931,896open jobs
56,942companies
155,467added this week
Browse all
Salary
$142k – $200k per year
Location
In office (Westford)
Seniority
Architect · 12+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Sep 29, 2026. First seen by Alion on Aug 14, 2026. Johnson Controls scores A on the Alion truth index.

Overview
Company
Impact
Profile match
Johnson Controls International plc is a global technology and industrial leader specializing in smart building equipment, thermal management, and energy efficiency solutions. Legally headquartered in Cork, Ireland - with primary operational headquarters in Milwaukee/Glendale, Wisconsin - the multinational conglomerate operates across more than 150 countries.

Build your best future with the Johnson Controls team!

Who we are:

Johnson Controls is global leader in smart, healthy, and sustainable buildings. Our mission is to reimagine the performance of buildings to serve people, places, and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe. You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard - your next great opportunity is just a few clicks away!

What We Offer:

  • Competitive salary

  • Paid vacation/holidays/sick time

  • Comprehensive benefits package including 401K, medical, dental, and vision care.

  • On-the-job/cross-training opportunities

  • Encouraging and collaborative team environment

  • Dedication to safety through our Zero Harm policy

Position Summary

Johnson Controls Fire Solutions is seeking a strategic and influential Director, Product Security & Security Strategy to lead the cybersecurity vision, governance, and execution framework across a global portfolio of fire detection, suppression, life safety, connected devices, cloud platforms, mobile applications, and digital services.

This critical leadership role will be responsible for defining and advancing the Fire Solutions product security strategy while partnering closely with Enterprise Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and vulnerability management programs, drive Cyber Resilience Act (CRA) readiness and execution, and develop the organization's AI security threat response and governance capabilities.

The successful candidate will provide leadership across a complex global ecosystem of hardware, firmware, software, cloud, and IoT solutions, ensuring security is effectively integrated throughout the product lifecycle. This individual will translate cybersecurity requirements into practical engineering processes, improve security operational efficiency, and promote a culture of security ownership across the organization.

This position is critical to maintaining customer trust, meeting evolving cybersecurity expectations, supporting regulatory compliance initiatives, and ensuring the long-term success and resilience of the Fire Solutions business.

Key Responsibilities

Product Security Strategy & Leadership

  • Define and execute the Fire Solutions Product Security Strategy aligned with business objectives, customer expectations, and enterprise cybersecurity standards.

  • Partner with Johnson Controls Enterprise Security to establish security governance, policies, standards, and risk management frameworks across the product portfolio.

  • Serve as the senior product security leader for Fire Solutions and provide strategic cybersecurity guidance to business and engineering leadership.

  • Develop multi-year security roadmaps focused on improving product security maturity, resilience, and operational effectiveness.

  • Establish security metrics, KPIs, and executive reporting mechanisms to measure program effectiveness and risk reduction.

  • Drive a culture of security-by-design, accountability, and continuous improvement throughout the organization.

Security Governance & Compliance Execution

  • Lead the implementation of cybersecurity governance processes across the product development lifecycle.

  • Partner with Regulatory Affairs, Quality, Legal, and Engineering teams to operationalize cybersecurity requirements associated with emerging regulations and industry standards.

  • Translate regulatory cybersecurity requirements into scalable engineering processes, controls, documentation, and compliance evidence.

  • Support audit readiness activities, security assessments, certifications, and regulatory reviews.

  • Ensure cybersecurity requirements are integrated into product development, release, maintenance, and end-of-life processes.

  • Monitor industry trends, emerging threats, and evolving cybersecurity requirements to continuously improve security capabilities.

Cyber Resilience Act (CRA) Leadership

  • Lead the cybersecurity execution framework required to support CRA compliance across the Fire Solutions portfolio.

  • Work closely with Regulatory Affairs, which owns regulatory strategy and interpretation, to ensure cybersecurity obligations are effectively implemented within engineering and product development processes.

  • Establish and maintain processes supporting:

    • Secure development practices

    • Vulnerability management

    • Coordinated vulnerability disclosure

    • Software Bill of Materials (SBOM) management

    • Security documentation

    • Post-release monitoring and response

  • Coordinate cross-functional efforts to ensure sustainable compliance execution across global product teams.

  • Develop metrics and reporting to track cybersecurity compliance readiness and risk posture.

AI Security Governance & Threat Response

  • Define and lead the organization's AI security governance and threat response strategy.

  • Establish processes for identifying, assessing, mitigating, and responding to AI-related cybersecurity risks.

  • Partner with Enterprise Security and engineering teams to implement secure AI adoption practices and governance controls.

  • Evaluate AI-enabled product capabilities for cybersecurity risk and resilience.

  • Develop playbooks and response processes for AI-specific threats and vulnerabilities.

  • Leverage AI-driven security tools and automation to improve security effectiveness and operational efficiency.

Product Security Program Management

  • Drive adoption of secure development lifecycle (SSDLC) practices across hardware, firmware, software, cloud, mobile, and IoT product teams.

  • Lead threat modeling, security architecture reviews, risk assessments, and security design reviews.

  • Establish consistent security requirements for new product introductions and major platform enhancements.

  • Oversee security testing programs, penetration testing activities, and security validation processes.

  • Ensure security requirements are embedded throughout all phases of the product lifecycle.

Vulnerability Management & Incident Response

  • Establish and oversee global product vulnerability management processes.

  • Lead coordinated vulnerability disclosure and external vulnerability response activities.

  • Manage security incident response processes affecting products and connected services.

  • Develop remediation prioritization frameworks and risk-based decision-making processes.

  • Support customer communications and executive briefings related to cybersecurity issues and product security events.

  • Drive continual improvements in vulnerability response timelines and remediation effectiveness.

Security Process Excellence & Operational Efficiency

  • Design and implement scalable security processes that can be consistently adopted across global engineering organizations.

  • Identify opportunities to improve efficiency through process optimization, automation, and AI-assisted workflows.

  • Establish repeatable methods for security reviews, compliance evidence generation, risk assessments, and vulnerability tracking.

  • Define and measure operational performance indicators that demonstrate security program effectiveness and business impact.

  • Reduce friction in engineering processes while improving security outcomes and compliance readiness.

Global Leadership & Collaboration

  • Lead and influence geographically distributed teams and cross-functional stakeholders across multiple business functions.

  • Build strong partnerships with Enterprise Security, Regulatory Affairs, Quality, Product Management, Engineering, Operations, Legal, and Customer Support organizations.

  • Develop organizational capabilities, talent strategies, and succession plans within the product security function.

  • Drive alignment and decision-making across diverse technical and business stakeholders.

  • Serve as a trusted advisor to executive leadership on cybersecurity risks, investments, and priorities.

Customer & Industry Engagement

  • Represent Johnson Controls in customer discussions regarding product cybersecurity capabilities and security practices.

  • Support strategic customer engagements, audits, assessments, and security reviews.

  • Participate in industry working groups, standards organizations, and cybersecurity forums.

  • Maintain awareness of emerging technologies, threat landscapes, and industry best practices relevant to fire and life safety products.

Required Qualifications

  • Bachelor’s degree in computer science, Cybersecurity, Engineering, Information Technology, or a related technical discipline.

  • 12+ years of experience in cybersecurity, product security, software engineering, systems engineering, or related technical leadership roles.

  • 5+ years of experience leading large-scale security programs and influencing global organizations.

  • Demonstrated success developing and executing product security strategies within complex technology organizations.

  • Strong knowledge of product security, secure development practices, cloud security, IoT security, and vulnerability management.

  • Experience working closely with enterprise cybersecurity teams to implement governance, standards, and risk management frameworks.

  • Proven ability to drive cross-functional initiatives across engineering, product management, quality, and regulatory organizations.

  • Excellent leadership, communication, stakeholder management, and executive presentation skills.

Preferred Qualifications

  • Master's degree in Cybersecurity, Computer Science, Engineering, Business, or a related field.

  • Industry certifications such as CISSP, CISM, CRISC, CSSLP, GIAC, or equivalent.

  • Experience supporting products subject to cybersecurity regulations and compliance frameworks.

  • Knowledge of cybersecurity standards and frameworks including NIST, IEC 62443, ISO 27001, UL cybersecurity standards, and related industry practices.

  • Experience building and scaling product security organizations.

  • Experience implementing DevSecOps and security automation initiatives.

  • Knowledge of AI governance, AI security controls, and emerging AI threat landscapes.

Experience Required

The ideal candidate has successfully led cybersecurity and product security initiatives within global organizations that develop complex hardware and software products operating in highly regulated environments.

Global Product Experience

  • Experience supporting global product portfolios spanning:

    • Embedded systems

    • Hardware devices

    • Firmware platforms

    • Cloud services

    • Mobile applications

    • SaaS platforms

    • IoT and connected device ecosystems

  • Proven success integrating cybersecurity requirements across multiple product lines and technology stacks.

  • Experience balancing business objectives, customer needs, compliance requirements, and cybersecurity risk management.

Global Team Leadership & Communication

  • Demonstrated success leading globally distributed teams and influencing cross-functional organizations across multiple regions.

  • Ability to build alignment among engineering, product management, quality, regulatory, and cybersecurity stakeholders.

  • Strong executive presence with the ability to communicate complex technical concepts to both technical and non-technical audiences.

  • Experience driving organizational change and establishing company-wide security practices.

Highly Regulated Industry Experience

  • Experience within highly regulated industries such as:

    • Fire and life safety, Industrial automation, Building technologies, medical devices, Aerospace and defense, Critical infrastructure, Transportation systems, Energy or utility sectors

  • Experience supporting regulatory, audit, and compliance initiatives where cybersecurity requirements are critical to product development and market access.

  • Demonstrated ability to operationalize cybersecurity requirements within engineering organizations.

Hardware & Software Ecosystem Expertise

  • Deep understanding of securing products across an end-to-end technology ecosystem, including:

    • Hardware platforms

    • Embedded firmware

    • Edge devices

    • IoT architecture

    • Cloud infrastructure

    • Web applications

    • Mobile applications

    • APIs and connected services

  • Experience managing cybersecurity risks throughout the product lifecycle from concept and architecture through deployment, maintenance, and end-of-life support.

  • Knowledge of modern threat landscapes impacting connected devices, industrial systems, cloud platforms, and customer-facing applications.

Success Measures

Within the first 18-24 months, the Director will:

  • Establish and execute a comprehensive Fire Solutions Product Security Strategy.

  • Strengthen collaboration and operating models between Fire Solutions and Enterprise Security teams.

  • Implement scalable cybersecurity processes across the global product development organization.

  • Achieve sustainable CRA execution readiness across applicable product portfolios.

  • Establish a robust AI security governance and threat response framework.

  • Improve vulnerability management effectiveness and security response performance.

  • Increase security maturity through adoption of security-by-design and SSDLC practices.

  • Enhance security operational efficiency through automation, metrics, and process optimization.

  • Build strong partnerships across Engineering, Regulatory Affairs, Quality, Product Management, Program Management and Enterprise Security organizations.

SALARY RANGE: $142,000 - $200,000(Salary to be determined by the education, experience, knowledge, skills, and abilities of the applicant, internal equity, and alignment with market data.) This role offers a competitive Bonus plan that will take into account individual, group, and corporate performance. This position includes a competitive benefits package. The posted salary range reflects the target compensation for this role. However, we recognize that exceptional candidates may bring unique skills and experiences that exceed the typical profile. If you believe your background warrants consideration beyond the stated range, we encourage you to apply. To support an efficient and fair hiring process, we may use technology assisted tools, including artificial intelligence (AI), to help identify and evaluate candidates. All hiring decisions are ultimately made by human reviewers. For details, please visit the About Us tab on the Johnson Controls Careers site at https://jobs.johnsoncontrols.com/about-us

Johnson Controls International plc. is an equal employment opportunity and affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, sexual orientation, gender identity, status as a qualified individual with a disability or any other characteristic protected by law. To view more information about your equal opportunity and non-discrimination rights as a candidate, visitEEO is the Law. If you are an individual with a disability and you require an accommodation during the application process, please visit here.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
931,896 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Leadership
Similar stack
Same company
Westford
≈ $142k – $268k per year (Estimated) • In office • 15+ years exp • Bachelor's Degree • New York
Management
Agile
Apply
up to $170k per year • In office • 8+ years exp • Bachelor's Degree • Oak Brook
Design
AutoCAD
Management
Microsoft Office
Apply
≈ $140k – $280k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • United States
Apply
≈ $160k – $301k per year (Estimated) • In office • 12+ years exp • Bachelor's Degree • Durham
AI/ML
AI Agents
Apply
≈ $139k – $261k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Notre Dame
AI/ML
Machine Learning
Apply
≈ $51k – $135k per year (Estimated) • Remote (United States, Colombia, Mexico, Peru, Uruguay) • Full-Time
PHP
TypeScript
PHP
Laravel
AI/ML
Claude Code
AI Agents
DevOps
Datadog
AWS
Kubernetes
Amazon EKS
IAM
Cybersecurity
SOC 2
Threat Modeling
Apply
≈ $17k – $44k per year (Estimated) • Remote (likely EAEU) • Moscow
JavaScript
Kotlin
TypeScript
Node JS
Frontend
React.js
DevOps
GitLab CI
CI/CD
Git
GitLab
Linux
Cybersecurity
DefectDojo
STRIDE
CVE
Threat Modeling
КриптоПро
Apply
≈ $21k – $48k per year (Estimated) • In office • Full-Time • 3+ years exp • Bengaluru
Python
Go
AI/ML
Machine Learning
DevOps
Terraform
Helm
Azure
CI/CD
ArgoCD
Jenkins
AWS
Kubernetes
Amazon EKS
Azure AKS
IAM
DNS
Cybersecurity
Microsoft Defender
Least Privilege
SBOM
Microsoft Defender for Cloud
Kyverno
Microsoft Entra ID
Cryptography
Vault
Management
ServiceNow
Apply
≈ $21k – $54k per year (Estimated) • In office • Moscow
AI/ML
LLM
Machine Learning
Cybersecurity
Threat Modeling
OWASP
Apply
In office • India
Python
PowerShell
AI/ML
Copilot
Model Context Protocol
AI Agents
LLM Guardrails
DevOps
GitHub Actions
Platform Engineering
JFrog Artifactory
GitHub
Cybersecurity
SBOM
Apply
$120k – $150k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • New Freedom
Apply
$141k – $200k per year • In office • Full-Time • 15+ years exp • Bachelor's Degree • Westford
DevOps
CI/CD
Robotics
Digital Twin
Management
Agile
Apply
≈ $15k – $38k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bangkok
DevOps
Linux
Windows
Design
AutoCAD
Apply
≈ $33k – $85k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Shanghai
Analytics
Tableau
Power BI
Alteryx
Microsoft Excel
Master Data Management
Apply
≈ $15k – $38k per year (Estimated) • In office • Full-Time • 5+ years exp • Bachelor's Degree • Bangkok
DevOps
Linux
Windows
Design
AutoCAD
Apply
$272k – $431k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Westford • Austin • Durham
DevOps
Platform Engineering
eBPF
IAM
HPC
Cybersecurity
SOC 2
Zero Trust
Apply
$272k – $431k per year • Remote (United States) • Full-Time • 5+ years exp • Bachelor's Degree • Westford • Austin • Durham
AI/ML
LLM
DevOps
SLURM
Kubernetes
Shift-Left
Self-Healing
Cybersecurity
Shift-Left Security
Apply
$60k – $64k per year • In office • Part-Time • Westford
Management
Google Calendar
Apply
Finance Manager 5 days ago
$99k – $199k per year • In office • Full-Time • 7+ years exp • Bachelor's Degree • Westford
Apply
$168k – $265k per year • In office • Full-Time • 8+ years exp • Bachelor's Degree • Santa Clara • Westford • Austin • Durham • Boulder
Python
C++
SystemVerilog
Perl
AI/ML
Machine Learning
Chips/EDA
UVM
Synopsys Verdi
Apply
See all jobs
This is one of many
931,896 more open roles from verified company boards, updated every day.