28d ago
New

Senior Director Product Security

United StatesUnited States·Waukeshasenior
OtherDirector Product
1 views0 saves0 applied

Quick Summary

Key Responsibilities

Product Security Strategy: Set the enterprise product security strategy and multi year roadmap,

Technical Tools
OtherDirector Product

For more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen businesses and build a more resilient, efficient, sustainable energy future.


Ready to Power a Smarter World with us?

Requirements

~1 min read

At Generac, you'll have the opportunity to shape the security strategy for a growing portfolio of connected energy solutions that power homes, businesses, and communities worldwide. Your leadership will directly influence product innovation, customer trust, regulatory readiness, and the future of secure energy technology.

Responsibilities

~1 min read

Product Security Strategy:

  • →

    Set the enterprise product security strategy and multi year roadmap, and embed secure by design as the standard across the product portfolio and the energy technology solutions and services that extend it.

  • →

    Establish IEC 62443 as the primary product security framework, and define how its requirements apply across industrial, commercial, and consumer connected products.

  • →

    Make product security a visible driver of customer trust and competitive differentiation, and represent it to customers, partners, auditors, and regulators.

  • →

    Partner with engineering and product leadership so security requirements, threat models, and risk decisions are built into product design, development, and release. Secure Development Lifecycle · Define and operationalize the secure development lifecycle that engineering teams build to, including threat modeling, secure coding, security testing, and security gates within the development process.

  • →

    Lead the company toward formal certification of its secure development lifecycle against IEC 62443-4-1, advancing process maturity to the required level and preparing the organization for assessment by an accredited body. · Establish the foundations that position products and components for downstream certification, including IEC 62443-4-2 for components and IEC 62443-3-3 for systems.

  • →

    Drive software bill of materials, secure software supply chain, and vulnerability management practices into the development lifecycle.

  • Build and lead the Product Security Incident Response capability that receives, triages, investigates, and resolves vulnerabilities and incidents affecting products in the field.

  • Establish coordinated vulnerability disclosure and handling practices aligned to ISO/IEC 29147 and ISO/IEC 30111, including a public intake channel and clear security advisories for customers.

  • Stand up the processes and reporting needed to meet regulatory timelines, including the EU Cyber Resilience Act obligation to report actively exploited vulnerabilities and severe incidents on a 24 hour, 72 hour, and final report cadence.

  • Partner with enterprise security operations and incident response so product and enterprise incidents are handled as one coordinated response. 

  • Global Regulatory and Compliance Leadership

  • Lead the company's product security response to a fast moving global regulatory landscape, including the EU Cyber Resilience Act, the UK product security regime, and emerging product security regulations in other markets.

  • Translate new and emerging obligations into engineering requirements, evidence, and documentation, including conformity assessment, CE marking support, and declarations of conformity where required.

  • Maintain product security policies, standards, and control narratives, and own the evidence that demonstrates compliance to auditors, customers, and market surveillance authorities.

  • Track the regulatory horizon and advise executive leadership on the cost, risk, and timing of new requirements.

  • Organization and Talent

  • Build, staff, and develop a high performing product security organization, including managers and senior engineers, and establish product security as a respected discipline across the company.

  • Set clear direction, develop talent, and create a culture of ownership, engineering rigor, and customer focus.

  • Influence teams well beyond direct reports, embedding product security champions and practices within the engineering organizations of each business unit.

  • Manage product security tooling, services, and external partners, and steer investment toward the highest risk

  • reduction.

  • Bachelor degree in Engineering, Computer Science, Cybersecurity, or related field. Equivalent experience considered. 

  • Advanced degree in Engineering, Cybersecurity, or Computer Science

  • Certification / License

  • Additional ISA or IEC 62443, cloud, or product security certifications.

  • One or more of the following is strongly preferred: CISSP, CSSLP, GICSP, ISA or IEC 62443 certifications, or equivalent product and application security credentials. 

  • Work Experience

  • 12 years in cybersecurity, product security, or secure engineering, with progressive leadership responsibility. · 7 years leading teams, including leading other managers or senior engineers, ideally across multiple regions.

  • Proven record building or substantially maturing a product security program for connected, embedded, or industrial products.

  • Hands on leadership of a secure development lifecycle and a product security incident response capability.

  • Working experience applying IEC 62443 to real products, including familiarity with the path to IEC 62443-4-1 certification. 

  • Experience navigating global product security regulations such as the EU Cyber Resilience Act or comparable regimes.

  • Experience achieving or maintaining IEC 62443-4-1 certification of a secure development lifecycle. · Experience in energy, power, industrial, or connected consumer product environments.

  • Experience securing products that span operational technology, embedded systems, cloud connected services, and mobile applications. 

  • Experience aligning product security with enterprise security, including shared incident response and governance.

  • Deep knowledge of secure by design, the secure development lifecycle, threat modeling, and product vulnerability management. 

  • Strong command of IEC 62443, including the secure development lifecycle requirements of 62443-4-1 and the component and system requirements of 62443-4-2 and 62443-3-3.

  • Working knowledge of the global product security regulatory landscape, including the EU Cyber Resilience Act, the UK product security regime, and comparable emerging regimes in other markets.

  • Practical understanding of product security incident response and coordinated vulnerability disclosure aligned to ISO/IEC 29147 and ISO/IEC 30111.

  • Ability to set enterprise strategy and translate it into engineering practice, evidence, and certification outcomes. 

  • Excellent executive communication and influence, with the ability to represent product security to the board, customers, auditors, and regulators.

  • Demonstrated ability to build, develop, and retain a world class technical organization.

“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any other characteristic protected by law.”

Location & Eligibility

Where is the job
Waukesha, United States
On-site at the office
Who can apply
Open to applicants worldwide

Listing Details

Posted
September 1, 2026
First seen
September 30, 2026
Last seen
September 30, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
18%
Scored at
September 30, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Senior Director Product Security