Application Security Principal

15 hours ago


Louisville, United States PPL Full time

Company Summary Statement

As one of the largest investor-owned utility companies in the United States, PPL Corporation (NYSE: PPL), is committed to creating long-term, sustainable value for our 3.5 million customers, our shareowners and the communities we serve. Our high-performing regulated utilities — PPL Electric Utilities, Louisville Gas and Electric, Kentucky Utilities and Rhode Island Energy — provide an outstanding experience for our customers, consistently ranking among the best utilities in the nation. PPL’s companies are also addressing challenges head-on by investing in new infrastructure and technology that is creating a smarter, more reliable and resilient energy grid. We are committed to doing our part to advance a cleaner energy future and drive innovation that enables us to achieve net-zero carbon emissions by 2050 while maintaining energy reliability and affordability for the customers and communities we serve. PPL is a positive force in the cities and towns where we do business, providing support for programs and organizations that empower the success of future generations by helping to build and maintain strong, diverse communities today.

Overview

The Cybersecurity organization advances the overall state of security at PPL through critical initiatives and coordination of large security and customer-focused projects. The organization builds and procures technologies, tools, and processes to better enable teams at PPL to develop secure platforms and protect data and systems with appropriate security controls. IT Cybersecurity also develops systems to monitor and respond to attacks against our systems, provides educational awareness to the corporation on security best practices, and ensures data sharing relationships with third parties securely protects PPL information.

PPL is seeking a highly skilled Application Security Principal to join our Cybersecurity organization. In this role, you will work closely with our Product Cybersecurity Manager to ensure the security and integrity of our applications and software products. You will provide expert guidance, conduct security assessments, and help shape the security posture of our products. If you are passionate about application security and have a deep understanding of modern software development practices, this position is ideal for you. #LI-Hybrid

Responsibilities

  • Using a Secure by Design approach, design and implement, in coordination with Enterprise Architecture and Product Development teams, secure application architecture themeet the organization’s requirements.

  • Develop and/or expand threat modeling governance frameworks, including policy/procedure creation, risk assessments, and establishment of metrics.

  • Develop and maintainestablished security requirements and best practices for application development and deployment.

  • Analyze security needs and software requirements to determine feasibility of design within time and cost constraints and security requirements.

  • Conduct risk assessments for applications to identify potential vulnerabilities and threats.

  • Oversee and coordinate security testing activities, including static code analysis, dynamic application security testing, penetration testing, and code reviews.

  • Develop a security risk management planand execute strategies to mitigate/address identified risk by working with the Product Development teams.

  • Evaluate, implement, and manage security tools and technologies that enhance the security posture of applications.

  • Educate development teams on established security requirements and best practices.

  • Collaborates with business and technical owners, while engaging relevant SME’s, to establish compliance standards and trackable metrics

  • Maintain Knowledge and stay up to date on developing security technologies and integrate new technologies into architecture designs, where applicable.

  • Provide guidance, coaching, and support in the development of junior staff members.

  • All other duties and projects as assigned.

Qualifications

Education

  • Bachelor’s degree in Computer Science, Information Security, and/or a related field or an equivalent level of work related experience.

Experience

  • A minimum of 10+ years of experience in cybersecurity with a focus on software development, secure by design principles, and/or security architecture.

  • Proficiencyin conducting security testing, including vulnerability scanning, and static and dynamic code analysis.

  • Expertise in system hardening, including vulnerability assessment, penetration testing, and configuration management.

  • Expertise in designing secure architectures using established frameworks

  • Experience in application security tools and IDE Plug-in environments, including HP Fortify.

  • Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25.

  • Experience in the use of threat modeling tools, and understanding of frameworks such as STRIDE and PASTA.

  • Cloud Technology Expertise: Demonstrate a working knowledge of various enterprise technology stacks used to build applications in the cloud. Your understanding of cloud infrastructure will enable you to assess security aspects unique to cloud-based mobile applications and APIs.

  • Cloud Platform Experience: Possess working knowledge and practical experience in security testing within cloud platforms, particularly Azure. Your familiarity will be crucial for assessing the security of cloud-hosted mobile applications and APIs.

  • Experience in Cloud Native Security practices and technologies including Container security, Serverless security, Kubernetes security and Threat detection.

  • Experience in utilizing Cloud Native Security Tools and Platforms such as Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and Cloud Access Security Brokers (CASB).

  • Experience working in Agile teams and have knowledge of Agile principles and practices.

  • Knowledge of federal compliance standards, including NIST 800-53 and NIST CSF.

  • Ability to follow outlined processes and procedures with high degree of accuracy.

  • Strong analytical skills to assess risks and vulnerabilities in complex systems.

  • Strong leadership, communication, and interpersonal skills.

  • Collaborative and effective in cross-functional team environments.

Preferred Qualifications

  • Professional certifications such as CISSP, CSSLP, or CEH

  • Proficiency in scripting and automation for security testing.

  • Experience with AWS and Google Cloud services

  • Experience utilizing the Scaled Agile Framework (SAFe)

  • Experience in securing Artificial Intelligence, Machine Learning, etc and maintaining integrity of those powered solutions.

Education

  • Bachelor’s degree in Computer Science, Information Security, and/or a related field or an equivalent level of work related experience.

Experience

  • A minimum of 10+ years of experience in cybersecurity with a focus on software development, secure by design principles, and/or security architecture.

  • Proficiencyin conducting security testing, including vulnerability scanning, and static and dynamic code analysis.

  • Expertise in system hardening, including vulnerability assessment, penetration testing, and configuration management.

  • Expertise in designing secure architectures using established frameworks

  • Experience in application security tools and IDE Plug-in environments, including HP Fortify.

  • Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25.

  • Experience in the use of threat modeling tools, and understanding of frameworks such as STRIDE and PASTA.

  • Cloud Technology Expertise: Demonstrate a working knowledge of various enterprise technology stacks used to build applications in the cloud. Your understanding of cloud infrastructure will enable you to assess security aspects unique to cloud-based mobile applications and APIs.

  • Cloud Platform Experience: Possess working knowledge and practical experience in security testing within cloud platforms, particularly Azure. Your familiarity will be crucial for assessing the security of cloud-hosted mobile applications and APIs.

  • Experience in Cloud Native Security practices and technologies including Container security, Serverless security, Kubernetes security and Threat detection.

  • Experience in utilizing Cloud Native Security Tools and Platforms such as Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and Cloud Access Security Brokers (CASB).

  • Experience working in Agile teams and have knowledge of Agile principles and practices.

  • Knowledge of federal compliance standards, including NIST 800-53 and NIST CSF.

  • Ability to follow outlined processes and procedures with high degree of accuracy.

  • Strong analytical skills to assess risks and vulnerabilities in complex systems.

  • Strong leadership, communication, and interpersonal skills.

  • Collaborative and effective in cross-functional team environments.

Preferred Qualifications

  • Professional certifications such as CISSP, CSSLP, or CEH

  • Proficiency in scripting and automation for security testing.

  • Experience with AWS and Google Cloud services

  • Experience utilizing the Scaled Agile Framework (SAFe)

  • Experience in securing Artificial Intelligence, Machine Learning, etc and maintaining integrity of those powered solutions.

  • Using a Secure by Design approach, design and implement, in coordination with Enterprise Architecture and Product Development teams, secure application architecture themeet the organization’s requirements.

  • Develop and/or expand threat modeling governance frameworks, including policy/procedure creation, risk assessments, and establishment of metrics.

  • Develop and maintainestablished security requirements and best practices for application development and deployment.

  • Analyze security needs and software requirements to determine feasibility of design within time and cost constraints and security requirements.

  • Conduct risk assessments for applications to identify potential vulnerabilities and threats.

  • Oversee and coordinate security testing activities, including static code analysis, dynamic application security testing, penetration testing, and code reviews.

  • Develop a security risk management planand execute strategies to mitigate/address identified risk by working with the Product Development teams.

  • Evaluate, implement, and manage security tools and technologies that enhance the security posture of applications.

  • Educate development teams on established security requirements and best practices.

  • Collaborates with business and technical owners, while engaging relevant SME’s, to establish compliance standards and trackable metrics

  • Maintain Knowledge and stay up to date on developing security technologies and integrate new technologies into architecture designs, where applicable.

  • Provide guidance, coaching, and support in the development of junior staff members.

  • All other duties and projects as assigned.

Remote Work

The company reserves the right to determine if this position will be assigned to work on-site, remotely, or a combination of both. Assigned work location may change. In the case of remote work, physical presence in the office/on-site may be required to engage in face-to-face interaction and coordination of work among direct reports and co-workers.

Equal Employment Opportunity

Our company is an equal opportunity, affirmative action employer dedicated to diversity and the strength it brings to the workplace. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, national origin, protected veteran status, sexual orientation, gender identify, genetic information, disability status, or any other protected characteristic.



  • Louisville, United States O. Technical Solutions Full time

    As a Principal RF Engineer, you will be using your skills and expertise to design, develop, and test our complex products and technologies. These cover a very wide range from state of the art mission payloads and electronic systems through highly integrated aircraft to orbital and space exploration systems. You'll be responsible for RF front-end design,...


  • Louisville, United States Department of Homeland Security Full time

    Duties This Master Transportation Security Officer-SecurityTraining Instructor position is located at Louisville Muhammad Ali International Airport (SDF), Transportation Security Administration, Department of Homeland Security (DHS). As a Master Transportation Security Officer (MTSO), you will support the airport training program through performance of a...


  • Louisville, United States Sierra Space Full time

    Sierra Space Careers: Dare to Dream We honor those that are not afraid to dream big dreams, those that tenaciously chase their dreams even when others say it cannot be done, those that achieve big dreams and change everything. Those are Dreams Worth Chasing.  At Sierra Space we envision a future where humanity lives and works in space, on moons, and on...


  • Louisville, Kentucky, United States Churchill Downs Incorporated Full time

    Job DescriptionAs a Senior Leader in Cloud and Application Security, you will be responsible for establishing and enforcing security protocols for our digital platforms, including web applications, mobile apps, APIs, and AI models.Key ResponsibilitiesEstablish security protocols for AI models and applications, ensuring the protection of data integrity and...


  • Louisville, United States Evergreen Fire and Security Full time

    Job DescriptionJob DescriptionWho We AreEvergreen Fire and Security (EFS) is a recognized leader in the life safety and security solutions industry.  We are entrusted by the Federal Government and commercial customers to protect lives, critical infrastructure, and information by providing and maintaining technically advanced and innovative fire alarm,...


  • Louisville, United States Sierra Space Full time

    Sierra Space Careers: Dare to Dream We honor those that are not afraid to dream big dreams, those that tenaciously chase their dreams even when others say it cannot be done, those that achieve big dreams and change everything. Those are Dreams Worth Chasing.  At Sierra Space we envision a future where humanity lives and works in space, on moons, and on...

  • Applications Analyst

    15 hours ago


    Louisville, United States Heaven Hill Brands Full time

    Job DescriptionJob Description This role has a base location near Louisville, KY. Also open to surrounding states such as Ohio, Indiana and Tennessee.What the Role IsThe Applications Analyst will be responsible for administering a variety of applications and the EDI technology across the Heaven Hill enterprise. The role reports to the Director of IT Business...


  • Louisville, United States General Electric Full time

    At GE Appliances, a Haier company, we come together to make “good things, for life.” As the fastest-growing appliance company in the U.S., we’re powered by creators, thinkers, and makers who believe that anything is possible and that there’s always a better way. We believe in the power of our people and in giving them the freedom to explore,...


  • Louisville, Kentucky, United States General Electric Full time

    Job DescriptionWe are seeking a Senior Principal Business Architect to lead enterprise-wide business transformation initiatives and develop cutting-edge architectural frameworks to support our vision for the future.Responsibilities:Lead Business and Operating Model Design: Collaborate with executives to create strategic alignments, roadmaps, and standards...

  • Security Analyst

    10 hours ago


    Louisville, United States LOUISVILLE, KY 40222 Full time

    Job DescriptionJob DescriptionOverviewThe Risk & Compliance team is essential to the success of BrightSpring’s Information Security Program. We’re all about risk and strategy: We start with a risk based approach to understand what to take action on and why; Build organizational alignment and communicate the standardized approach to address risk; Mobilize...

  • Security Engineer

    5 days ago


    Louisville, United States Professional Staffing Services Group Full time

    Job DescriptionJob DescriptionSecurity Engineer - 12 month contract to hireLocation: Louisville, KY (hybrid with 2-3 days on site)Pay: $33/hrShift: M - F 8:30a-5:30p (potential on call support needed)Summary:This position is responsible for the daily security monitoring, support, and ticketing of the client's network, user accounts, and email. This...

  • Security Consultant

    7 days ago


    Louisville, United States NTT DATA Americas, Inc Full time

    NTT DATA strives to hire exceptional, innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now. We are currently seeking a Security Consultant to join our team in REMOTE, Kentucky (US-KY), United States (US). Job Description: The Security Consultant...


  • Louisville, United States Department of the Air Force Full time

    Duties As a SECURITY SPECIALIST (TRAINING SPECIALIST)-TITLE 32, GS-0080-9, you will review all operations, mobility, contingency, and exercise plans to ensure combat readiness for the SF Squadron. Evaluate equipment, manning and training requirements to meet wartime, contingency, deployment, and pre-planned tasking. Manage plans for deployment, disaster...


  • Louisville, Kentucky, United States Churchill Downs Incorporated Full time

    Job Summary:Churchill Downs Incorporated is seeking a strategic and experienced leader to oversee and enhance our security posture across public cloud environments, applications, and digital platforms. This leadership role will be responsible for developing and implementing comprehensive security strategies, policies, and practices that protect our...


  • Louisville, United States University of Louisville Full time

    Department: Location: Belknap Campus Time Type: Full time Worker Type: Regular Job Req ID: R106042 Minimum Requirements: Bachelor's degree in Cyber or Information Security, Information Systems Management, Business or related discipline and six (6) years of related work experience with an emphasis in formation security, compliance, government or related area....


  • Louisville, United States Churchill Downs Incorporated Full time

    Job DescriptionJob DescriptionSUMMARY:The Director of SAP Business Applications provides leadership to a team of ERP professionals and collaborates with existing stakeholders and business leaders on the SAP ERP application portfolio and toolset. The position will oversee the teams that execute and support the enterprise software SAP applications, ensuring...


  • Louisville, United States Churchill Downs Incorporated Full time

    SUMMARY: The Director of SAP Business Applications provides leadership to a team of ERP professionals and collaborates with existing stakeholders and business leaders on the SAP ERP application portfolio and toolset. The position will oversee the teams that execute and support the enterprise software SAP applications, ensuring close adherence to change...


  • Louisville, United States TeAM Inc Full time

    TeAM, a Veteran Owned Small Business (VOSB) and Small Disadvantaged Business (SDB), offering public and private sector organizations high quality, “best of breed” technical and management solutions, is seeking an experienced Senior Information Security Specialist! The selected candidate will provide critical support in protecting and securing the Air...


  • Louisville, United States Sierra Space Full time

    Sierra Space Careers: Dare to Dream We honor those that are not afraid to dream big dreams, those that tenaciously chase their dreams even when others say it cannot be done, those that achieve big dreams and change everything. Those are Dreams Worth Chasing.  At Sierra Space we envision a future where humanity lives and works in space, on moons, and on...


  • Louisville, United States By Light Professional IT Services Full time

    Cyber Security EngineerJob Locations US-KY | US-KYID 2023-8627# of Openings 1Category CyberClearance Tier 3 - Secret/ADP IICompany Overviewinteractive Personnel Electronic Records Management System (iPERMS) is a secure net-centric information system that directly supports the Army's military personnel records management mission in war, mobilization, and...