Senior Director Product Security

Generac Power Systems Inc

North Prairie (WI)

On-site

USD 180,000 - 280,000

Full time

14 days+
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Generac Power Systems Inc. seeks a Senior Director, Product Security in Wisconsin to lead the enterprise product security strategy across connected energy solutions and services.

You will embed secure by design, drive IEC 62443 adoption, and partner with engineering, legal, and leadership to ensure compliance and customer trust. You will build a world-class security organization, define governance, and oversee incident response and vulnerability disclosures in a rapidly evolving regulatory

Qualifications

  • Bachelor degree in Engineering, Computer Science, Cybersecurity or related field.
  • 12+ years in cybersecurity/product security with progressive leadership.
  • Experience applying IEC 62443 to products and secure development lifecycle.

Responsibilities

  • Set and drive the enterprise product security strategy and roadmaps.
  • Lead IEC 62443 adoption across products and services.
  • Oversee secure development lifecycle, threat modeling, and governance.
  • Manage product security incident response and vulnerability handling.
  • Ensure regulatory readiness across EU/UK markets and beyond.

Skills

Leadership
IEC 62443
Product security strategy
Secure SDLC
Regulatory affairs

Education

Bachelor's degree in Engineering, Computer Science, Cybersecurity
Advanced degree preferred

Job description

We believe power is a promise - a shared commitment to be there for others when it matters most. For more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen businesses and build a more resilient, efficient, sustainable energy future. Ready to Power a Smarter World with us? Generac is seeking a forward-thinking Senior Director, Product Security to lead and advance our enterprise-wide product security strategy across a rapidly expanding portfolio of connected products, energy technologies, software, and digital services. This highly visible leadership role is responsible for ensuring security is embedded into every stage of the product lifecycle, enabling our teams to deliver innovative solutions that are secure by design and trusted by customers around the world. As the company’s foremost product security leader, you will define the frameworks, governance, and security standards that shape how we design, develop, deploy, and support connected technologies. Leveraging IEC 62443 as the foundation of our product security program, you will lead the evolution of our secure development lifecycle, drive enterprise-wide adoption of secure engineering practices, and establish best-in-class Product Security Incident Response capabilities that safeguard customers and products in the field. This role will play a pivotal part in navigating an increasingly complex global regulatory environment, including the EU Cyber Resilience Act, UK Product Security requirements, and emerging international standards. You will translate evolving cybersecurity regulations into practical engineering processes that position Generac ahead of compliance requirements while strengthening customer trust and market differentiation. As a strategic enterprise leader, the Senior Director will partner closely with Engineering, Information Security, Legal, Quality, Product Management, and Business Leadership to build a world-class product security organization and culture. This leader will regularly engage with executive leadership, board members, customers, auditors, and regulatory agencies, serving as a trusted advisor on product security strategy, risk management, and secure innovation. This is a unique opportunity to influence how a global technology and energy solutions company designs, builds, and delivers its products while transforming product security into a sustainable competitive advantage for the future.

Why Join Generac? At Generac, you'll have the opportunity to shape the security strategy for a growing portfolio of connected energy solutions that power homes, businesses, and communities worldwide. Your leadership will directly influence product innovation, customer trust, regulatory readiness, and the future of secure energy technology.

MAJOR RESPONSIBILITIES
  • Product Security Strategy: Set the enterprise product security strategy and multi year roadmap, and embed secure by design as the standard across the product portfolio and the energy technology solutions and services that extend it.
  • Establish IEC 62443 as the primary product security framework, and define how its requirements apply across industrial, commercial, and consumer connected products.
  • Make product security a visible driver of customer trust and competitive differentiation, and represent it to customers, partners, auditors, and regulators.
  • Partner with engineering and product leadership so security requirements, threat models, and risk decisions are built into product design, development, and release.
  • Secure Development Lifecycle: Define and operationalize the secure development lifecycle that engineering teams build to, including threat modeling, secure coding, security testing, and security gates within the development process.
  • Lead the company toward formal certification of its secure development lifecycle against IEC 62443-4-1, advancing process maturity to the required level and preparing the organization for assessment by an accredited body.
  • Establish the foundations that position products and components for downstream certification, including IEC 62443-4-2 for components and IEC 62443-3-3 for systems.
  • Drive software bill of materials, secure software supply chain, and vulnerability management practices into the development lifecycle.
  • Product Security Incident Response: Build and lead the Product Security Incident Response capability that receives, triages, investigates, and resolves vulnerabilities and incidents affecting products in the field.
  • Establish coordinated vulnerability disclosure and handling practices aligned to ISO/IEC 29147 and ISO/IEC 30111, including a public intake channel and clear security advisories for customers.
  • Stand up the processes and reporting needed to meet regulatory timelines, including the EU Cyber Resilience Act obligation to report actively exploited vulnerabilities and severe incidents on a 24 hour, 72 hour, and final report cadence.
  • Partner with enterprise security operations and incident response so product and enterprise incidents are handled as one coordinated response.
  • Global Regulatory and Compliance Leadership: Lead the company's product security response to a fast moving global regulatory landscape, including the EU Cyber Resilience Act, the UK product security regime, and emerging product security regulations in other markets.
  • Translate new and emerging obligations into engineering requirements, evidence, and documentation, including conformity assessment, CE marking support, and declarations of conformity where required.
  • Maintain product security policies, standards, and control narratives, and own the evidence that demonstrates compliance to auditors, customers, and market surveillance authorities.
  • Track the regulatory horizon and advise executive leadership on the cost, risk, and timing of new requirements.
  • Organization and Talent: Build, staff, and develop a high performing product security organization, including managers and senior engineers, and establish product security as a respected discipline across the company.
  • Set clear direction, develop talent, and create a culture of ownership, engineering rigor, and customer focus.
  • Influence teams well beyond direct reports, embedding product security champions and practices within the engineering organizations of each business unit.
  • Manage product security tooling, services, and external partners, and steer investment toward the highest risk reduction.
Minimum Job Requirements
  • Education: Bachelor degree in Engineering, Computer Science, Cybersecurity, or related field. Equivalent experience considered.
  • Certification / License One or more of the following is strongly preferred: CISSP, CSSLP, GICSP, ISA or IEC 62443 certifications, or equivalent product and application security credentials.
  • Work Experience 12 years in cybersecurity, product security, or secure engineering, with progressive leadership responsibility.
  • 7 years leading teams, including leading other managers or senior engineers, ideally across multiple regions.
  • Proven record building or substantially maturing a product security program for connected, embedded, or industrial products.
  • Hands on leadership of a secure development lifecycle and a product security incident response capability.
  • Working experience applying IEC 62443 to real products, including familiarity with the path to IEC 62443-4-1 certification.
  • Experience navigating global product security regulations such as the EU Cyber Resilience Act or comparable regimes.
Preferred Job Requirements
  • Education: Advanced degree in Engineering, Cybersecurity, or Computer Science
  • Certification / License Additional ISA or IEC 62443, cloud, or product security certifications.
  • Work Experience Experience achieving or maintaining IEC 62443-4-1 certification of a secure development lifecycle.
  • Experience in energy, power, industrial, or connected consumer product environments.
  • Experience securing products that span operational technology, embedded systems, cloud connected services, and mobile applications.
  • Experience aligning product security with enterprise security, including shared incident response and governance.
Knowledge / Skills / Abilities
  • Deep knowledge of secure by design, the secure development lifecycle, threat modeling, and product vulnerability management.
  • Strong command of IEC 62443, including the secure development lifecycle requirements of 62443-4-1 and the component and system requirements of 62443-4-2 and 62443-3-3.
  • Working knowledge of the global product security regulatory landscape, including the EU Cyber Resilience Act, the UK product security regime, and comparable emerging regimes in other markets.
  • Practical understanding of product security incident response and coordinated vulnerability disclosure aligned to ISO/IEC 29147 and ISO/IEC 30111.
  • Ability to set enterprise strategy and translate it into engineering practice, evidence, and certification outcomes.
  • Excellent executive communication and influence, with the ability to represent product security to the board, customers, auditors, and regulators.
  • Demonstrated ability to build, develop, and retain a world class technical organization.

“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any other characteristic protected by law.” We believe power is a promise - a shared commitment to be there for others when it matters most. For more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen businesses and build a more resilient, efficient, sustainable energy future. Ready to Power a Smarter World with us? As one of the leaders and largest suppliers of power generation equipment and technology, the work we do touches millions of lives. Employees at Generac are encouraged to be innovative and are valued as an integral part of our global team. Our challenging goals develop knowledgeable employees dedicated to helping continue Generac’s success. Generac provides individuals the opportunity to work in a fast-paced agile work environment where their work makes a difference in people’s lives and their own.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Director Product Security
Senior Director Product Security

DR Power LLP • Waukesha (WI), Northern (KY)

Hybrid
USD 180,000 - 240,000
Senior Director Product Security
Senior Director Product Security

Generac • Waukesha (WI)

On-site
USD 190,000 - 270,000
Director Cybersecurity Operations
Director Cybersecurity Operations

Generac Power Systems Inc • North Prairie (WI)

On-site
USD 180,000 - 240,000
Director Cybersecurity Operations
Director Cybersecurity Operations

DR Power LLP • Waukesha (WI), Northern (KY)

Hybrid
USD 170,000 - 210,000
Director Cybersecurity Operations
Director Cybersecurity Operations

Generac Power Systems • Waukesha (WI)

On-site
USD 180,000 - 240,000
Senior Manager Engineering Firmware
Senior Manager Engineering Firmware

DR Power LLP • Waukesha (WI), Northern (KY)

Hybrid
USD 140,000 - 190,000
Product Support Designer
Product Support Designer

DR Power LLP • Sussex (WI)

Hybrid
USD 85,000 - 110,000
Product Support Engineer
Product Support Engineer

DR Power LLP • Beaver Dam (WI), Northern (KY)

On-site
USD 95,000 - 120,000
Product Support Engineer
Product Support Engineer

Generac Power Systems Inc • Town of Beaver Dam (WI)

On-site
USD 85,000 - 120,000
Product Support Engineer
Product Support Engineer

Generac Power Systems Inc • City of Berlin (WI)

On-site
USD 85,000 - 100,000