JobsGenerac

Senior Director Product Security

Generac · Waukesha, WI

Posted Aug 31, 2026 · We last checked this listing on Sep 20, 2026

Apply at Generac

Likely interview questions for this role

Written from this job description, not a generic list. Each one notes what the interviewer is really checking.

Behavioral

Tell me about a time you built or significantly matured a product security program for connected or embedded products from a fairly immature starting point. What did you find when you got there, and what did you change first?

Whether the candidate has actually led a program from scratch versus operated inside an already-mature one

Describe a coordinated vulnerability disclosure case you've handled that got messy, maybe a researcher went public early or a fix took longer than promised. What did you do and what would you do differently now?

Real PSIRT incident experience and judgment under pressure, not textbook process knowledge

Tell me about a time you had to get engineering teams who didn't report to you to change how they build products. How did you get buy-in without authority?

Cross-functional influence, since this role's success depends on adoption far outside the direct reporting line

Tell me about a time you had to build out a security team, including hiring managers or senior engineers under you. What did you look for, and what mistake did you make along the way that taught you something?

Track record of building and developing a technical organization, not just individually contributing

Technical

Walk me through how you would apply IEC 62443-4-1 to Generac's engineering organization, and what it would take to get our secure development lifecycle ready for certification by an accredited body.

Real hands-on knowledge of 62443-4-1 process requirements versus surface familiarity with the standard's name

How would you explain the difference between IEC 62443-4-2 and 62443-3-3 to a product manager who has never heard of either, and why does that distinction matter when we're deciding what to certify first?

Ability to translate standards into terms engineering and business people can act on

How do you think about securing a product that spans OT, embedded firmware, a cloud backend, and a mobile app, all as one connected system? Where do the biggest gaps usually hide in that kind of architecture?

Depth across the full connected-product stack rather than expertise in just one layer

How would you decide what a software bill of materials and vulnerability management practice should actually catch, given that Generac's product portfolio spans industrial, commercial, and consumer devices with very different risk profiles?

Judgment on scoping and prioritizing SBOM and vulnerability management rather than applying one template everywhere

Situational

Say the EU Cyber Resilience Act requires us to report an actively exploited vulnerability within 24 hours of awareness. Walk me through what happens in your organization in that first day, from the moment someone reports it to the moment the report goes out.

Whether the candidate has actually built the operational plumbing for CRA timelines, not just read about them

Engineering leadership tells you that adding security gates to the release process will delay three major product launches this year. How do you handle that conversation?

Ability to hold a security standard under business pressure without becoming the department that says no

You're asked to brief the board on Generac's exposure under the EU Cyber Resilience Act and the UK product security regime. What are the two or three things you'd actually want them to walk away understanding?

Executive communication skill and ability to distill complex regulation into decision-relevant points

A customer's procurement team asks for evidence that a Generac product meets CE marking and Cyber Resilience Act conformity requirements, and the documentation isn't fully ready. What do you tell them, and what do you do internally in the following weeks?

Honesty and operational competence in managing compliance evidence and customer trust simultaneously

How do you decide where a shared incident response process ends and enterprise information security's process begins, when a product vulnerability turns out to also be a network intrusion?

Understanding of how product security and enterprise security should be coordinated rather than siloed

Practice this interview out loud.

Offer builds a real interview for this exact role at Generac from your resume and this job description, asks the questions one at a time, and tells you what landed. The first one is free.

Practice this out loud

The full job description

As published by Generac.

We believe power is a promise - a shared commitment to be there for others when it matters most. For more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen businesses and build a more resilient, efficient, sustainable energy future. Ready to Power a Smarter World with us? Generac is seeking a forward-thinking Senior Director, Product Security to lead and advance our enterprise-wide product security strategy across a rapidly expanding portfolio of connected products, energy technologies, software, and digital services. This highly visible leadership role is responsible for ensuring security is embedded into every stage of the product lifecycle, enabling our teams to deliver innovative solutions that are secure by design and trusted by customers around the world. As the company’s foremost product security leader, you will define the frameworks, governance, and security standards that shape how we design, develop, deploy, and support connected technologies. Leveraging IEC 62443 as the foundation of our product security program, you will lead the evolution of our secure development lifecycle, drive enterprise-wide adoption of secure engineering practices, and establish best-in-class Product Security Incident Response capabilities that safeguard customers and products in the field. This role will play a pivotal part in navigating an increasingly complex global regulatory environment, including the EU Cyber Resilience Act, UK Product Security requirements, and emerging international standards. You will translate evolving cybersecurity regulations into practical engineering processes that position Generac ahead of compliance requirements while strengthening customer trust and market differentiation. As a strategic enterprise leader, the Senior Director will partner closely with Engineering, Information Security, Legal, Quality, Product Management, and Business Leadership to build a world-class product security organization and culture. This leader will regularly engage with executive leadership, board members, customers, auditors, and regulatory agencies, serving as a trusted advisor on product security strategy, risk management, and secure innovation. This is a unique opportunity to influence how a global technology and energy solutions company designs, builds, and delivers its products while transforming product security into a sustainable competitive advantage for the future. Why Join Generac? At Generac, you'll have the opportunity to shape the security strategy for a growing portfolio of connected energy solutions that power homes, businesses, and communities worldwide. Your leadership will directly influence product innovation, customer trust, regulatory readiness, and the future of secure energy technology. MAJOR RESPONSIBILITIES: Product Security Strategy: • Set the enterprise product security strategy and multi year roadmap, and embed secure by design as the standard across the product portfolio and the energy technology solutions and services that extend it. • Establish IEC 62443 as the primary product security framework, and define how its requirements apply across industrial, commercial, and consumer connected products. • Make product security a visible driver of customer trust and competitive differentiation, and represent it to customers, partners, auditors, and regulators. • Partner with engineering and product leadership so security requirements, threat models, and risk decisions are built into product design, development, and release. Secure Development Lifecycle · Define and operationalize the secure development lifecycle that engineering teams build to, including threat modeling, secure coding, security testing, and security gates within the development process. • Lead the company toward formal certification of its secure development lifecycle against IEC 62443-4-1, advancing process maturity to the required level and preparing the organization for assessment by an accredited body. · Establish the foundations that position products and components for downstream certification, including IEC 62443-4-2 for components and IEC 62443-3-3 for systems. • Drive software bill of materials, secure software supply chain, and vulnerability management practices into the development lifecycle. Product Security Incident Response: • Build and lead the Product Security Incident Response capability that receives, triages, investigates, and resolves vulnerabilities and incidents affecting products in the field. • Establish coordinated vulnerability disclosure and handling practices aligned to ISO/IEC 29147 and ISO/IEC 30111, including a public intake channel and clear security advisories for customers. • Stand up the processes and reporting needed to meet regulatory timelines, including the EU Cyber Resilience Act obligation to report actively exploited vulnerabilities and severe incidents on a 24 hour, 72 hour, and final report cadence. • Partner with enterprise security operations and incident response so product and enterprise incidents are handled as one coordinated response.  • Global Regulatory and Compliance Leadership • Lead the company's product security response to a fast moving global regulatory landscape, including the EU Cyber Resilience Act, the UK product security regime, and emerging product security regulations in other markets. • Translate new and emerging obligations into engineering requirements, evidence, and documentation, including conformity assessment, CE marking support, and declarations of conformity where required. • Maintain product security policies, standards, and control narratives, and own the evidence that demonstrates compliance to auditors, customers, and market surveillance authorities. • Track the regulatory horizon and advise executive leadership on the cost, risk, and timing of new requirements. • Organization and Talent • Build, staff, and develop a high performing product security organization, including managers and senior engineers, and establish product security as a respected discipline across the company. • Set clear direction, develop talent, and create a culture of ownership, engineering rigor, and customer focus. • Influence teams well beyond direct reports, embedding product security champions and practices within the engineering organizations of each business unit. • Manage product security tooling, services, and external partners, and steer investment toward the highest risk • reduction. Minimum Job Requirements: Education: • Bachelor degree in Engineering, Computer Science, Cybersecurity, or related field. Equivalent experience considered.  Certification / License • One or more of the following is strongly preferred: CISSP, CSSLP, GICSP, ISA or IEC 62443 certifications, or equivalent product and application security credentials.  • Work Experience • 12 years in cybersecurity, product security, or secure engineering, with progressive leadership responsibility. · 7 years leading teams, including leading other managers or senior engineers, ideally across multiple regions. • Proven record building or substantially maturing a product security program for connected, embedded, or industrial products. • Hands on leadership of a secure development lifecycle and a product security incident response capability. • Working experience applying IEC 62443 to real products, including familiarity with the path to IEC 62443-4-1 certification.  • Experience navigating global product security regulations such as the EU Cyber Resilience Act or comparable regimes. Preferred Job Requirements Education: • Advanced degree in Engineering, Cybersecurity, or Computer Science • Certification / License • Additional ISA or IEC 62443, cloud, or product security certifications. Work Experience • Experience achieving or maintaining IEC 62443-4-1 certification of a secure development lifecycle. · Experience in energy, power, industrial, or connected consumer product environments. • Experience securing products that span operational technology, embedded systems, cloud connected services, and mobile applications.  • Experience aligning product security with enterprise security, including shared incident response and governance. Knowledge / Skills / Abilities • Deep knowledge of secure by design, the secure development lifecycle, threat modeling, and product vulnerability management.  • Strong command of IEC 62443, including the secure development lifecycle requirements of 62443-4-1 and the component and system requirements of 62443-4-2 and 62443-3-3. • Working knowledge of the global product security regulatory landscape, including the EU Cyber Resilience Act, the UK product security regime, and comparable emerging regimes in other markets. • Practical understanding of product security incident response and coordinated vulnerability disclosure aligned to ISO/IEC 29147 and ISO/IEC 30111. • Ability to set enterprise strategy and translate it into engineering practice, evidence, and certification outcomes.  • Excellent executive communication and influence, with the ability to represent product security to the board, customers, auditors, and regulators. • Demonstrated ability to build, develop, and retain a world class technical organization. “We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any other characteristic protected by law.”

Apply at Generac

Related jobs

New Product Sourcing Specialist - Purchasing

Generac · Waukesha, WI

Posted Sep 17 · Verified Sep 20

Intern Engineering - Advanced Manufacturing

Generac · Waukesha, WI

Posted Sep 17 · Verified Sep 20

Mechanical Engineer II

Generac · Sussex, WI

Posted Sep 17 · Verified Sep 20

Material Handler - Weekend Shift

Generac · Whitewater, WI

Posted Sep 17 · Verified Sep 20

Inside Sales Representative Residential

Generac · Pewaukee, WI

Posted Sep 17 · Verified Sep 20

Industrial Engineer I

Generac · Beaver Dam, WI

Posted Sep 16 · Verified Sep 20