Uma candidatura completa num minuto — currículo e carta de apresentação personalizados, prontos a enviar.
Johnson Controls is seeking a strategic Director, Product Security & Security Strategy to lead cybersecurity across a global portfolio of Fire Solutions, including hardware, software, cloud, and IoT. You will shape security strategy, governance, and risk management in collaboration with Enterprise Security, Regulatory Affairs, Quality, Legal, and Operations.
You will drive multi-year roadmaps, establish security metrics, and ensure secure-by-design practices across the lifecycle while
Johnson Controls is global leader in smart, healthy, and sustainable buildings. Our mission is to reimagine the performance of buildings to serve people, places, and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe. You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard – your next great opportunity is just a few clicks away!
Competitive salary
Paid vacation/holidays/sick time
Comprehensive benefits package including 401K, medical, dental, and vision care.
On-the-job/cross-training opportunities
Encouraging and collaborative team environment
Dedication to safety through our Zero Harm policy
Johnson Controls Fire Solutions is seeking a strategic and influential Director, Product Security & Security Strategy to lead the cybersecurity vision, governance, and execution framework across a global portfolio of fire detection, suppression, life safety, connected devices, cloud platforms, mobile applications, and digital services.
This critical leadership role will be responsible for defining and advancing the Fire Solutions product security strategy while partnering closely with Enterprise Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and vulnerability management programs, drive Cyber Resilience Act (CRA) readiness and execution, and develop the organization's AI security threat response and governance capabilities.
The successful candidate will provide leadership across a complex global ecosystem of hardware, firmware, software, cloud, and IoT solutions, ensuring security is effectively integrated throughout the product lifecycle. This individual will translate cybersecurity requirements into practical engineering processes, improve security operational efficiency, and promote a culture of security ownership across the organization.
This position is critical to maintaining customer trust, meeting evolving cybersecurity expectations, supporting regulatory compliance initiatives, and ensuring the long-term success and resilience of the Fire Solutions business.
Define and execute the Fire Solutions Product Security Strategy aligned with business objectives, customer expectations, and enterprise cybersecurity standards.
Partner with Johnson Controls Enterprise Security to establish security governance, policies, standards, and risk management frameworks across the product portfolio.
Serve as the senior product security leader for Fire Solutions and provide strategic cybersecurity guidance to business and engineering leadership.
Develop multi-year security roadmaps focused on improving product security maturity, resilience, and operational effectiveness.
Establish security metrics, KPIs, and executive reporting mechanisms to measure program effectiveness and risk reduction.
Drive a culture of security-by-design, accountability, and continuous improvement throughout the organization.
Lead the implementation of cybersecurity governance processes across the product development lifecycle.
Partner with Regulatory Affairs, Quality, Legal, and Engineering teams to operationalize cybersecurity requirements associated with emerging regulations and industry standards.
Translate regulatory cybersecurity requirements into scalable engineering processes, controls, documentation, and compliance evidence.
Support audit readiness activities, security assessments, certifications, and regulatory reviews.
Ensure cybersecurity requirements are integrated into product development, release, maintenance, and end-of-life processes.
Monitor industry trends, emerging threats, and evolving cybersecurity requirements to continuously improve security capabilities.
Lead the cybersecurity execution framework required to support CRA compliance across the Fire Solutions portfolio.
Work closely with Regulatory Affairs, which owns regulatory strategy and interpretation, to ensure cybersecurity obligations are effectively implemented within engineering and product development processes.
Establish and maintain processes supporting:
Secure development practices
Vulnerability management
Coordinated vulnerability disclosure
Software Bill of Materials (SBOM) management
Security documentation
Post-release monitoring and response
Coordinate cross-functional efforts to ensure sustainable compliance execution across global product teams.
Develop metrics and reporting to track cybersecurity compliance readiness and risk posture.
Define and lead the organization's AI security governance and threat response strategy.
Establish processes for identifying, assessing, mitigating, and responding to AI-related cybersecurity risks.
Partner with Enterprise Security and engineering teams to implement secure AI adoption practices and governance controls.
Evaluate AI-enabled product capabilities for cybersecurity risk and resilience.
Develop playbooks and response processes for AI-specific threats and vulnerabilities.
Leverage AI-driven security tools and automation to improve security effectiveness and operational efficiency.
Drive adoption of secure development lifecycle (SSDLC) practices across hardware, firmware, software, cloud, mobile, and IoT product teams.
Lead threat modeling, security architecture reviews, risk assessments, and security design reviews.
Establish consistent security requirements for new product introductions and major platform enhancements.
Oversee security testing programs, penetration testing activities, and security validation processes.
Ensure security requirements are embedded throughout all phases of the product lifecycle.
Establish and oversee global product vulnerability management processes.
Lead coordinated vulnerability disclosure and external vulnerability response activities.
Manage security incident response processes affecting products and connected services.
Develop remediation prioritization frameworks and risk-based decision‑making processes.
Support customer communications and executive briefings related to cybersecurity issues and product security events.
Drive continual improvements in vulnerability response timelines and remediation effectiveness.
Design and implement scalable security processes that can be consistently adopted across global engineering organizations.
Identify opportunities to improve efficiency through process optimization, automation, and AI-assisted workflows.
Establish repeatable methods for security reviews, compliance evidence generation, risk assessments, and vulnerability tracking.
Define and measure operational performance indicators that demonstrate security program effectiveness and business impact.
Reduce friction in engineering processes while improving security outcomes and compliance readiness.
Lead and influence geographically distributed teams and cross‑functional stakeholders across multiple business functions.
Build strong partnerships with Enterprise Security, Regulatory Affairs, Quality, Product Management, Engineering, Operations, Legal, and Customer Support organizations.
Develop organizational capabilities, talent strategies, and succession plans within the product security function.
Drive alignment and decision‑making across diverse technical and business stakeholders.
Serve as a trusted advisor to executive leadership on cybersecurity risks, investments, and priorities.
Represent Johnson Controls in customer discussions regarding product cybersecurity capabilities and security practices.