Security Compliance Analyst IV

Posted 4 Days Ago
Be an Early Applicant
Sussex, WI, USA
In-Office
Senior level
Appliances • Industrial • Manufacturing
The Role
Governs enterprise security compliance and ISMS operations across ISO 27001, NIST, TX-RAMP, CMMC, and related frameworks. Manages control mappings, evidence quality, compliance registers, assessments, audits, exceptions, corrective actions, POA&Ms, reporting, and remediation tracking. Partners with risk, privacy, legal, audit, technology, and business teams while supporting regulatory readiness, GRC tooling, automation, and AI governance. Requires 7–10 years of specialized experience in regulated enterprise environments and strong understanding of cloud compliance.
Summary Generated by Built In
We believe power is a promise - a shared commitment to be there for others when it matters most.

For more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen businesses and build a more resilient, efficient, sustainable energy future.


Ready to Power a Smarter World with us?

We are seeking a highly experienced Security Compliance Analyst to join our Enterprise IT Compliance & Governance team. This role supports the foundational elements of the Generac Information Security Management System (ISMS) and enterprise compliance operations by governing the quality, completeness, and traceability of compliance evidence; facilitating multi‑framework assessments; maintaining centralized registers that ensure traceability between controls, requirements, exceptions, and corrective actions; and governing exception and remediation activities.  

  

This role functions as a subject matter expert and partners with business, technology, risk, legal, and audit teams to develop, implement, monitor, and improve security controls and compliance programs that protect company assets and support organizational objectives. This position leverages authoritative outputs from Risk Management, Privacy, and related governance functions to ensure the organization meets regulatory requirements, contractual obligations, and related governance functions to enable the organization to meet regulatory requirements, contractual obligations, and industry standards in a sustainable, consistent, and auditable manner across all business units. 

Major Responsibilities  

ISMS Operations & Governance 

  • Support the operation of the enterprise ISMS foundational layer in alignment with Generac’s Compliance & Governance operating model.   

  • Govern enterprise compliance governance activities across ISO 27001, NIST CSF 2.0, NIST 800171, TXRAMP, and other applicable frameworks.   

  • Leverage authoritative outputs from Risk Management, Privacy, and Incident Response to inform governance decisions and prioritization.  

  • Execute complex tasks like regulatory exam execution, deep-dive risk assessments , and massive IT system audits.  

Framework, Controls & Evidence Management 

  • Operate and maintain the common Generac Controls Framework (GCF), including control mappings, applicability logic and evidence expectations.   

  • Govern the quality, completeness, and traceability of compliance evidence across all enterprise control owners.   

  • Maintain authoritative enterprise registers for controls, requirements, evidence, exceptions, corrective actions, and assessments.  

  • Support readiness assessments for emerging regulatory frameworks impacting connected products and digital systems (e.g., EU Cyber Resilience Act), including control mapping and evidence expectations.  

Assessment & Audit Readiness 

  • Facilitate enterprise compliance assessments, readiness reviews, and surveillance activities.   

  • Coordinate internal and external audit activities and support auditor engagement and evidence validation.  

  • Ensure enterprise frameworks and evidence expectations support regulated and contractual obligations while execution remains with designated businessunit compliance teams.  

Exceptions & Corrective Actions 

  • Govern the enterprise exception and corrective action lifecycle, including intake, approval workflows, tracking, and closure assurance.  

  • Monitor systemic issues, exception trends, and remediation effectiveness across the enterprise.  

Reporting, Communication & Enablement  

  • Produce enterprise compliance KPIs, dashboards, and management review inputs.  

  • Provide governance guidance and communications to control owners to clarify expectations and evidence requirements.  

  • Contribute to enterprise security and compliance maturity assessments and trend reporting (e.g., NIST CSF 2.0), including baseline establishment and reassessment support.  

  • Handle heavy cross-functional coordination managing Plan of Action and Milestones (POA&Ms) and Liaising with external regulatory bodies. 

  •  

Tooling, Automation & Continuous Improvement 

  • Operate enterprise compliance tooling and workflows.  

  • Support automation and AIgovernance guardrails to improve scale, consistency, and auditability.  

 

Minimum Job Requirements 

Education 

  • Bachelor’s degree (or higher) in Information Security, Cybersecurity, Information Technology, or a related field.  

 

Certification / License 

  • No certification is required for this role.   

  • Foundational certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, or other GRC-related credentials are considered an asset.  

 

Work Experience 

  • 7-10 years of highly specialized experience in/with/for regulated environments (FERC, NERC) such as financial, federal, or defense sectors. 

  • Experience in security compliance, GRC operations, ISMS support, or control assurance within an enterprise environment.   

  • Experience actively supporting, coordinating, or facilitating compliance assessments or audit readiness activities in a governance or assurance capacity across frameworks such as ISO 27001, SOC 2, NIST-based frameworks, or CMMC.   

  • Experience working within multi-framework compliance programs, including control mapping, evidence governance, and remediation tracking.   

  • Experience coordinating compliance activities with distributed control owners and stakeholders across multiple business units or regions.  

 

Knowledge / Skills / Abilities 

  • Strong understanding of security controls, compliance frameworks, and governance practices.   

  • Experience with ISO 27001, NIST CSF, NIST 800171 / CMMC, TXRAMP, and related regulatory or contractual standards.   

  • Ability to interpret control requirements and assess the quality, completeness, and traceability of evidence provided by control owners.   

  • Strong documentation, analysis, and workflow or register management skills supporting auditability and traceability.   

  • Experience with enterprise compliance tooling, structured registers, or GRC platforms is beneficial.   

  • Effective communication skills for working with crossfunctional stakeholders across business units and regions.   

  • Ability to manage multiple concurrent compliance activities and deadlines in a distributed enterprise environment.   

  • High attention to detail with strong organization and followthrough.   

  • Ability to work independently and collaboratively within a global team.   

  • Understanding of cloud environments (AWS, Azure, GCP) and their compliance and sharedresponsibiliy considerations.  

  • Commitment to integrity, accuracy, and maintaining confidentiality of sensitive enterprise information.  

“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any other characteristic protected by law.”

Skills Required

  • Bachelor's degree or higher in Information Security, Cybersecurity, Information Technology, or a related field
  • 7–10 years of highly specialized experience in regulated environments such as financial, federal, defense, FERC, or NERC sectors
  • Experience in security compliance, GRC operations, ISMS support, or enterprise control assurance
  • Experience supporting, coordinating, or facilitating compliance assessments or audit readiness across ISO 27001, SOC 2, NIST-based frameworks, or CMMC
  • Experience with multi-framework compliance programs, control mapping, evidence governance, and remediation tracking
  • Experience coordinating compliance activities with distributed control owners and stakeholders across business units or regions
  • Strong understanding of security controls, compliance frameworks, and governance practices
  • Experience with ISO 27001, NIST CSF, NIST 800-171 or CMMC, TX-RAMP, and related regulatory or contractual standards
  • Ability to assess the quality, completeness, and traceability of control evidence
  • Strong documentation, analysis, workflow, and register management skills
  • Ability to manage multiple concurrent compliance activities and deadlines
  • Understanding of AWS, Azure, or GCP cloud environments and shared-responsibility compliance considerations
  • ISO 27001 Lead Implementer or Lead Auditor, CISA, or other GRC-related certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Waukesha, Wisconsin
3,437 Employees
Year Founded: 1959

What We Do

Generac is a leading energy technology company committed to powering a smarter world. Our purpose is to lead the evolution to a more resilient, efficient, and sustainable world through our backup and prime power systems. As a company, we are committed to sustainable, cleaner energy products poised to revolutionize the 21st century electrical grid. Founded in 1959, Generac introduced the first affordable backup generator and later created the category of automatic home standby generators. Generac’s people contribute to the company’s growth and success by living our corporate values everyday - integrity, innovation, agility, teamwork, and excellence. We foster a culture that supports diversity, equity, inclusivity, and good corporate citizenship, globally. If you're interested in powering your future with Generac, visit www.generac.com/about-us/careers to find a position that fits your career goals and celebrated talents. #PoweringPossibilities #ThePowerOfGenerac

Similar Jobs

Cox Enterprises Logo Cox Enterprises

Sales Strategy & Enablement Director

Artificial Intelligence • Automotive • Greentech • Information Technology • Machine Learning • Software • Cybersecurity
Remote or Hybrid
United States
30000 Employees
135K-225K Annually

Pfizer Logo Pfizer

HSS-Health and Science Specialist - Southern Maryland, MD

Artificial Intelligence • Healthtech • Machine Learning • Natural Language Processing • Biotech • Pharmaceutical
In-Office or Remote
3 Locations
121990 Employees
94K-165K Annually

DraftKings Logo DraftKings

Associate, Regulation

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
United States
6400 Employees
56K-70K Annually

Northwestern Mutual Logo Northwestern Mutual

Consultant

Fintech • Insurance • Financial Services
Remote or Hybrid
Wisconsin, USA
8400 Employees
89K-154K Annually

Similar Companies Hiring

Fortune Brands Innovations Thumbnail
Manufacturing
Deerfield, IL
10000 Employees
Rosendin Thumbnail
Other • Manufacturing
San Jose, CA
6219 Employees
Amalgamated Sugar Thumbnail
Food • Greentech • Agriculture • Industrial • Manufacturing
Boise, Idaho
768 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account