... Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and ...
... Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and ...
... Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and ...
... Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and ...
... Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and ...
... Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and ...
WHOOP is seeking a Director, Security Engineering & Operations to lead the teams responsible for enterprise security engineering and security operations. Reporting directly to the CISO and serving as ...
WHOOP is seeking a Director, Security Engineering & Operations to lead the teams responsible for enterprise security engineering and security operations. Reporting directly to the CISO and serving as ...
WHOOP is seeking a Director, Security Engineering & Operations to lead the teams responsible for enterprise security engineering and security operations. Reporting directly to the CISO and serving as ...
WHOOP is seeking a Director, Security Engineering & Operations to lead the teams responsible for enterprise security engineering and security operations. Reporting directly to the CISO and serving as ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
S. The Director, Security Engineering is responsible for the service delivery and engineering of the SIEM, EDR, SOAR, and other security platforms supporting Optiv's Managed Security Services (MSS ...
Role Summary Pinterest is looking for a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security ...
Role Summary Pinterest is looking for a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security ...
Role Summary Pinterest is looking for a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security ...
Role Summary Pinterest is looking for a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security ...
Role Summary Pinterest is looking for a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security ...
Role Summary Pinterest is looking for a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security ...
Role Summary Pinterest is looking for a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security ...
Role Summary Pinterest is looking for a Senior Director of Security Engineering to serve as the CISO's operating partner and lead the engineering execution for the entire Product and Cloud Security ...
As the Senior Director of Security Engineering, you will be responsible for building and leading a dedicated, humble, and paranoid team of Security Engineers to secure Ripple's products ...
As the Senior Director of Security Engineering, you will be responsible for building and leading a dedicated, humble, and paranoid team of Security Engineers to secure Ripple's products ...
As the Senior Director of Security Engineering, you will be responsible for building and leading a dedicated, humble, and paranoid team of Security Engineers to secure Ripple's products ...
As the Senior Director of Security Engineering, you will be responsible for building and leading a dedicated, humble, and paranoid team of Security Engineers to secure Ripple's products ...
Director Security Engineering information
See salary details
$73K - $89.5K
3% of jobs
$89.5K - $105.9K
5% of jobs
$105.9K - $122.4K
6% of jobs
$122.4K - $138.8K
9% of jobs
$140.1K is the 25th percentile. Wages below this are outliers.
$138.8K - $155.3K
11% of jobs
$155.3K - $171.7K
7% of jobs
$171.7K - $188.2K
7% of jobs
The median wage is $189.6K / yr.
$188.2K - $204.6K
6% of jobs
$204.6K - $221.1K
3% of jobs
$221.1K - $237.5K
1% of jobs
$243.7K is the 75th percentile. Wages above this are outliers.
$237.5K - $254K
40% of jobs
$73K
$194.7K
$254K
How much do director security engineering jobs pay per year?
What does a director of security engineering do?
How does a director of security engineering typically collaborate with other departments to ensure organizational security?
What are the key skills and qualifications needed to thrive as a director of security engineering, and why are they important?
What is the difference between Director Security Engineering vs Security Manager?
| Aspect | Director Security Engineering | Security Manager |
|---|---|---|
| Responsibilities | Oversees security architecture, strategy, and engineering teams; focuses on security infrastructure and long-term planning. | Manages security operations, implements policies, and handles day-to-day security incident response. |
| Required Credentials | Typically requires a bachelor's degree in cybersecurity, computer science, or related fields; certifications like CISSP or CISM are common. | Similar credentials as Director, often with CISSP, CISM, or Security+. |
| Work Environment | Strategic, leadership-focused, often in larger organizations or tech companies. | Operational, team management, and incident handling, often in various industries. |
The main difference between a Director Security Engineering and a Security Manager lies in scope and focus. The Director emphasizes security architecture and strategic planning, while the Security Manager concentrates on daily security operations and policy enforcement. Both roles require similar credentials and work in security-focused environments, but their responsibilities differ in scale and focus.
Is a director security engineering a stressful job?
What cities are hiring for Director Security Engineering jobs?
Cities with the most Director Security Engineering job openings:
What states have the most Director Security Engineering jobs?
States with the most job openings for Director Security Engineering jobs include:
What are popular job titles related to Director Security Engineering jobs?
For Director Security Engineering jobs, the most frequently searched job titles are:

Director Security Engineering
Westford, MA • On-site
Full-time
Medical, Dental, Vision, Retirement, PTO
Re-posted 11 days ago
Johnson Controls rating
8.0
Based on 416 frontline employees who took The Breakroom Quiz
Job description
Build your best future with the Johnson Controls team!
Who we are:
Johnson Controls is global leader in smart, healthy, and sustainable buildings. Our mission is to reimagine the performance of buildings to serve people, places, and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe. You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard - your next great opportunity is just a few clicks away!
What We Offer:
Competitive salary
Paid vacation/holidays/sick time
Comprehensive benefits package including 401K, medical, dental, and vision care.
On-the-job/cross-training opportunities
Encouraging and collaborative team environment
Dedication to safety through our Zero Harm policy
Position Summary
Johnson Controls Fire Solutions is seeking a strategic and influential Director, Product Security & Security Strategy to lead the cybersecurity vision, governance, and execution framework across a global portfolio of fire detection, suppression, life safety, connected devices, cloud platforms, mobile applications, and digital services.
This critical leadership role will be responsible for defining and advancing the Fire Solutions product security strategy while partnering closely with Enterprise Security, Engineering, Product Management, Regulatory Affairs, Quality, Legal, and Operations organizations. The Director will establish scalable security processes, lead cybersecurity risk and vulnerability management programs, drive Cyber Resilience Act (CRA) readiness and execution, and develop the organization's AI security threat response and governance capabilities.
The successful candidate will provide leadership across a complex global ecosystem of hardware, firmware, software, cloud, and IoT solutions, ensuring security is effectively integrated throughout the product lifecycle. This individual will translate cybersecurity requirements into practical engineering processes, improve security operational efficiency, and promote a culture of security ownership across the organization.
This position is critical to maintaining customer trust, meeting evolving cybersecurity expectations, supporting regulatory compliance initiatives, and ensuring the long-term success and resilience of the Fire Solutions business.
Key Responsibilities
Product Security Strategy & Leadership
Define and execute the Fire Solutions Product Security Strategy aligned with business objectives, customer expectations, and enterprise cybersecurity standards.
Partner with Johnson Controls Enterprise Security to establish security governance, policies, standards, and risk management frameworks across the product portfolio.
Serve as the senior product security leader for Fire Solutions and provide strategic cybersecurity guidance to business and engineering leadership.
Develop multi-year security roadmaps focused on improving product security maturity, resilience, and operational effectiveness.
Establish security metrics, KPIs, and executive reporting mechanisms to measure program effectiveness and risk reduction.
Drive a culture of security-by-design, accountability, and continuous improvement throughout the organization.
Security Governance & Compliance Execution
Lead the implementation of cybersecurity governance processes across the product development lifecycle.
Partner with Regulatory Affairs, Quality, Legal, and Engineering teams to operationalize cybersecurity requirements associated with emerging regulations and industry standards.
Translate regulatory cybersecurity requirements into scalable engineering processes, controls, documentation, and compliance evidence.
Support audit readiness activities, security assessments, certifications, and regulatory reviews.
Ensure cybersecurity requirements are integrated into product development, release, maintenance, and end-of-life processes.
Monitor industry trends, emerging threats, and evolving cybersecurity requirements to continuously improve security capabilities.
Cyber Resilience Act (CRA) Leadership
Lead the cybersecurity execution framework required to support CRA compliance across the Fire Solutions portfolio.
Work closely with Regulatory Affairs, which owns regulatory strategy and interpretation, to ensure cybersecurity obligations are effectively implemented within engineering and product development processes.
Establish and maintain processes supporting:
Secure development practices
Vulnerability management
Coordinated vulnerability disclosure
Software Bill of Materials (SBOM) management
Security documentation
Post-release monitoring and response
Coordinate cross-functional efforts to ensure sustainable compliance execution across global product teams.
Develop metrics and reporting to track cybersecurity compliance readiness and risk posture.
AI Security Governance & Threat Response
Define and lead the organization's AI security governance and threat response strategy.
Establish processes for identifying, assessing, mitigating, and responding to AI-related cybersecurity risks.
Partner with Enterprise Security and engineering teams to implement secure AI adoption practices and governance controls.
Evaluate AI-enabled product capabilities for cybersecurity risk and resilience.
Develop playbooks and response processes for AI-specific threats and vulnerabilities.
Leverage AI-driven security tools and automation to improve security effectiveness and operational efficiency.
Product Security Program Management
Drive adoption of secure development lifecycle (SSDLC) practices across hardware, firmware, software, cloud, mobile, and IoT product teams.
Lead threat modeling, security architecture reviews, risk assessments, and security design reviews.
Establish consistent security requirements for new product introductions and major platform enhancements.
Oversee security testing programs, penetration testing activities, and security validation processes.
Ensure security requirements are embedded throughout all phases of the product lifecycle.
Vulnerability Management & Incident Response
Establish and oversee global product vulnerability management processes.
Lead coordinated vulnerability disclosure and external vulnerability response activities.
Manage security incident response processes affecting products and connected services.
Develop remediation prioritization frameworks and risk-based decision-making processes.
Support customer communications and executive briefings related to cybersecurity issues and product security events.
Drive continual improvements in vulnerability response timelines and remediation effectiveness.
Security Process Excellence & Operational Efficiency
Design and implement scalable security processes that can be consistently adopted across global engineering organizations.
Identify opportunities to improve efficiency through process optimization, automation, and AI-assisted workflows.
Establish repeatable methods for security reviews, compliance evidence generation, risk assessments, and vulnerability tracking.
Define and measure operational performance indicators that demonstrate security program effectiveness and business impact.
Reduce friction in engineering processes while improving security outcomes and compliance readiness.
Global Leadership & Collaboration
Lead and influence geographically distributed teams and cross-functional stakeholders across multiple business functions.
Build strong partnerships with Enterprise Security, Regulatory Affairs, Quality, Product Management, Engineering, Operations, Legal, and Customer Support organizations.
Develop organizational capabilities, talent strategies, and succession plans within the product security function.
Drive alignment and decision-making across diverse technical and business stakeholders.
Serve as a trusted advisor to executive leadership on cybersecurity risks, investments, and priorities.
Customer & Industry Engagement
Represent Johnson Controls in customer discussions regarding product cybersecurity capabilities and security practices.
Support strategic customer engagements, audits, assessments, and security reviews.
Participate in industry working groups, standards organizations, and cybersecurity forums.
Maintain awareness of emerging technologies, threat landscapes, and industry best practices relevant to fire and life safety products.
Required Qualifications
Bachelor's degree in computer science, Cybersecurity, Engineering, Information Technology, or a related technical discipline.
12+ years of experience in cybersecurity, product security, software engineering, systems engineering, or related technical leadership roles.
5+ years of experience leading large-scale security programs and influencing global organizations.
Demonstrated success developing and executing product security strategies within complex technology organizations.
Strong knowledge of product security, secure development practices, cloud security, IoT security, and vulnerability management.
Experience working closely with enterprise cybersecurity teams to implement governance, standards, and risk management frameworks.
Proven ability to drive cross-functional initiatives across engineering, product management, quality, and regulatory organizations.
Excellent leadership, communication, stakeholder management, and executive presentation skills.
Preferred Qualifications
Master's degree in Cybersecurity, Computer Science, Engineering, Business, or a related field.
Industry certifications such as CISSP, CISM, CRISC, CSSLP, GIAC, or equivalent.
Experience supporting products subject to cybersecurity regulations and compliance frameworks.
Knowledge of cybersecurity standards and frameworks including NIST, IEC 62443, ISO 27001, UL cybersecurity standards, and related industry practices.
Experience building and scaling product security organizations.
Experience implementing DevSecOps and security automation initiatives.
Knowledge of AI governance, AI security controls, and emerging AI threat landscapes.
Experience Required
The ideal candidate has successfully led cybersecurity and product security initiatives within global organizations that develop complex hardware and software products operating in highly regulated environments.
Global Product Experience
Experience supporting global product portfolios spanning:
Embedded systems
Hardware devices
Firmware platforms
Cloud services
Mobile applications
SaaS platforms
IoT and connected device ecosystems
Proven success integrating cybersecurity requirements across multiple product lines and technology stacks.
Experience balancing business objectives, customer needs, compliance requirements, and cybersecurity risk management.
Global Team Leadership & Communication
Demonstrated success leading globally distributed teams and influencing cross-functional organizations across multiple regions.
Ability to build alignment among engineering, product management, quality, regulatory, and cybersecurity stakeholders.
Strong executive presence with the ability to communicate complex technical concepts to both technical and non-technical audiences.
Experience driving organizational change and establishing company-wide security practices.
Highly Regulated Industry Experience
Experience within highly regulated industries such as:
Fire and life safety, Industrial automation, Building technologies, medical devices, Aerospace and defense, Critical infrastructure, Transportation systems, Energy or utility sectors
Experience supporting regulatory, audit, and compliance initiatives where cybersecurity requirements are critical to product development and market access.
Demonstrated ability to operationalize cybersecurity requirements within engineering organizations.
Hardware & Software Ecosystem Expertise
Deep understanding of securing products across an end-to-end technology ecosystem, including:
Hardware platforms
Embedded firmware
Edge devices
IoT architecture
Cloud infrastructure
Web applications
Mobile applications
APIs and connected services
Experience managing cybersecurity risks throughout the product lifecycle from concept and architecture through deployment, maintenance, and end-of-life support.
Knowledge of modern threat landscapes impacting connected devices, industrial systems, cloud platforms, and customer-facing applications.
Success Measures
Within the first 18-24 months, the Director will:
Establish and execute a comprehensive Fire Solutio...
What Johnson Controls employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Johnson Controls
Sourced by ZipRecruiter
Johnson Controls is a world leader in smart buildings, creating safe, healthy and sustainable spaces. For nearly 140 years, we’ve made buildings better and now we’re transforming them again with our award-winning digital technologies and services. We’re using artificial intelligence and data driven solutions to give you deeper insight into your building’s health, sustainability and performance. It’s changing the way we design, operate and maintain indoor environments and driving to a new era of autonomous buildings. We deliver the blueprint of the future for industries such as healthcare, schools, data centers, airports, stadiums, hotels, manufacturing and beyond through OpenBlue, our comprehensive suite of connected solutions. Johnson Controls offers the world’s largest portfolio of building technology, software and services. Supported by a team of more than 100,000 dedicated employees working across 150 countries, we’re helping customers achieve their sustainability goals and power their mission.
Industry
Machinery manufacturing, water transportation, public safety statistics centers and offices and manufacturing
Company size
10,000+ Employees
Headquarters location
Milwaukee, WI, US