Director, Product Security – Secure Servicing (Remote)

Build your best future with the Johnson Controls team

As a global leader in smart, healthy and sustainable buildings, our mission is to reimagine the performance of buildings to serve people, places and the planet. Join a winning team that enables you to build your best future! Our teams are uniquely positioned to support a multitude of industries across the globe.

You will have the opportunity to develop yourself through meaningful work projects and learning opportunities. We strive to provide our employees with an experience, focused on supporting their physical, financial, and emotional wellbeing. Become a member of the Johnson Controls family and thrive in an empowering company culture where your voice and ideas will be heard – your next great opportunity is just a few clicks away!

What we offer

Competitive salary and bonus plan
Paid vacation/holidays/sick time
Comprehensive benefits package including 401K, medical, dental, and vision care – Available day one
Extensive product and on the job/cross training opportunities with outstanding internal resources
Encouraging and collaborative team environment
Dedication to safety through our Zero Harm policy
Check us Out: Day in the Life of the Building of the Future https://youtu.be/pdZMNrDJviY

What you will do

The future is being built today, and Johnson Controls is making that future more productive, more secure and more sustainable. We are harnessing the power of cloud, data analytics, the Internet of Things, and user design thinking to deliver on the promise of intelligent buildings and smart cities that connect communities in ways that make people’s lives – and the world – better.

In this career defining opportunity, you will report directly to the Chief Product Security Officer and lead cybersecurity initiatives which drive growth and differentiation for Johnson Controls. You will collaborate with stakeholders to ensure company programs, products, and solutions as installed and serviced in the field are compliant with Product Security governance. You will measure, influence, and lead initiatives around controls designed to reduce and / or mitigate cyber risk to our connect products’ customer base. In this pivotal role, you will lead efforts that ensure cybersecurity awareness amongst our Field Installation teams and reinforce customer trust in Johnson Controls products and solutions.

How you will do it

  • Lead and supervise a team of regional cybersecurity leaders to ensure your department’s initiatives are deployed consistently across all field sites and teams globally.
  • Manage an assessment program measuring compliance of installed products with controls such as hardening guides, NIST controls, and the ISA/IEC 62443 framework.
  • Provide departmental input on budget plans, forecasts, and expenditures for Product Security.
  • Manage multi-year vendor contracts and third-party partner relationships.
  • Coordinate with legal and other regulatory and compliance groups to ensure the company is compliant with key laws, regulations, and certifications.
  • Lead a Field Security Champion network of key field technicians to deploy training, communicate cyber guidance, and collect input and data on cyber aspects of field operations.
  • Assist in cybersecurity risk and technology assessment of merger and acquisition opportunities.
  • Use agile methodologies to manage resources and track milestones and deliverables.
  • Define, gather, and monitor meaningful metrics for compliance and continuous improvement.
  • Develop and maintain security technical documentation for internal and external use.
  • Occasionally participate in cybersecurity committees, boards, councils and working groups.

What we look for

  • Bachelor’s degree in computer science, engineering, cybersecurity, or another technical field required; Master’s degree preferred.
  • Minimum of 15 years of technical leadership experience with at least 7 years in cybersecurity.
  • Leadership experience managing product security governance and compliance requirements and risks.
  • Track record of building cohesive teams and collaborating successfully with other functions.
  • Technical and operational excellence, thought leadership, integrative thinking, and passion.
  • Excellent problem-solving skills with the ability to assess and translate cybersecurity requirements from various sources into practical plans and schedules.
  • Superior skill in written and verbal communications as well as planning/delivering presentations.
  • Experience with Building Operational Technologies (e.g. Controls Systems, Building Management) a plus.
  • Experience with technology related compliance and risk management related frameworks such as NIST SSDF / CSF, ISA/IEC 62443, ISO 27001, SOC 2 or others comparable.
  • CISSP, CISM, GISCP, CEH or related security certifications are a plus.
  • Travel is occasional at 10-20%, including international.

#LI-MJ1

#LI-Remote

Johnson Controls International plc. is an equal employment opportunity and affirmative action employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, protected veteran status, genetic information, sexual orientation, gender identity, status as a qualified individual with a disability or any other characteristic protected by law. To view more information about your equal opportunity and non-discrimination rights as a candidate, visit EEO is the Law. If you are an individual with a disability and you require an accommodation during the application process, please visit here.