{"id":543143,"url":"https://alion.io/job/johnsoncontrols-director-security-engineering","title":"Director Security Engineering","company":{"id":448321,"name":"Johnson Controls","domain":"johnsoncontrols.com","url":"https://alion.io/company/johnsoncontrols-3","size_band":"5000+","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"A","score":88,"open_postings":702,"ghost_share":0.001,"stale_share":0.477,"repost_share":0.004,"time_to_fill_p50_days":24,"computed_at":"2026-09-30T05:45:00Z"}},"role":"Leadership","role_family":"Leadership","seniority":"head","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Westford, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":142000,"max":200000,"currency":"USD","period":"year","gross":null,"usd_annual":200000},"salary_estimate":null,"experience_years_min":12,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"SBOM","optional":false},{"name":"Threat Modeling","optional":false},{"name":"ISO 27001","optional":true}],"status":"live","first_seen_at":"2026-08-14T00:00:00Z","employer_posted_date":"2026-08-14","last_verified_at":"2026-09-30T23:02:01Z","board_verified":true,"closed_at":null,"days_open":48,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":48},"description":"Build your best future with the Johnson Controls team!\nWho we are:\nJohnson Controls is global leader in smart, healthy, and sustainable buildings. Our mission is to reimagine the performance of buildings to serve people, places, and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe. You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard - your next great opportunity is just a few clicks away!\nWhat We Offer:\nCompetitive salary\n\nPaid vacation/holidays/sick time\n\nComprehensive benefits package including 401K, medical, dental, and vision care.\n\nOn-the-job/cross-training opportunities\n\nEncouraging and collaborative team environment\n\nDedication to safety through our Zero Harm policy\n\nPosition Summary\nJohnson Controls Fire Solutions is seeking a strategic and influential Director, Product Security & Security Strategy to lead the cybersecurity vision, governance, and execution framework across a global portfolio of fire detection, suppression, life safety, connected devices, cloud platforms, mobile applications, and digital services.\nThis critical leadership role will be responsible for defining and advancing the Fire Solutions product security strategy while partnering closely with Enterprise Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and vulnerability management programs, drive Cyber Resilience Act (CRA) readiness and execution, and develop the organization's AI security threat response and governance capabilities.\nThe successful candidate will provide leadership across a complex global ecosystem of hardware, firmware, software, cloud, and IoT solutions, ensuring security is effectively integrated throughout the product lifecycle. This individual will translate cybersecurity requirements into practical engineering processes, improve security operational efficiency, and promote a culture of security ownership across the organization.\nThis position is critical to maintaining customer trust, meeting evolving cybersecurity expectations, supporting regulatory compliance initiatives, and ensuring the long-term success and resilience of the Fire Solutions business.\nKey Responsibilities\nProduct Security Strategy & Leadership\nDefine and execute the Fire Solutions Product Security Strategy aligned with business objectives, customer expectations, and enterprise cybersecurity standards.\n\nPartner with Johnson Controls Enterprise Security to establish security governance, policies, standards, and risk management frameworks across the product portfolio.\n\nServe as the senior product security leader for Fire Solutions and provide strategic cybersecurity guidance to business and engineering leadership.\n\nDevelop multi-year security roadmaps focused on improving product security maturity, resilience, and operational effectiveness.\n\nEstablish security metrics, KPIs, and executive reporting mechanisms to measure program effectiveness and risk reduction.\n\nDrive a culture of security-by-design, accountability, and continuous improvement throughout the organization.\n\nSecurity Governance & Compliance Execution\nLead the implementation of cybersecurity governance processes across the product development lifecycle.\n\nPartner with Regulatory Affairs, Quality, Legal, and Engineering teams to operationalize cybersecurity requirements associated with emerging regulations and industry standards.\n\nTranslate regulatory cybersecurity requirements into scalable engineering processes, controls, documentation, and compliance evidence.\n\nSupport audit readiness activities, security assessments, certifications, and regulatory reviews.\n\nEnsure cybersecurity requirements are integrated into product development, release, maintenance, and end-of-life processes.\n\nMonitor industry trends, emerging threats, and evolving cybersecurity requirements to continuously improve security capabilities.\n\nCyber Resilience Act (CRA) Leadership\nLead the cybersecurity execution framework required to support CRA compliance across the Fire Solutions portfolio.\n\nWork closely with Regulatory Affairs, which owns regulatory strategy and interpretation, to ensure cybersecurity obligations are effectively implemented within engineering and product development processes.\n\nEstablish and maintain processes supporting:\nSecure development practices\n\nVulnerability management\n\nCoordinated vulnerability disclosure\n\nSoftware Bill of Materials (SBOM) management\n\nSecurity documentation\n\nPost-release monitoring and response\n\nCoordinate cross-functional efforts to ensure sustainable compliance execution across global product teams.\n\nDevelop metrics and reporting to track cybersecurity compliance readiness and risk posture.\n\nAI Security Governance & Threat Response\nDefine and lead the organization's AI security governance and threat response strategy.\n\nEstablish processes for identifying, assessing, mitigating, and responding to AI-related cybersecurity risks.\n\nPartner with Enterprise Security and engineering teams to implement secure AI adoption practices and governance controls.\n\nEvaluate AI-enabled product capabilities for cybersecurity risk and resilience.\n\nDevelop playbooks and response processes for AI-specific threats and vulnerabilities.\n\nLeverage AI-driven security tools and automation to improve security effectiveness and operational efficiency.\n\nProduct Security Program Management\nDrive adoption of secure development lifecycle (SSDLC) practices across hardware, firmware, software, cloud, mobile, and IoT product teams.\n\nLead threat modeling, security architecture reviews, risk assessments, and security design reviews.\n\nEstablish consistent security requirements for new product introductions and major platform enhancements.\n\nOversee security testing programs, penetration testing activities, and security validation processes.\n\nEnsure security requirements are embedded throughout all phases of the product lifecycle.\n\nVulnerability Management & Incident Response\nEstablish and oversee global product vulnerability management processes.\n\nLead coordinated vulnerability disclosure and external vulnerability response activities.\n\nManage security incident response processes affecting products and connected services.\n\nDevelop remediation prioritization frameworks and risk-based decision-making processes.\n\nSupport customer communications and executive briefings related to cybersecurity issues and product security events.\n\nDrive continual improvements in vulnerability response timelines and remediation effectiveness.\n\nSecurity Process Excellence & Operational Efficiency\nDesign and implement scalable security processes that can be consistently adopted across global engineering organizations.\n\nIdentify opportunities to improve efficiency through process optimization, automation, and AI-assisted workflows.\n\nEstablish repeatable methods for security reviews, compliance evidence generation, risk assessments, and vulnerability tracking.\n\nDefine and measure operational performance indicators that demonstrate security program effectiveness and business impact.\n\nReduce friction in engineering processes while improving security outcomes and compliance readiness.\n\nGlobal Leadership & Collaboration\nLead and influence geographically distributed teams and cross-functional stakeholders across multiple business functions.\n\nBuild strong partnerships with Enterprise Security, Regulatory Affairs, Quality, Product Management, Engineering, Operations, Legal, and Customer Support organizations.\n\nDevelop organizational capabilities, talent strategies, and succession plans within the product security function.\n\nDrive alignment and decision-making across diverse technical and business stakeholders.\n\nServe as a trusted advisor to executive leadership on cybersecurity risks, investments, and priorities.\n\nCustomer & Industry Engagement\nRepresent Johnson Controls in customer discussions regarding product cybersecurity capabilities and security practices.\n\nSupport strategic customer engagements, audits, assessments, and security reviews.\n\nParticipate in industry working groups, standards organizations, and cybersecurity forums.\n\nMaintain awareness of emerging technologies, threat landscapes, and industry best practices relevant to fire and life safety products.\n\nRequired Qualifications\nBachelor’s degree in computer science, Cybersecurity, Engineering, Information Technology, or a related technical discipline.\n\n12+ years of experience in cybersecurity, product security, software engineering, systems engineering, or related technical leadership roles.\n\n5+ years of experience leading large-scale security programs and influencing global organizations.\n\nDemonstrated success developing and executing product security strategies within complex technology organizations.\n\nStrong knowledge of product security, secure development practices, cloud security, IoT security, and vulnerability management.\n\nExperience working closely with enterprise cybersecurity teams to implement governance, standards, and risk management frameworks.\n\nProven ability to drive cross-functional initiatives across engineering, product management, quality, and regulatory organizations.\n\nExcellent leadership, communication, stakeholder management, and executive presentation skills.\n\nPreferred Qualifications\nMaster's degree in Cybersecurity, Computer Science, Engineering, Business, or a related field.\n\nIndustry certifications such as CISSP, CISM, CRISC, CSSLP, GIAC, or equivalent.\n\nExperience supporting products subject to cybersecurity regulations and compliance frameworks.\n\nKnowledge of cybersecurity standards and frameworks including NIST, IEC 62443, ISO 27001, UL cybersecurity standards, and related industry practices.\n\nExperience building and scaling product security organizations.\n\nExperience implementing DevSecOps and security automation initiatives.\n\nKnowledge of AI governance, AI security controls, and emerging AI threat landscapes.\n\nExperience Required\nThe ideal candidate has successfully led cybersecurity and product security initiatives within global organizations that develop complex hardware and software products operating in highly regulated environments.\nGlobal Product Experience\nExperience supporting global product portfolios spanning:\nEmbedded systems\n\nHardware devices\n\nFirmware platforms\n\nCloud services\n\nMobile applications\n\nSaaS platforms\n\nIoT and connected device ecosystems\n\nProven success integrating cybersecurity requirements across multiple product lines and technology stacks.\n\nExperience balancing business objectives, customer needs, compliance requirements, and cybersecurity risk management.\n\nGlobal Team Leadership & Communication\nDemonstrated success leading globally distributed teams and influencing cross-functional organizations across multiple regions.\n\nAbility to build alignment among engineering, product management, quality, regulatory, and cybersecurity stakeholders.\n\nStrong executive presence with the ability to communicate complex technical concepts to both technical and non-technical audiences.\n\nExperience driving organizational change and establishing company-wide security practices.\n\nHighly Regulated Industry Experience\nExperience within highly regulated industries such as:\nFire and life safety, Industrial automation, Building technologies, medical devices, Aerospace and defense, Critical infrastructure, Transportation systems, Energy or utility sectors\n\nExperience supporting regulatory, audit, and compliance initiatives where cyber...","description_format":"text","description_chars":15384,"description_truncated":true,"requirements":{"experience_years_min":12,"management_years_min":5,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":["401k plan","Equity"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Information Security"],"lifecycle":[{"event":"open","at":"2026-09-08T09:56:12Z"}],"liveness":{"score":29,"band":"fade","label":"Fading","p_open":1,"p_active":0.807,"p_room":0.36,"age_days":47,"expected_fill_days":24,"reasons":["conf:2","velocity","win:tail","crowd:brand"],"computed_at":"2026-09-30T05:45:00Z"},"pay":{"stated_usd_annual":200000,"is_top_pay":false},"html_url":"https://alion.io/job/johnsoncontrols-director-security-engineering","json_url":"https://alion.io/job/johnsoncontrols-director-security-engineering.json","meta":{"generated_at":"2026-10-01T02:55:44Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2300,"day_limit":5000,"remaining_today":2700,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}