ForgeApply
Try it free

ForgeApply · Job listing

Security Compliance Analyst IV

Generac

Sussex, WI - USA, USonsite

See all 136 open roles at Generac

Tailor your resume for this Generac job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for Generac's site. Free trial, no card required.

About this role

We believe power is a promise - a shared commitment to be there for others when it matters most.

For more than 65 years, we've turned big ideas into solutions that help protect homes, strengthen businesses and build a more resilient, efficient, sustainable energy future.

Ready to Power a Smarter World with us?

We are seeking a highly experienced Security Compliance Analyst to join our Enterprise IT Compliance & Governance team. This role supports the foundational elements of the Generac Information Security Management System (ISMS) and enterprise compliance operations by governing the quality, completeness, and traceability of compliance evidence; facilitating multi‑framework assessments; maintaining centralized registers that ensure traceability between controls, requirements, exceptions, and corrective actions; and governing exception and remediation activities.      This role functions as a subject matter expert and partners with business, technology, risk, legal, and audit teams to develop, implement, monitor, and improve security controls and compliance programs that protect company assets and support organizational objectives. This position leverages authoritative outputs from Risk Management, Privacy, and related governance functions to ensure the organization meets regulatory requirements, contractual obligations, and related governance functions to enable the organization to meet regulatory requirements, contractual obligations, and industry standards in a sustainable, consistent, and auditable manner across all business units. 

Major Responsibilities     

ISMS Operations & Governance    

• Support the operation of the enterprise ISMS foundational layer in alignment with Generac’s Compliance & Governance operating model.    

• Govern enterprise compliance governance activities across ISO 27001, NIST CSF 2.0, NIST 800 ‑ 171, TX ‑ RAMP, and other applicable frameworks.    

• Leverage authoritative outputs from Risk Management, Privacy, and Incident Response to inform governance decisions and prioritization.   

• Execute complex tasks like regulatory exam execution, deep-dive risk  assessments  ,   and   massive IT system audits.   

Framework, Controls & Evidence Management    

• Operate and  maintain  the common Generac Controls Framework (GCF), including control mappings, applicability  logic  and evidence expectations.    

• Govern the quality, completeness, and traceability of compliance evidence across all enterprise control owners.    

• Maintain authoritative enterprise registers for controls, requirements, evidence, exceptions, corrective actions, and assessments.   

• Support readiness assessments for emerging regulatory frameworks  impacting  connected products and digital systems (e.g., EU Cyber Resilience Act), including control mapping and evidence expectations.   

Assessment & Audit Readiness    

• Facilitate enterprise compliance assessments, readiness reviews, and surveillance activities.    

• Coordinate internal and external audit activities and support auditor engagement and  evidence  validation.   

• Ensure enterprise frameworks and evidence expectations support regulated and contractual obligations while execution  remains  with designated   business ‑ unit   compliance teams.   

Exceptions & Corrective Actions    

• Govern the enterprise exception and corrective action lifecycle, including intake,  approval  workflows, tracking, and closure assurance.   

• Monitor systemic issues, exception trends, and remediation effectiveness across the enterprise.   

Reporting, Communication & Enablement      

• Produce enterprise   compliance   KPIs, dashboards, and management   review inputs.   

• Provide governance guidance and communications to control owners to clarify expectations and  evidence  requirements.   

• Contribute to enterprise security and compliance maturity assessments and trend reporting (e.g., NIST CSF 2.0), including baseline establishment and   re ‑ assessment   support.   

• H andle heavy cross-functional coordination managing Plan of Action and Mile stones   (POA &Ms) and Liaising with external regulatory bodies.  

•  

Tooling, Automation & Continuous Improvement    

• Operate enterprise  compliance  tooling and workflows.   

• Support automation and   AI ‑ governance   guardrails to improve scale, consistency, and auditability.   

Minimum Job Requirements    

Education    

• Bachelor’s degree (or higher) in Information Security, Cybersecurity, Information Technology, or  a related  field.   

Certification / License    

• No certification is  required  for this role.    

• Foundational certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, or other GRC-related credentials are considered an asset.   

Work Experience    

• 7-10 years of highly s p ecialized   e xperience in/with/ for regulated   environments   (FERC, NE RC) such as financial, federal, or def ense sect ors .  

• E xperience in security compliance, GRC operations, ISMS support, or control assurance within an enterprise environment.    

• Experience   actively supporting, coordinating, or  facilitating  compliance assessments or audit readiness activities in a governance or assurance capacity across frameworks such as ISO 27001, SOC 2, NIST-based frameworks, or CMMC.    

• Experience working within multi-framework compliance programs, including control mapping,  evidence  governance, and remediation tracking.    

• Experience coordinating compliance activities with distributed control owners and stakeholders across multiple business units or regions.   

Knowledge / Skills / Abilities    

• Strong understanding of security controls, compliance frameworks, and governance practices.    

• Experience   with   ISO 27001, NIST CSF, NIST 800 ‑ 171 / CMMC, TXRAMP, and related regulatory or   contractual standards.    

• Ability to interpret control requirements and assess the quality, completeness, and traceabi

Tailor your resume for this Generac role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · No Salary on the Job Posting? How to Find the Number Before You Interview