Provider of regulated electricity and natural gas delivery with major grid modernization investments.
Ensures PPL's cybersecurity compliance with NERC CIP, TSA and other regulatory standards.
5 days ago ago
Expert & Leadership (13+ years)
Full Time
Louisville, KY
Office Full-Time
Company Size
9,657 Employees
Service Specialisms
Construction services
Engineering
Project Management
Consulting
Technical Services
Design
Turnkey
General Contractor
Sector Specialisms
Electric Distribution
Electric Transmission
Gas Distribution
Gas Transmission
Regulated Generation
Power Generation
Wholesale Energy Sales
Retail Energy Supply
Role
Description
root cause
compliance assessment
documentation
security research
audit support
project planning
Coordinates event and root cause analysis to identify gaps in controls including advising and supporting management in defining appropriate remedial actions and tracking.
Performs assessments, helps the organization institute, and monitor compliance with cybersecurity framework and regulatory requirements.
Maintains accurate and up-to-date documentation related to NERC CIP Compliance, and other compliance frameworks.
Plays a role in complex problem analysis and makes recommendations for how to advance PPL’s cybersecurity compliance profile and culture with a team of motivated individuals.
Provides high level research on internal projects, recommending strategic directions and plans that address company-wide security issues. This includes projects related to CIP implementations.
Balances security best practices and business drivers against framework requirements, business risk, and impact to make recommendations that minimize PPL’s risk profile.
Identifies opportunities for continuous improvement in Cybersecurity’s compliance program.
Supports teams in regulatory audits, spot-checks, and self-certifications including mock audits.
Participates in compliance activities including providing consulting assistance with business areas and IT groups for cybersecurity compliance standards, policies, procedures, and measures.
Assists in preparing for compliance audits where responsibilities include developing Reliability Standard Audit Worksheets (RSAWs) and compiling supporting evidentiary documentation.
Collaborates with relevant stakeholders in the development of audit responses and remediation plans for any identified findings.
Contributes to developing, implementing, and evaluating project plans, goals, and timelines for the implementation of internal controls across all applicable standards.
Requirements
nist
soc
nerc cip
bachelor's
compliance
critical thinking
Experience preparing and presenting complex topics to non-technical audiences, at various levels within the organization.
Collaborative and effective in cross-functional team environments.
Experience in examining and evaluating internal controls based on regulatory requirements to ensure adherence to the requirements is performed.
Working knowledge of security related frameworks and activities including, but not limited to, NIST Cybersecurity Framework, SOC 1, SOC 2, etc.
Demonstrated ability to lead projects and assignments and perform multiple activities concurrently.
Critical thinking skills with the ability to identify and solve complex problems with limited managerial oversight.
Experience with applying compliance frameworks, to successfully comply with security policies, standards, and guidelines.
Bachelor’s degree in Computer Science, Information Security, and/or a related field or an equivalent level of work related experience.
Effective written, verbal, and interpersonal communication skills along with outstanding attention to detail with dedication to encouraging a culture of compliance and security.
Effectively communicates with clients, peers and management in security matters in both verbal and written form.
Strong analytical skills to assess risks and vulnerabilities in complex systems.
Understanding of requirements gathering, discovery, service mapping, problem management, asset management, project management, and service catalogs as they relate to regulatory compliance.
Proven experience establishing, managing, and validating compliance requirements with internal and external parties.
Experience with NERC CIP regulatory requirements, such as standards development, controls framework development, or compliance.
2 or more years of work experience in a compliance or audit focused position or equivalent (Intermediate)
Experience creating, implementing, and documenting internal processes and technology to enhance compliance, efficiency, and education.
5 or more years of work experience in a compliance or audit focused position or equivalent (Senior)
The company was established in 1920 as Pennsylvania Power & Light, marking the beginning of its journey in the energy sector.
$14 billion invested
Infrastructure Investment
Over recent years, the company has invested over $14 billion to modernize its grid and strengthen infrastructure.
$7–8 billion annual revenue
Financial Performance
The company generates approximately $7–8 billion in annual revenue, reflecting its position as a large-cap utility provider.
50 J.D. Power awards
Customer Satisfaction Recognition
Its grid modernization efforts have earned national recognition, including over 50 J.D. Power awards for customer satisfaction.
Headquartered in Allentown, Pennsylvania, it operates across Pennsylvania, Kentucky, Virginia, and Rhode Island.
Structured into three regulated segments—Kentucky, Pennsylvania, and Rhode Island—it delivers both electricity and natural gas.
Over recent years, it has invested more than $14 billion (up to $20 billion by 2028) to modernize its grid and strengthen infrastructure.
Typical projects include transmission upgrades, smart-grid technology deployment, and large-scale infrastructure resilience enhancements.
Its grid modernization efforts have earned national recognition, including over 50 J.D. Power awards for customer satisfaction.
Notably, after spinning off non-regulated generation in 2015 and selling UK operations in 2021, it refocused on U.S. utilities and acquired Rhode Island Energy in 2022.
Culture + Values
Safety and Health: We do not compromise on safety and health.
Customer Focus: We deliver customer service that is second to none.
Diversity, Equity and Inclusion: We value each other and appreciate our differences.
Performance Excellence and Innovation: We get the job done right, and we are always improving.
Integrity and Openness: We do the right thing.
Corporate Citizenship: We are environmentally conscious and invested in the communities we serve.
Environment + Sustainability
Net-zero by 2050
Carbon Emissions Target
Aiming to achieve net-zero carbon emissions by 2050 through comprehensive sustainability strategies.
70% and 80% Reduction
CO2 and GHG Emissions Targets
Reduction targets for CO2 and other greenhouse gases, with 70% by 2035 and 80% by 2040 from 2010 levels.
$20B Investment
Infrastructure Modernization
Invested $20 billion over the last decade to modernize transmission and distribution infrastructure in Pennsylvania and Kentucky.
$2.4B Improvements
Infrastructure Completed 2023
Completed $2.4 billion in infrastructure improvements in 2023, on time and within budget.
Engaged in over 150 active R&D projects.
Generated $75 million in O&M savings in 2023 through technology and transformation initiatives.
Expanded use of smart grids, automation, data analytics, and AI.
Donated over $13.6 million to community improvement initiatives in 2023.
Achieved top-quartile reliability across utilities and best-in-nation generation reliability in Kentucky.
Discloses via CDP, EEI‑AGA and aligns with GRI, SASB and TCFD frameworks.
Inclusion & Diversity
Top 1 utility
ESG & workforce diversity ranking
Recognized as the top utility company by DiversityInc for its commitment to ESG and workforce diversity.
100% DEI score
Disability Equality Index
Received a perfect score on the Disability Equality Index (DEI) in 2019 and annually since 2018, earning recognition as a Best Place to Work for disability inclusion.
100+ students supported
Day-in-the-Life program
Hosts an annual program providing real-world work experience for college students on the autism spectrum and other disabilities.
Annual conference held
Diverse business partnerships
Organizes an annual supplier diversity conference focused on expanding opportunities for diverse business partnerships.
Company-wide DEI strategy focused on workforce development, inclusive culture, community support, customer engagement, and diverse supplier partnerships.
16 employee-led resource groups fostering professional development and cultural awareness.
Active REACH employee resource group addressing the needs and well-being of employees with disabilities.
Mentorship opportunities through Disability:IN’s NexGen Leaders program.