OT/ICS Security Principal Architect

1 week ago


Louisville, United States PPL Full time

Company Summary Statement As one of the largest investor-owned utility companies in the United States, PPL Corporation (NYSE: PPL), is committed to creating long-term, sustainable value for our 3.5 million customers, our shareowners and the communities we serve. Our high-performing regulated utilities — PPL Electric Utilities, Louisville Gas and Electric, Kentucky Utilities and Rhode Island Energy — provide an outstanding experience for our customers, consistently ranking among the best utilities in the nation. PPL’s companies are also addressing challenges head-on by investing in new infrastructure and technology that is creating a smarter, more reliable and resilient energy grid. We are committed to doing our part to advance a cleaner energy future and drive innovation that enables us to achieve net-zero carbon emissions by 2050 while maintaining energy reliability and affordability for the customers and communities we serve. PPL is a positive force in the cities and towns where we do business, providing support for programs and organizations that empower the success of future generations by helping to build and maintain strong, diverse communities today. Overview The Cybersecurity organization advances the overall state of security at PPL through critical initiatives and coordination of large security and customer-focused projects. The organization builds and procures technologies, tools, and processes to better enable teams at PPL to develop secure platforms and protect data and systems with appropriate security controls. IT Cybersecurity also develops systems to monitor and respond to attacks against our systems, provides educational awareness to the corporation on security best practices, and ensures data sharing relationships with third parties securely protect PPL information. PPL is seeking a highly skilled Operational Technology/Industrial Control Systems Principal Architect to join our Cybersecurity organization. In this role, you will work closely with our Operations, Information Technology, and Cybersecurity team to ensure the security and configuration of the PPL critical infrastructure. You will have direct responsibility for the usage and monitoring of the cyber technology within the OT/ICS environment as well as leading the OT/ICS security strategy. You will provide expert guidance, conduct security assessments, and provide detailed design and implementation of secure OT/ICS architecture. If you are passionate about OT/ICS and have a deep understanding of cybersecurity, architecture, infrastructure, risk, and compliance, this position is ideal for you. #LI-Hybrid Responsibilities Develop and Implement a comprehensive OT/ICS security strategy that aligns with the organization’s overall security objectives and regulatory requirements. Design and document secure OT/ICS architectures that meet the organization's functional and security requirements. Design and/or evaluate current OT/ICS infrastructure and incorporate security principles into all stages of the System Development Lifecycle. Collaborate with cross-functional teams to integrate security controls and processes into OT/ICS infrastructure and applications. Complete Threat Modeling assessments, analyze impact, and develop mitigation strategies. Perform security reviews of architecture, infrastructure, and applications, identify gaps, develop a security risk management plan, and execute strategies to mitigate/address identified risk. Responsible for the governance of OT/ICS Security policies, procedures, and standards. Offer technical guidance and support to OT/ICS operations and engineering teams. Assess and recommend security tools, technologies, and services that enhance OT/ICS security posture. Serve as a Subject Matter Expert on OT/ICS Security related topics, best practices, emerging technologies and the evolving threat landscape. Provide guidance, coaching, and support in the development of junior staff members. All other duties and projects as assigned. Qualifications Education Bachelor’s degree in Computer Science, Information Security, and/or a related field or an equivalent level of work related experience. Experience A minimum of 10+ years of direct OT/ICS security, including architecture, design, and implementation. Strong understanding of OT/ICS technologies, including SCADA, PLC, and DCS systems Experience in developing and deploying defense in depth and layered architecture within an OT/ICS environment. Experience in designing and implementing network infrastructure within OT/ICS environment. Expertise in system hardening, including vulnerability assessment, penetration testing, and configuration management. Proficiency in conducting security testing, including vulnerability scanning, and static and dynamic code analysis. Expertise in OT/ICS security frameworks and standards (e.g., NERC CIP, TSA, Purdue Model) Ability to follow outlined processes and procedures with high degree of accuracy. Experience working in Agile teams and have knowledge of Agile principles and practices. Strong analytical skills to assess risks and vulnerabilities in complex systems. Strong leadership, communication, and interpersonal skills. Collaborative and effective in cross-functional team environments (including Network, IAM, Monitoring and Detection, Asset Management, etc.). Experience assessing, hardening, and standardizing OT/ICS access control and management Design and implementation of passive threat monitoring and detection capabilities Practical experience working with technologies from OT/ICS vendors Preferred Qualifications Direct experience in utility and/or energy related industries. Proficiency in scripting and automation for security testing. Experience utilizing the Scaled Agile Framework (SAFe) Certified Information Systems Security Professional- CISSP Master's Degree in related technical discipline or MBA. SANS ICS410: ICS/SCADA Security Essentials SANS ICS515: ICS Visibility, Detection, and Response SANS ICS612: ICS Cybersecurity In-Depth SANS GIAC Response and Industrial Defense (GRID) Certified SANS Global Industrial Cyber Security Professional (GICSP) Certified SANS GIAC Critical Infrastructure Protection (GCIP) Certified Education Bachelor’s degree in Computer Science, Information Security, and/or a related field or an equivalent level of work related experience. Experience A minimum of 10+ years of direct OT/ICS security, including architecture, design, and implementation. Strong understanding of OT/ICS technologies, including SCADA, PLC, and DCS systems Experience in developing and deploying defense in depth and layered architecture within an OT/ICS environment. Experience in designing and implementing network infrastructure within OT/ICS environment. Expertise in system hardening, including vulnerability assessment, penetration testing, and configuration management. Proficiency in conducting security testing, including vulnerability scanning, and static and dynamic code analysis. Expertise in OT/ICS security frameworks and standards (e.g., NERC CIP, TSA, Purdue Model) Ability to follow outlined processes and procedures with high degree of accuracy. Experience working in Agile teams and have knowledge of Agile principles and practices. Strong analytical skills to assess risks and vulnerabilities in complex systems. Strong leadership, communication, and interpersonal skills. Collaborative and effective in cross-functional team environments (including Network, IAM, Monitoring and Detection, Asset Management, etc.). Experience assessing, hardening, and standardizing OT/ICS access control and management Design and implementation of passive threat monitoring and detection capabilities Practical experience working with technologies from OT/ICS vendors Preferred Qualifications Direct experience in utility and/or energy related industries. Proficiency in scripting and automation for security testing. Experience utilizing the Scaled Agile Framework (SAFe) Certified Information Systems Security Professional- CISSP Master's Degree in related technical discipline or MBA. SANS ICS410: ICS/SCADA Security Essentials SANS ICS515: ICS Visibility, Detection, and Response SANS ICS612: ICS Cybersecurity In-Depth SANS GIAC Response and Industrial Defense (GRID) Certified SANS Global Industrial Cyber Security Professional (GICSP) Certified SANS GIAC Critical Infrastructure Protection (GCIP) Certified Develop and Implement a comprehensive OT/ICS security strategy that aligns with the organization’s overall security objectives and regulatory requirements. Design and document secure OT/ICS architectures that meet the organization's functional and security requirements. Design and/or evaluate current OT/ICS infrastructure and incorporate security principles into all stages of the System Development Lifecycle. Collaborate with cross-functional teams to integrate security controls and processes into OT/ICS infrastructure and applications. Complete Threat Modeling assessments, analyze impact, and develop mitigation strategies. Perform security reviews of architecture, infrastructure, and applications, identify gaps, develop a security risk management plan, and execute strategies to mitigate/address identified risk. Responsible for the governance of OT/ICS Security policies, procedures, and standards. Offer technical guidance and support to OT/ICS operations and engineering teams. Assess and recommend security tools, technologies, and services that enhance OT/ICS security posture. Serve as a Subject Matter Expert on OT/ICS Security related topics, best practices, emerging technologies and the evolving threat landscape. Provide guidance, coaching, and support in the development of junior staff members. All other duties and projects as assigned. Remote Work The company reserves the right to determine if this position will be assigned to work on-site, remotely, or a combination of both. Assigned work location may change. In the case of remote work, physical presence in the office/on-site may be required to engage in face-to-face interaction and coordination of work among direct reports and co-workers. Equal Employment Opportunity Our company is an equal opportunity, affirmative action employer dedicated to diversity and the strength it brings to the workplace. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, national origin, protected veteran status, sexual orientation, gender identify, genetic information, disability status, or any other protected characteristic.


  • Security Architect

    2 weeks ago


    Louisville, United States Heaven Hill Brands Full time

    Job DescriptionJob DescriptionThis role is office hybrid and based in Louisville, Kentucky. What the Role Is The Security Architect will be the lead information security technologist for Heaven Hill. This position will be responsible for assessment of information security risks and threats, security technology architecture, development and execution of...

  • Security Architect

    1 week ago


    Louisville, United States Heaven Hill Brands Full time

    This role is office hybrid and based in Louisville, Kentucky. What the Role Is The Security Architect will be the lead information security technologist for Heaven Hill. This position will be responsible for assessment of information security risks and threats, security technology architecture, development and execution of roadmaps to reduce risks to...

  • Solution Architect

    1 week ago


    Louisville, United States Motorola Solutions Full time

    Company Overview At Motorola Solutions, we're guided by a shared purpose - helping people be their best in the moments that matter - and we live up to our purpose every day by solving for safer. Because people can only be their best when they not only feel safe, but are safe. We're solving for safer by building the best possible technologies across every...


  • louisville, United States Photon Full time

    Principal/ SME .Net Fullstack (React +.Net + Azure)Louisville, KY (Hybrid)Long term Digital eCommerce Full Stack Technical Lead, you will lead the design, development, and deployment of scalable, cross-platform applications to enhance the digital shopping experience. With a strong background in mobile and web development using React Native and ReactJS, you...


  • Louisville, United States Photon Full time

    Principal/ SME .Net Fullstack (React +.Net + Azure)Louisville, KY (Hybrid)Long term Digital eCommerce Full Stack Technical Lead, you will lead the design, development, and deployment of scalable, cross-platform applications to enhance the digital shopping experience. With a strong background in mobile and web development using React Native and ReactJS, you...

  • Azure Cloud Architect

    2 weeks ago


    Louisville, United States SysMind Tech Full time

    Job Title Azure Cloud Architect Relevant Experience (in Yrs) 10 to 12 Years Technical/Functional Skills Business Knowledge in healthcare domain , Strong on Cloud Technologies and problem solving skills. The following Azure Certifications are highly desired; significant hands on experience may be substituted: o Certified Developing Azure Solutions (70-532) o...


  • Louisville, Kentucky, United States Tyler Technologies Full time

    We're seeking a seasoned Cloud Software Architect to collaborate with our team of talented engineers and innovative problem-solvers who build scalable software solutions for governments worldwide.This role is part of our Data & Insights division, which creates cloud-based platforms and applications to accelerate the flow of government data into the hands of...

  • Data Architect

    1 week ago


    Louisville, United States Syntricate Technologies Full time

    Data Architect 12+ Months Long Term Louisville, KY (Hybrid) Web Cam Interview W2 only Role:- We are seeking an experienced Data Architect with hands-on expertise in Azure Databricks, Azure Data Lakehouse, and Medallion Architecture. The ideal candidate will have strong implementation experience, including the integration of Delta Lake...

  • IT Architect

    1 week ago


    Louisville, United States MAXIMUS Full time

    Description & Requirements Maximus is looking for an IT Architect- Cloud Solutions. The IT Architect - Cloud Solutions is responsible for public cloud enablement at Maximus, as a team member of the Cloud Center of Excellence (CCoE). Part of the CCoE role is to assist with the adoption of public cloud through architected frameworks, developing reusable...

  • OIC Architect

    1 month ago


    Louisville, United States Axiom Software Solutions Limited Full time

    RoleOIC Architect Location – Louisville KY (Remote) Job Description: Note: Looking for OIC Architecting Development and Finance Cloud Functional knowledge/integrations. Responsibilities: • 12 years hands on technical experience with integration / middleware platform in iPaaS focused on either Oracle Integration Cloud (OIC) and/or Oracle...


  • Louisville, Kentucky, United States Spectrum Full time

    Unlock Your Potential as a Sales Solutions ArchitectWe are seeking a skilled and results-driven Sales Solutions Architect to join our team at Spectrum Enterprise. As a Sales Solutions Architect, you will play a critical role in crafting innovative solutions, technical sales proposals, and consultations that highlight the benefits of our services to...

  • UI/UX Architect

    6 days ago


    Louisville, Kentucky, United States United Software Group Full time

    Job Title: UI/UX ArchitectAbout the Role:We are seeking an experienced UI/UX Architect to join our team at United Software Group. This is a fantastic opportunity for a talented individual to work on exciting projects and contribute to the growth of our company.Estimated Salary: $120,000 - $150,000 per year, depending on experience.Job Description:The...


  • louisville, United States Emids Full time

    Role Title – Solution ArchitectLocation – Louisville, KYMode of Hire - Contract-Hire / Full-time with benefitsThe RoleThe Data Architect proactively leads and supports software developers, database architects, data analysts and data scientists on data initiatives and will ensure optimal data delivery architecture is consistent throughout ongoing...


  • louisville, United States Emids Full time

    Role Title – Solution ArchitectLocation – Louisville, KYMode of Hire - Contract-Hire / Full-time with benefitsThe RoleThe Data Architect proactively leads and supports software developers, database architects, data analysts and data scientists on data initiatives and will ensure optimal data delivery architecture is consistent throughout ongoing...


  • Louisville, United States Emids Full time

    Role Title – Solution ArchitectLocation – Louisville, KYMode of Hire - Contract-Hire / Full-time with benefitsThe RoleThe Data Architect proactively leads and supports software developers, database architects, data analysts and data scientists on data initiatives and will ensure optimal data delivery architecture is consistent throughout ongoing...


  • Louisville, United States Emids Full time

    Role Title – Solution ArchitectLocation – Louisville, KYMode of Hire - Contract-Hire / Full-time with benefitsThe RoleThe Data Architect proactively leads and supports software developers, database architects, data analysts and data scientists on data initiatives and will ensure optimal data delivery architecture is consistent throughout ongoing...


  • Louisville, Kentucky, United States Syntricate Technologies Full time

    About the RoleWe are seeking an experienced Senior Cloud Data Architect to join our team at Syntricate Technologies. This role requires a deep understanding of cloud-native data solutions and the ability to architect and deliver scalable, high-performing data platforms that can support advanced analytics, machine learning, and business intelligence...

  • Application Architect

    6 months ago


    Louisville, United States Wipro Full time

    Role Purpose The purpose of the role is to create exceptional and detailed architectural application design and provide thought leadership and enable delivery teams to provide exceptional client engagement and satisfaction. Do Develop architectural application for the new deals/ major change requests in existing deals Creates an enterprise-wide architecture...


  • Louisville, Kentucky, United States Resource Informatics Group Inc Full time

    We are seeking a highly skilled Database Systems Architect to join our team at Resource Informatics Group Inc. As a key member of our database administration team, you will be responsible for designing, implementing, and maintaining high-performance database systems.Your primary focus will be on ensuring the security, integrity, and scalability of our...


  • Louisville, Kentucky, United States Heaven Hill Brands Full time

    About the RoleThis is a unique opportunity to join the Heaven Hill Brands team as a key player in shaping our information security strategy and roadmap. As a seasoned security leader, you will be responsible for driving our security vision, developing and implementing security capabilities, and ensuring the protection of our assets and data.Key...