×
Register Here to Apply for Jobs or Post Jobs. X

Security Compliance Analyst IV

Job in Sussex, Waukesha County, Wisconsin, 53089, USA
Listing for: Generac
Full Time position
Listed on 2026-08-28
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Business Analyst
Job Description & How to Apply Below

Security Compliance Analyst

We are seeking a highly experienced Security Compliance Analyst to join our Enterprise IT Compliance & Governance team. This role supports the foundational elements of the Generac Information Security Management System (ISMS) and enterprise compliance operations by governing the quality, completeness, and traceability of compliance evidence; facilitating multi-framework assessments; maintaining centralized registers that ensure traceability between controls, requirements, exceptions, and corrective actions;

and governing exception and remediation activities.

This role functions as a subject matter expert and partners with business, technology, risk, legal, and audit teams to develop, implement, monitor, and improve security controls and compliance programs that protect company assets and support organizational objectives.

Major Responsibilities

ISMS Operations & Governance

  • Support the operation of the enterprise ISMS foundational layer in alignment with Generac's Compliance & Governance operating model.
  • Govern enterprise compliance governance activities across ISO 27001, NIST CSF 2.0, NIST 800-171, TX-RAMP, and other applicable frameworks.
  • Leverage authoritative outputs from Risk Management, Privacy, and Incident Response to inform governance decisions and prioritization.
  • Execute complex tasks like regulatory exam execution, deep-dive risk assessments, and massive IT system audits.

Framework, Controls & Evidence Management

  • Operate and maintain the common Generac Controls Framework (GCF), including control mappings, applicability logic, and evidence expectations.
  • Govern the quality, completeness, and traceability of compliance evidence across all enterprise control owners.
  • Maintain authoritative enterprise registers for controls, requirements, evidence, exceptions, corrective actions, and assessments.
  • Support readiness assessments for emerging regulatory frameworks impacting connected products and digital systems (e.g., EU Cyber Resilience Act), including control mapping and evidence expectations.

Assessment & Audit Readiness

  • Facilitate enterprise compliance assessments, readiness reviews, and surveillance activities.
  • Coordinate internal and external audit activities and support auditor engagement and evidence validation.
  • Ensure enterprise frameworks and evidence expectations support regulated and contractual obligations while execution remains with designated business-unit compliance teams.

Exceptions & Corrective Actions

  • Govern the enterprise exception and corrective action lifecycle, including intake, approval workflows, tracking, and closure assurance.
  • Monitor systemic issues, exception trends, and remediation effectiveness across the enterprise.

Reporting, Communication & Enablement

  • Produce enterprise compliance KPIs, dashboards, and management review inputs.
  • Provide governance guidance and communications to control owners to clarify expectations and evidence requirements.
  • Contribute to enterprise security and compliance maturity assessments and trend reporting (e.g., NIST CSF 2.0), including baseline establishment and re-assessment support.
  • Handle heavy cross-functional coordination managing Plan of Action and Milestones (POA&Ms) and liaising with external regulatory bodies.

Tooling, Automation & Continuous Improvement

  • Operate enterprise compliance tooling and workflows.
  • Support automation and AI-governance guardrails to improve scale, consistency, and auditability.

Minimum Job Requirements

Education

  • Bachelor's degree (or higher) in Information Security, Cybersecurity, Information Technology, or a related field.

Certification / License

  • No certification is required for this role.
  • Foundational certifications such as ISO 27001 Lead Implementer or Lead Auditor, CISA, or other GRC-related credentials are considered an asset.

Work Experience

  • 7-10 years of highly specialized experience in/with/for regulated environments (FERC, NERC) such as financial, federal, or defense sectors.
  • Experience in security compliance, GRC operations, ISMS support, or control assurance within an enterprise environment.
  • Experience actively supporting, coordinating, or facilitating compliance assessments or audit readiness…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary