Enter a job title or keyword

Security Compliance Analyst IV

Generac


Job Location:

Sussex, NJ - USA

Monthly Salary: Not provided by the employer
Posted: 27 August 2026 (10 days ago)
Application Deadline: 24 November 2026
Vacancies: 1 Vacancy

Job Summary

We believe power is a promise - a shared commitment to be there for others when it matters most.

For more than 65 years weve turned big ideas into solutions that help protect homes strengthen businesses and build a more resilient efficient sustainable energy future.


Ready to Power a Smarter World with us



We are seeking a highly experienced Security Compliance Analyst to join our EnterpriseITCompliance & Governance team. This role supports the foundational elements of the Generac Information Security Management System (ISMS) and enterprise compliance operations by governing the quality completeness and traceability of compliance evidence; facilitatingmultiframeworkassessments; maintaining centralized registers that ensure traceability between controls requirements exceptions and corrective actions; and governing exception and remediation activities.

This role functions as a subject matter expert and partners with business technology risk legal and audit teams to develop implement monitor and improve security controls and compliance programs that protect company assets and support organizational objectives. This positionleveragesauthoritative outputs from Risk Management Privacy and related governance functions to ensurethe organization meetsregulatory requirements contractual obligations andrelated governance functionstoenabletheorganization to meet regulatory requirements contractual obligations and industry standards in a sustainable consistent and auditable manner across all business units.

Major Responsibilities

ISMS Operations & Governance

  • Support the operation of the enterprise ISMS foundational layer in alignment with Generacs Compliance & Governance operating model.

  • Govern enterprise compliancegovernanceactivities across ISO 27001 NIST CSF 2.0 NIST 800171 TXRAMP and other applicable frameworks.

  • Leverage authoritative outputs from Risk Management Privacy and Incident Response to inform governance decisions and prioritization.

  • Execute complex taskslike regulatory exam execution deep-dive riskassessmentsandmassive IT system audits.

Framework Controls & Evidence Management

  • Operate andmaintainthecommonGeneracControlsFramework (GCF) including control mappings applicabilitylogicandevidenceexpectations.

  • Govern the quality completeness and traceability of compliance evidence across all enterprise control owners.

  • Maintain authoritative enterprise registers for controls requirements evidence exceptions corrective actions and assessments.

  • Support readiness assessments for emerging regulatory frameworksimpactingconnected products and digital systems (e.g. EU Cyber Resilience Act) including control mapping and evidence expectations.

Assessment & Audit Readiness

  • Facilitate enterprise compliance assessments readiness reviews and surveillance activities.

  • Coordinate internal and external audit activities and support auditor engagement andevidencevalidation.

  • Ensure enterprise frameworks and evidence expectations support regulated and contractual obligations whileexecutionremainswith designatedbusinessunitcompliance teams.

Exceptions & Corrective Actions

  • Govern the enterprise exception and corrective action lifecycle including intakeapprovalworkflows tracking and closure assurance.

  • Monitor systemic issues exception trends and remediation effectiveness across the enterprise.

Reporting Communication & Enablement

  • Produce enterprisecomplianceKPIs dashboards and managementreview inputs.

  • Provide governance guidance and communications to control owners to clarify expectations andevidencerequirements.

  • Contribute to enterprise security and compliance maturity assessments and trend reporting (e.g. NIST CSF 2.0) including baseline establishment andreassessmentsupport.

  • Handle heavy cross-functional coordination managing Plan of Action and Milestones(POA&Ms) and Liaising with external regulatory bodies.

Tooling Automation & Continuous Improvement

  • Operate enterprisecompliancetooling and workflows.

  • Support automation andAIgovernanceguardrails to improve scale consistency and auditability.

Minimum Job Requirements

Education

  • Bachelors degree (or higher) in Information Security Cybersecurity Information Technology ora relatedfield.

Certification / License

  • No certification isfor this role.

  • Foundational certifications such as ISO 27001 Lead Implementer or Lead Auditor CISA or other GRC-related credentials are considered an asset.

Work Experience

  • 7-10 years of highly specializedexperience in/with/for regulatedenvironments(FERC NERC) such as financial federal or defense sectors.

  • Experience in security compliance GRC operations ISMS support or control assurance within an enterprise environment.

  • Experienceactively supporting coordinating orfacilitatingcompliance assessments or audit readiness activities in a governance or assurance capacityacross frameworks such as ISO 27001 SOC 2 NIST-based frameworks or CMMC.

  • Experience working within multi-framework compliance programs including control mappingevidencegovernance and remediation tracking.

  • Experience coordinating compliance activities with distributed control owners and stakeholders across multiple business units or regions.

Knowledge / Skills / Abilities

  • Strong understanding of security controls compliance frameworks and governance practices.

  • ExperiencewithISO 27001 NIST CSF NIST 800171 / CMMC TXRAMP and related regulatory orcontractual standards.

  • Ability to interpret control requirements and assess the quality completeness and traceability of evidence provided by control owners.

  • Strong documentation analysis and workflow or register management skills supporting auditability and traceability.

  • Experience with enterprise compliance tooling structured registers or GRC platforms is beneficial.

  • Effective communication skills for working withcrossfunctionalstakeholders across business units and regions.

  • Ability to manage multiple concurrent compliance activities and deadlines in a distributed enterprise environment.

  • High attention to detail with strong organization andfollowthrough.

  • Ability to work independently and collaboratively within a global team.

  • Understanding of cloud environments (AWS Azure GCP) and their compliance andsharedresponsibiliyconsiderations.

  • Commitment to integrity accuracy and maintaining confidentiality of sensitive enterprise information.

We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation national origin disability status protected veteran status or any other characteristic protected by law.


Required Experience:

IC


About Company

Company Logo

Since 1959, Generac Power Systems has been committed to building the most reliable, durable, efficient, and environmentally-friendly generators and power equipment.

View Profile View Profile