Generac Power Systems

Security Compliance Analyst IV

Generac Power Systems$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, or related field.
  • 7-10 years in regulated environments such as financial, federal, or defense sectors.
  • Specialized experience in security compliance and ISMS support within enterprise environments.
  • Demonstrated experience with compliance assessments across frameworks like ISO 27001 and SOC 2.
  • Ability to manage compliance activities with distributed stakeholders, ensuring governance and communication effectively.

Responsibilities

  • Support the operation of the enterprise ISMS in line with compliance goals.
  • Govern compliance activities across major standards like ISO 27001 and NIST.
  • Leverage risk management outputs to guide compliance decisions.
  • Facilitate compliance assessments and auditing processes effectively.
  • Maintain authoritative registers for compliance controls and evidence across the enterprise.
  • Monitor compliance exception and corrective action trends and effectiveness.

Benefits

  • Collaborative work environment with cross-functional teams.
  • Opportunities for continuous improvement and automation of processes.
  • Engagement with external regulatory bodies and industry frameworks.
  • Development opportunities in security compliance and governance.
  • Access to enterprise compliance tools and resources.
Full Job Description
We are seeking a highly experienced Security Compliance Analyst to join our Enterprise IT Compliance & Governance team. This role supports the foundational elements of the Generac Information Security Management System (ISMS) and enterprise compliance operations by governing the quality, completeness, and traceability of compliance evidence; facilitating multi-framework assessments; maintaining centralized registers that ensure traceability between controls, requirements, exceptions, and corrective actions; and governing exception and remediation activities.

This role functions as a subject matter expert and partners with business, technology, risk, legal, and audit teams to develop, implement, monitor, and improve security controls and compliance programs that protect company assets and support organizational objectives. This position leverages authoritative outputs from Risk Management, Privacy, and related governance functions to ensure the organization meets regulatory requirements, contractual obligations, and related governance functions to enable the organization to meet regulatory requirements, contractual obligations, and industry standards in a sustainable, consistent, and auditable manner across all business units.

Major Responsibilities

ISMS Operations & Governance

  • Support the operation of the enterprise ISMS foundational layer in alignment with Generac's Compliance & Governance operating model.


  • Govern enterprise compliance governance activities across ISO 27001, NIST CSF 2.0, NIST 800-171, TX-RAMP, and other applicable frameworks.


  • Leverage authoritative outputs from Risk Management, Privacy, and Incident Response to inform governance decisions and prioritization.


  • Execute complex tasks like regulatory exam execution, deep-dive risk assessments , and massive IT system audits.


Framework, Controls & Evidence Management

  • Operate and maintain the common Generac Controls Framework (GCF), including control mappings, applicability logic and evidence expectations.


  • Govern the quality, completeness, and traceability of compliance evidence across all enterprise control owners.


  • Maintain authoritative enterprise registers for controls, requirements, evidence, exceptions, corrective actions, and assessments.


  • Support readiness assessments for emerging regulatory frameworks impacting connected products and digital systems (e.g., EU Cyber Resilience Act), including control mapping and evidence expectations.


Assessment & Audit Readiness

  • Facilitate enterprise compliance assessments, readiness reviews, and surveillance activities.


  • Coordinate internal and external audit activities and support auditor engagement and evidence validation.


  • Ensure enterprise frameworks and evidence expectations support regulated and contractual obligations while execution remains with designated business-unit compliance teams.


Exceptions & Corrective Actions

  • Govern the enterprise exception and corrective action lifecycle, including intake, approval workflows, tracking, and closure assurance.


  • Monitor systemic issues, exception trends, and remediation effectiveness across the enterprise.


Reporting, Communication & Enablement

  • Produce enterprise compliance KPIs, dashboards, and management review inputs.


  • Provide governance guidance and communications to control owners to clarify expectations and evidence requirements.


  • Contribute to enterprise security and compliance maturity assessments and trend reporting (e.g., NIST CSF 2.0), including baseline establishment and re-assessment support.


  • Handle heavy cross-functional coordination managing Plan of Action and Milestones (POA&Ms) and Liaising with external regulatory bodies.


Tooling, Automation & Continuous Improvement

  • Operate enterprise compliance tooling and workflows.


  • Support automation and AI-governance guardrails to improve scale, consistency, and auditability.


Minimum Job Requirements

Education

  • Bachelor's degree (or higher) in Information Security, Cybersecurity, Information Technology, or a related field.


Certification / License

  • No certification is required for this role.


  • Foundational certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, or other GRC-related credentials are considered an asset.


Work Experience

  • 7-10 years of highly specialized experience in/with/for regulated environments (FERC, NERC) such as financial, federal, or defense sectors.


  • Experience in security compliance, GRC operations, ISMS support, or control assurance within an enterprise environment.


  • Experience actively supporting, coordinating, or facilitating compliance assessments or audit readiness activities in a governance or assurance capacity across frameworks such as ISO 27001, SOC 2, NIST-based frameworks, or CMMC.


  • Experience working within multi-framework compliance programs, including control mapping, evidence governance, and remediation tracking.


  • Experience coordinating compliance activities with distributed control owners and stakeholders across multiple business units or regions.


Knowledge / Skills / Abilities

  • Strong understanding of security controls, compliance frameworks, and governance practices.


  • Experience with ISO 27001, NIST CSF, NIST 800-171 / CMMC, TXRAMP, and related regulatory or contractual standards.


  • Ability to interpret control requirements and assess the quality, completeness, and traceability of evidence provided by control owners.


  • Strong documentation, analysis, and workflow or register management skills supporting auditability and traceability.


  • Experience with enterprise compliance tooling, structured registers, or GRC platforms is beneficial.


  • Effective communication skills for working with cross-functional stakeholders across business units and regions.


  • Ability to manage multiple concurrent compliance activities and deadlines in a distributed enterprise environment.


  • High attention to detail with strong organization and follow-through.


  • Ability to work independently and collaboratively within a global team.


  • Understanding of cloud environments (AWS, Azure, GCP) and their compliance and shared-responsibiliy considerations.


  • Commitment to integrity, accuracy, and maintaining confidentiality of sensitive enterprise information.


About Generac Power Systems

Generac Power Systems is a manufacturer of backup power generation products for residential, commercial, and industrial customers. The company was founded in 1959 and is headquartered in Waukesha, Wisconsin. Generac operates through two business segments: Domestic and International. The Domestic segment produces generators, transfer switches, and other backup power equipment for residential and commercial customers in the United States. The International segment produces similar products for customers outside the United States. Generac sells its products through a network of dealers and distributors.
Learn more about Generac Power Systems
Size
8,955 employees
Market Cap
$5.6 billion
Industry
Net Income
$350.5 million
Founded
1959
5 Year Trend
+20.9%
Revenue
$2.4 billion
NASDAQ

Similar Jobs

More Jobs at Generac Power Systems

More Information Technology Jobs

Find similar Security Compliance Analyst IV jobs: