab will provide reasonable accommodation (such as a qualified sign language interpreter or other personal assistance) with our application process upon request as required to comply with applicable laws. If you have a disability and require accommodation assistance in this application process, please visit the Recruiting Support link in the footer of each page of our career website.  

Our Commitment to a Culture of Inclusion & Belonging
\nAt Ecolab, we believe the best teams are inclusive. We are on a journey to create a workplace where every associate can grow and achieve their best. We are committed to fair and equal treatment of associates and applicants and recruit, hire, promote, transfer and provide opportunities for advancement based on individual qualifications and job performance. In all matters affecting employment, compensation, benefits, working conditions, and opportunities for advancement, we will not discriminate against any associate or applicant for employment because of race, religion, color, creed, national origin, citizenship status, sex, sexual orientation, gender identity and expressions, genetic information, marital status, age, disability, or status as a covered veteran.

\n

In addition, we are committed to furthering the principles of Equal Employment Opportunity (EEO) through Affirmative Action (AA).

\n

We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles’ Fair Chance Initiative for Hiring Ordinance, the San Francisco Fair Chance Ordinance, and the New York City Fair Chance Act.

Job Tags

Hourly pay, Minimum wage, Local area, Relocation,

Similar Jobs

Divine Global Solutions

IBM Curam Developer Job at Divine Global Solutions

 ...Job Description Job Description Job Summary We are seeking a IBM Curam Developer to join our team! As a Developer, you will be responsible for below responsibilities. Responsibilities Work closely with other web developers, as well as other teams, to... 

ORAU

Geology and Tectonics of Mars (Pasadena) Job at ORAU

 ...missions in space science, Earth science, aeronautics, space operations, exploration systems, and astrobiology. Research focus: geologic interpretation of data returned by Mars orbiter and lander/rover missions. Areas include geology, geomorphology, rock distribution... 

Randstad

Order selector Job at Randstad

 ...positions! Hours are first shift from 5am-2:30pm. You need to have availability on the weekends. (Sundays included!) There is no background check required for employment! Please apply today or contact Allysia at: ****@*****.*** salary: $18 - $20... 

ADEX Healthcare Staffing LLC

Travel Telemetry Registered Nurse Job at ADEX Healthcare Staffing LLC

 ...Job Description ADEX Healthcare Staffing LLC is seeking a travel nurse RN Telemetry Med Surg for a travel nursing job in Alexandria,...  ...ASAP start. A minimum of 2+ years of recent hospital bedside experience is required. Candidates must be able to start within 5 weeks.... 

Fresh Grocer

Fresh Grocer - Meat Cutter Clerk Job at Fresh Grocer

 ...Meat Department Associate To deliver a great customer experience while working in the Meat Department; to maintain a visually appealing...  ...band saws, grinders, wrapping machines, power jacks, knives and cutters. Ability to stand/walk for the duration of a scheduled shift....