For more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen businesses and build a more resilient, efficient, sustainable energy future.
Ready to Power a Smarter World with us?
Generac is seeking a forward-thinking Senior Director, Product Security to lead and advance our enterprise-wide product security strategy across a rapidly expanding portfolio of connected products, energy technologies, software, and digital services. This highly visible leadership role is responsible for ensuring security is embedded into every stage of the product lifecycle, enabling our teams to deliver innovative solutions that are secure by design and trusted by customers around the world.
As the company’s foremost product security leader, you will define the frameworks, governance, and security standards that shape how we design, develop, deploy, and support connected technologies. Leveraging IEC 62443 as the foundation of our product security program, you will lead the evolution of our secure development lifecycle, drive enterprise-wide adoption of secure engineering practices, and establish best-in-class Product Security Incident Response capabilities that safeguard customers and products in the field.
This role will play a pivotal part in navigating an increasingly complex global regulatory environment, including the EU Cyber Resilience Act, UK Product Security requirements, and emerging international standards. You will translate evolving cybersecurity regulations into practical engineering processes that position Generac ahead of compliance requirements while strengthening customer trust and market differentiation.
As a strategic enterprise leader, the Senior Director will partner closely with Engineering, Information Security, Legal, Quality, Product Management, and Business Leadership to build a world-class product security organization and culture. This leader will regularly engage with executive leadership, board members, customers, auditors, and regulatory agencies, serving as a trusted advisor on product security strategy, risk management, and secure innovation.
This is a unique opportunity to influence how a global technology and energy solutions company designs, builds, and delivers its products while transforming product security into a sustainable competitive advantage for the future.
Why Join Generac?
At Generac, you'll have the opportunity to shape the security strategy for a growing portfolio of connected energy solutions that power homes, businesses, and communities worldwide. Your leadership will directly influence product innovation, customer trust, regulatory readiness, and the future of secure energy technology.
MAJOR RESPONSIBILITIES:
Product Security Strategy:
Set the enterprise product security strategy and multi year roadmap, and embed secure by design as the standard across the product portfolio and the energy technology solutions and services that extend it.
Establish IEC 62443 as the primary product security framework, and define how its requirements apply across industrial, commercial, and consumer connected products.
Make product security a visible driver of customer trust and competitive differentiation, and represent it to customers, partners, auditors, and regulators.
Partner with engineering and product leadership so security requirements, threat models, and risk decisions are built into product design, development, and release. Secure Development Lifecycle · Define and operationalize the secure development lifecycle that engineering teams build to, including threat modeling, secure coding, security testing, and security gates within the development process.
Lead the company toward formal certification of its secure development lifecycle against IEC 62443-4-1, advancing process maturity to the required level and preparing the organization for assessment by an accredited body. · Establish the foundations that position products and components for downstream certification, including IEC 62443-4-2 for components and IEC 62443-3-3 for systems.
Drive software bill of materials, secure software supply chain, and vulnerability management practices into the development lifecycle.
Product Security Incident Response:
Build and lead the Product Security Incident Response capability that receives, triages, investigates, and resolves vulnerabilities and incidents affecting products in the field.
Establish coordinated vulnerability disclosure and handling practices aligned to ISO/IEC 29147 and ISO/IEC 30111, including a public intake channel and clear security advisories for customers.
Stand up the processes and reporting needed to meet regulatory timelines, including the EU Cyber Resilience Act obligation to report actively exploited vulnerabilities and severe incidents on a 24 hour, 72 hour, and final report cadence.
Partner with enterprise security operations and incident response so product and enterprise incidents are handled as one coordinated response.
Global Regulatory and Compliance Leadership
Lead the company's product security response to a fast moving global regulatory landscape, including the EU Cyber Resilience Act, the UK product security regime, and emerging product security regulations in other markets.
Translate new and emerging obligations into engineering requirements, evidence, and documentation, including conformity assessment, CE marking support, and declarations of conformity where required.
Maintain product security policies, standards, and control narratives, and own the evidence that demonstrates compliance to auditors, customers, and market surveillance authorities.
Track the regulatory horizon and advise executive leadership on the cost, risk, and timing of new requirements.
Organization and Talent
Build, staff, and develop a high performing product security organization, including managers and senior engineers, and establish product security as a respected discipline across the company.
Set clear direction, develop talent, and create a culture of ownership, engineering rigor, and customer focus.
Influence teams well beyond direct reports, embedding product security champions and practices within the engineering organizations of each business unit.
Manage product security tooling, services, and external partners, and steer investment toward the highest risk
reduction.
Minimum Job Requirements:
Education:
Bachelor degree in Engineering, Computer Science, Cybersecurity, or related field. Equivalent experience considered.
Certification / License
One or more of the following is strongly preferred: CISSP, CSSLP, GICSP, ISA or IEC 62443 certifications, or equivalent product and application security credentials.
Work Experience
12 years in cybersecurity, product security, or secure engineering, with progressive leadership responsibility. · 7 years leading teams, including leading other managers or senior engineers, ideally across multiple regions.
Proven record building or substantially maturing a product security program for connected, embedded, or industrial products.
Hands on leadership of a secure development lifecycle and a product security incident response capability.
Working experience applying IEC 62443 to real products, including familiarity with the path to IEC 62443-4-1 certification.
Experience navigating global product security regulations such as the EU Cyber Resilience Act or comparable regimes.
Preferred Job Requirements
Education:
Advanced degree in Engineering, Cybersecurity, or Computer Science
Certification / License
Additional ISA or IEC 62443, cloud, or product security certifications.
Work Experience
Experience achieving or maintaining IEC 62443-4-1 certification of a secure development lifecycle. · Experience in energy, power, industrial, or connected consumer product environments.
Experience securing products that span operational technology, embedded systems, cloud connected services, and mobile applications.
Experience aligning product security with enterprise security, including shared incident response and governance.
Knowledge / Skills / Abilities
Deep knowledge of secure by design, the secure development lifecycle, threat modeling, and product vulnerability management.
Strong command of IEC 62443, including the secure development lifecycle requirements of 62443-4-1 and the component and system requirements of 62443-4-2 and 62443-3-3.
Working knowledge of the global product security regulatory landscape, including the EU Cyber Resilience Act, the UK product security regime, and comparable emerging regimes in other markets.
Practical understanding of product security incident response and coordinated vulnerability disclosure aligned to ISO/IEC 29147 and ISO/IEC 30111.
Ability to set enterprise strategy and translate it into engineering practice, evidence, and certification outcomes.
Excellent executive communication and influence, with the ability to represent product security to the board, customers, auditors, and regulators.
Demonstrated ability to build, develop, and retain a world class technical organization.
“We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any other characteristic protected by law.”
Skills Required
- Bachelor’s degree in Engineering, Computer Science, Cybersecurity, or a related field, or equivalent experience
- 12 years of experience in cybersecurity, product security, or secure engineering with progressive leadership responsibility
- 7 years leading teams, including managers or senior engineers, ideally across multiple regions
- Experience building or substantially maturing a product security program for connected, embedded, or industrial products
- Hands-on leadership of a secure development lifecycle and product security incident response capability
- Working experience applying IEC 62443 to real products, including familiarity with IEC 62443-4-1 certification
- Experience navigating global product security regulations such as the EU Cyber Resilience Act or comparable regimes
- Advanced degree in Engineering, Cybersecurity, or Computer Science
- CISSP, CSSLP, GICSP, ISA, IEC 62443, cloud, or equivalent product security certifications
- Experience achieving or maintaining IEC 62443-4-1 certification of a secure development lifecycle
- Experience in energy, power, industrial, or connected consumer product environments
- Experience securing products spanning operational technology, embedded systems, cloud-connected services, and mobile applications
- Experience aligning product security with enterprise security, including shared incident response and governance
- Deep knowledge of secure by design, secure development lifecycles, threat modeling, and product vulnerability management
- Strong command of IEC 62443-4-1, IEC 62443-4-2, and IEC 62443-3-3
- Working knowledge of global product security regulatory requirements
- Practical understanding of product security incident response and coordinated vulnerability disclosure aligned to ISO/IEC 29147 and ISO/IEC 30111
- Excellent executive communication and influence with boards, customers, auditors, and regulators
- Demonstrated ability to build, develop, and retain a world-class technical organization
What We Do
Generac is a leading energy technology company committed to powering a smarter world. Our purpose is to lead the evolution to a more resilient, efficient, and sustainable world through our backup and prime power systems. As a company, we are committed to sustainable, cleaner energy products poised to revolutionize the 21st century electrical grid. Founded in 1959, Generac introduced the first affordable backup generator and later created the category of automatic home standby generators. Generac’s people contribute to the company’s growth and success by living our corporate values everyday - integrity, innovation, agility, teamwork, and excellence. We foster a culture that supports diversity, equity, inclusivity, and good corporate citizenship, globally. If you're interested in powering your future with Generac, visit www.generac.com/about-us/careers to find a position that fits your career goals and celebrated talents. #PoweringPossibilities #ThePowerOfGenerac








