Director, Application & Product Security

Date: Aug 28, 2026

Location: CHICAGO, IL, US, 60661-4555

Company: Grainger Businesses

 

Work Location Type: Hybrid  

Req Number  334149

About Grainger

W.W. Grainger, Inc. is a leading broad line distributor with operations primarily in North America and Japan. At Grainger, We Keep the World Working® by serving more than 4.6 million customers worldwide with maintenance, repair and operating (MRO) products and value-added solutions delivered through innovative technology and deep customer expertise. Known for its commitment to service and purpose-driven culture, the Company reported 2025 revenue of $17.9 billion. For more information, visit www.grainger.com.  

 

Compensation

The anticipated base pay compensation range for this position is $163,800.00$273,000.00. This role is eligible for an incentive target of up to 25%, based on the achievement of individual and company performance objectives in accordance with the current terms of the incentive program which are subject to change.

 

Rewards and Benefits

With benefits starting on day one, our programs provide choice and flexibility to meet team members' individual needs, including:

  • Medical, dental, vision, and life insurance plans with coverage starting on day one of employment and 6 free sessions each year with a licensed therapist to support your emotional wellbeing.
  • 18 paid time off (PTO) days annually for full-time employees (accrual prorated based on employment start date) and 6 company holidays per year.
  • 6% company contribution to a 401(k) Retirement Savings Plan each pay period, no employee contribution required.
  • Employee discounts, tuition reimbursement, student loan refinancing and free access to financial counseling, education, and tools.
  • Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents.

 

For additional information and details regarding Grainger’s benefits, please click on the link below:

 

https://experience100.ehr.com/grainger/Home/Tools-Resources/Key-Resources/New-Hire

 

Grainger Benefits

The pay range provided above is not a guarantee of compensation.  The range reflects the potential base pay for this role at the time of this posting based on the job grade for this position. Individual base pay compensation will depend, in part, on factors such as geographic work location and relevant experience and skills.   

 

The anticipated compensation range described above is subject to change and the compensation ultimately paid may be higher or lower than the range described above. 

Grainger reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion at any time, consistent with applicable law.

 

 

Position Details

We are seeking a Director, Application & Product Security to join our Information Security organization. You will lead Grainger’s Application & Product Security program by establishing the strategy, governance, and security practices that enable the secure design, development, and delivery of applications, APIs, and digital products. You will partner with Engineering, Product Management, Platform Engineering, Enterprise Architecture, and Security Architecture and Security Engineering to integrate security into software delivery processes while enabling engineering teams to deliver secure, resilient, and innovative solutions.

 

The Director, Application & Product Security requires deep experience in application security, product security, secure software development practices, and modern technology platforms. The successful candidate understands how engineering organizations build and deliver software and can effectively partner with engineering leaders to integrate security throughout the software development lifecycle. This leader is a trusted advisor who enables secure innovation through collaboration, influence, and technical leadership rather than direct ownership of software development. You will report to the Chief Information Security Officer (CISO). This is a hybrid role based in downtown Chicago, with weekly presence at our Mart location.  There is a very strong preference for a candidate who resides in Chicago or is willing to relocate here.

 

You Will

  • Lead Grainger’s enterprise Application & Product Security strategy in alignment with the Information Security strategy and business objectives.
  • Build, develop, and lead a high-performing Application & Product Security organization.
  • Establish enterprise standards and governance for the Secure Software Development Lifecycle (SSDLC), secure-by-design, and secure-by-default engineering practices.
  • Partner with Engineering, Product Management, Platform Engineering, Enterprise Architecture, and Security Architecture and Security Engineering to establish secure development standards, integrate security into engineering workflows, and improve the security posture of Grainger’s applications and digital products.
  • Lead threat modeling, secure design reviews, and application and product security assessments for critical business initiatives.
  • Establish and mature capabilities for application security testing, software composition analysis, API security, software supply chain security, and DevSecOps practices.
  • Define security requirements and reference architectures for applications, APIs, cloud-native technologies, and emerging software architectures.
  • Partner with Security Architecture and Security Engineering to establish secure development practices for AI-enabled applications, AI-assisted software development, and emerging software technologies.
  • Build trusted relationships with engineering organizations and serve as a strategic advisor on secure software development and product security.
  • Establish developer enablement and Security Champion programs that improve secure coding practices and strengthen security ownership across engineering teams.
  • Define application and product security metrics, key risk indicators, and executive reporting to measure program maturity, adoption, and business outcomes.
  • Monitor application and product security risks and work with engineering teams to prioritize remediation based on business risk.
  • Evaluate emerging application security technologies and industry best practices to continuously improve Grainger’s security capabilities while supporting engineering velocity.
  • Develop, mentor, and retain technical security talent while fostering a culture of innovation, accountability, collaboration, and continuous improvement.
  • Represent the Application & Product Security function in enterprise architecture reviews, strategic technology initiatives, and executive governance forums.

 

You Have

  • Bachelor’s Degree in Computer Science, Cybersecurity, Information Systems, Software Engineering, or related field required.
  • 10+ years of progressive experience in application security, product security, cybersecurity, software architecture, or related technology disciplines required.
  • 5+ years of leadership experience building and leading technical security teams required.
  • Experience implementing Secure Software Development Lifecycle (SSDLC) practices within large engineering organizations required.
  • Demonstrated understanding of modern software engineering practices including Agile, DevOps, CI/CD, cloud-native development, APIs, microservices, containers, and Infrastructure as Code required.
  • Experience partnering with software engineering and product organizations to embed security throughout the software development lifecycle required.
  • Experience with application security practices including threat modeling, application security testing, software composition analysis, API security, software supply chain security, and vulnerability management required.
  • Strong understanding of secure software design principles, application security risks, OWASP guidance, and secure-by-design practices required.
  • Experience partnering with senior technology leaders and influencing engineering organizations through technical leadership, collaboration, and trusted advisory relationships required.
  • Strong written, verbal, and executive communication skills with the ability to communicate complex technical concepts and cyber risk to senior leadership required.
  • Professional certifications such as CISSP, CSSLP, GIAC, or equivalent technical credentials preferred.

 

 

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, protected veteran status or any other protected characteristic under federal, state, or local law. We are proud to be an equal opportunity workplace.

 

We are committed to fostering an inclusive, accessible work environment that includes both providing reasonable accommodations to individuals with disabilities during the application and hiring process as well as throughout the course of one’s employment, should you need a reasonable accommodation during the application and selection process, including, but not limited to use of our website, any part of the application, interview or hiring process, please advise us so that we can provide appropriate assistance.