Jobs · Management · Illinois

Director of Security Engineering

Ecolab · Naperville, IL · 2 wk ago
Management$137k–$206k/yrFull-time

Lead the enterprise security architecture, engineering, and exposure management programs for a global Fortune 500 environment. This role owns the proactive side of security: architecture decisions, platform engineering, security standards enforcement, vulnerability and exposure management, and initiatives that harden the environment before threats land.

Responsibilities

  • Own security architecture standards, benchmarks, and compliance posture for the enterprise aligned to CIS Benchmarks, NIST CSF 2.0, and platform hardening requirements.
  • Make platform and tooling decisions across the security technology stack including endpoint, cloud, network, data protection, and collaboration security.
  • Lead security solution selection, evaluation, and implementation for new capabilities across multi-cloud, on-premises, and OT environments.
  • Guide zero-trust architecture implementation including network segmentation, conditional access enforcement, and least-privilege design patterns.
  • Drive security configuration standards and compliance across Azure, AWS, GCP, on-premises infrastructure, and industrial control system environments.
  • Stand up and operationalize the Continuous Threat Exposure Management (CTEM) function, directing a team of exposure analysts across infrastructure, cloud, application, and external attack surface domains.
  • Define and operationalize the CTEM cycle: discovery, prioritization (exploitability-weighted), mobilization, validation, and remediation tracking.
  • Establish and enforce vulnerability remediation SLAs with infrastructure, platform, and application teams across the enterprise.
  • Build executive-facing exposure reporting and risk quantification tied to business outcomes.
  • Drive convergence of vulnerability scanning, cloud security posture management, and attack surface management into a unified exposure view.
  • Oversee day-to-day security engineering including platform maintenance, incident support, approval workflows, and operational stability across the security tooling portfolio.
  • Manage the solution review and re-attestation process for enterprise technology including vendor evaluations and M&A security assessments.
  • Drive automation of manual security processes including approvals, compliance checks, and configuration auditing.
  • Partner with Observability and Automation teams on SIEM integration, security automation playbooks, and compliance dashboards.
  • Translate governance and compliance requirements from GRC into implemented technical controls, deploying and configuring security platforms to monitor and enforce policy compliance across the enterprise.
  • Oversee OT security assessments across global manufacturing sites, ensure regulatory compliance (NIS2, CFATS), and drive network segmentation programs for industrial environments.
  • Organize and prioritize work across multiple concurrent workstreams spanning endpoint hardening, cloud exposure remediation, network benchmarking, data protection, and OT security.
  • Use modern tools including AI assistants (Claude, Copilot) to accelerate planning, analysis, documentation, and decision-making across the team.
  • Present program status, roadmaps, and investment cases to executive leadership with clarity and confidence.
  • Drive cross-functional initiatives requiring coordination across infrastructure, networking, cloud platforms, and application teams.
  • Lead and develop a distributed security organization consisting of managers, architects, and engineers across multiple technical domains.
  • Build organizational clarity across architecture, engineering, and the new exposure management function.
  • Provide leadership in talent development, succession planning, coaching, performance management, and team engagement.
  • Manage staffing strategy across full-time employees, partners, and contingent resources to meet delivery needs.
  • Oversee third-party vendors and consulting partners supporting security programs and services.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, Engineering, or a related discipline; equivalent experience may be considered.
  • 12+ years of progressive experience in cybersecurity, security architecture, security engineering, or vulnerability management.
  • 5+ years of leadership experience managing multi-team security functions at the Senior Manager or Director level.
  • Demonstrated success delivering security initiatives through teams: hardening programs, platform deployments, and posture improvements completed on schedule.
  • Experience managing 15+ person organizations including managers, architects, and engineers with varied technical specializations.
  • Experience building new functions or teams, particularly in exposure management, vulnerability operations, or CTEM disciplines.
  • Background in cross-functional program delivery, driving remediation and compliance outcomes through teams not under direct reporting authority.

Skills

  • Strong knowledge of cloud security architecture across Azure, AWS, and GCP including CSPM/CNAPP platforms, container security, and cloud-native controls.
  • Strong knowledge of network security including next-generation firewalls, secure web gateways, network segmentation, DNS security, and zero-trust network access.
  • Experience with endpoint security platforms (EDR), endpoint hardening, and CIS benchmark implementation at enterprise scale.
  • Knowledge of data protection platforms (DLP), data classification, insider threat programs, and unstructured data controls.
  • Strong knowledge of vulnerability and exposure management: scanning platforms, CTEM frameworks, attack surface management, exposure prioritization, and remediation SLA governance. Qualys experience strongly preferred.
  • Knowledge of OT/ICS security including network segmentation for industrial environments, asset discovery, and regulatory frameworks (NIS2).
  • Familiarity with security architecture frameworks: CIS Benchmarks (multi-platform), NIST CSF 2.0, and zero-trust architecture principles.
  • Comfort with security automation platforms (SOAR) and AI-assisted workflows for accelerating team productivity and decision-making.

Preferred Qualifications

  • Experience in a Fortune 500, global, manufacturing, or industrial environment with complex, heterogeneous technology estates.
  • Prior experience standing up a CTEM, exposure management, or vulnerability operations function.
  • Familiarity with M&A security assessment processes and integrating acquisitions.
  • Background in OT/ICS security for manufacturing environments.
  • Familiarity with platforms such as Wiz, Zscaler, Palo Alto, Elastic, Armis, Qualys, or Swimlane.
  • Relevant certifications such as CISSP, CISM, or technical certifications in cloud security, network security, or vulnerability management.

Leadership Competencies

  • Organized and decisive leader who manages multiple concurrent workstreams and makes priority calls under competing demands.
  • Delivery-oriented with a track record of driving initiatives to completion through teams: milestones hit, SLAs enforced, projects closed.
  • Strong presenter who communicates technical security posture, risk, and investment needs to executive audiences clearly and confidently.
  • Skilled at influencing without authority, driving remediation and compliance outcomes through infrastructure, platform, and application teams.
  • Builder mentality: energized by standing up new capabilities while keeping existing operations running smoothly.

Additional Information

  • Travel up to 10% may be required for site assessments, team collaboration, and vendor engagements.
  • The role may require coordination across global teams, including off-hours support for key initiatives, escalations, or major incidents.

Pay

The base salary range for this position is $137,400.00 - $206,200.00. This position is eligible for annual bonus and long-term incentives based on performance, per plan terms.

Benefits

Ecolab strives to provide comprehensive and market-competitive benefits to meet the needs of our associates and their families. View our benefits.

Similar jobs