Senior Product Security Assessor
Generac
5 - 10 years
Pune City
Posted: 15/06/2026
Job Description
Primary Purpose
The Senior Product Security Assessor is responsible for performing structured, risk-based security assessments across Generac products and platforms, spanning backend cloud services, DevSecOps pipelines, and IoT devices. This role is assessment-focused rather than build-focused, combining deep technical understanding with strong analytical and documentation skills. The assessor evaluates architectures, implementations, and controls against established security requirements and standards, particularly IEC 62443, and provides clear, actionable remediation guidance to engineering teams. This role aligns with the offshore Product Security engagement model and supports scalable, repeatable security reviews across the portfolio.
Major Responsibiliti
esConduct end-to-end product security assessments for cloud services, backend systems, DevSecOps pipelines, and IoT devices against defined security requirement
s.Evaluate security controls across application, infrastructure, device, and pipeline layers to identify gaps, weaknesses, and non-conformance
s.Perform assessments aligned to IEC 62443 and internal Generac product security standard
s.Clearly document assessment scope, findings, compliance status, and overall security postur
e.Perform structured threat modeling for identified findings and architectural designs across cloud, device, and DevSecOps domain
s.Assess risk severity and potential impact, considering exploitability, exposure, and business contex
t.Translate technical findings into clear risk statements that engineering and product teams can act upo
n.Assess backend cloud architectures, including containerized workloads and orchestrated environments, for secure configuration, network segmentation, identity controls, and data protectio
n.Review container security practices such as image scanning, runtime protections, and least-privilege configuration
s.Evaluate cloud logging, monitoring, and incident detection capabilities to ensure adequate security observabilit
y.Assess CI and CD pipelines to ensure security controls are integrated and consistently applie
d.Review use of SAST, DAST, SCA, and infrastructure-as-code scanning within development workflow
s.Evaluate secrets management, key handling, and signing processes used in build and release pipeline
s.Identify gaps in automation, enforcement, or visibility that could introduce security ris
k.Conduct IoT device security assessments covering hardware, firmware, and embedded softwar
e.Evaluate secure boot, firmware signing, credential storage, encryption, and update mechanism
s.Assess protections against physical tampering, reverse engineering, and unauthorized firmware modificatio
n.Review device compliance against IEC 62443-based device security requirement
s.Produce clear, structured assessment reports that document findings, risk ratings, and compliance gap
s.Provide prioritized, risk-informed remediation recommendations that are practical and actionabl
e.Support engineering teams by clarifying findings, answering technical questions, and validating remediation evidenc
e.Execute assessments in alignment with defined Product Security engagement models and timeline
s.Participate in regular checkpoints, status updates, and structured feedback session
s.Ensure consistency and quality across assessments through standardized templates and methodologie
s.
Educat
ionBachelors degree in Computer Science, Engineering, Cybersecurity, or a related technical field. Equivalent practical experience is also valu
ed.
Work Experi
ence5+ years of experience in product security, cloud security, DevSecOps, or IoT security ro
les.5+ years of IT audit experie
nce.The ability to manage up to 10 concurrent, complex aud
its.Hands-on experience performing threat modeling, vulnerability assessments, and security revi
ews.Strong understanding of backend cloud architectures, container platforms, and CI and CD pipeli
nes.Experience with IEC 62443 compliance assessments or similar industrial cybersecurity standards in production environme
nts.Experience conducting security assessments of IoT or embedded devices, including firmware analysis and hardware security evaluat
ion.Familiarity with DevSecOps tooling such as SAST, DAST, SCA, and infrastructure-as-code scanning platfo
rms.Experience with cloud security posture management in AWS, Azure, or GCP environme
nts.
Knowledge / Skills / Abil
itiesWorking knowledge of embedded systems, firmware security, and IoT security princi
ples.Mastery of security standards and frameworks such as IEC 62443, ISO 27001, and NIST 80
0-53.Ability to produce clear, concise, and high-quality security assessment documenta
tion.Clear communicator who can work across engineering, product, and security stakehol
ders.Preferred Job Require
ments
Certification / L
icenseCertifications such as CISSP, CCSP, CSSLP, or cloud security certifications are helpful but not req
Services you might be interested in
We Search & Apply Jobs for You!
Our team scans through 1000s of opportunities and applies to roles best suited to your profile
Save 100+ hours and focus on what matters - cracking interviews and landing offers.
