Cybersecurity Mgr - Advanced Threat Mitigation Team

AEP Service Corporation

United States

On-site

USD 137,000 - 178,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

AEP Service Corporation is seeking a Cybersecurity Manager to lead the Advanced Threat Mitigation team within the Intelligence & Defence organization. The role oversees threat monitoring, incident response, detection engineering, and threat hunting across IT, OT, cloud, and business environments.

The Manager will drive continuous improvement of defensive capabilities, coordinate with multiple cybersecurity functions, and provide strategic leadership for advanced cyber defense initiatives.

Qualifications

  • Bachelor's degree or Associate degree with 2+ years in Security or related field, or HS diploma with 4+ years.
  • 0

Responsibilities

  • Lead and develop a cybersecurity team responsible for threat monitoring, incident response, threat hunting, detection engineering, and cyber defense operations.
  • Establish performance metrics and drive continuous improvements in cybersecurity effectiveness.
  • Direct daily threat monitoring and ensure timely detection, analysis, escalation, and response across IT, OT, and cloud environments.
  • Oversee detection engineering across SIEM, EDR/XDR, NDR, cloud, identity, and OT security platforms.
  • Manage incident response, containment, eradication, recovery, and post-incident analysis with cross-functional coordination.
  • Lead threat hunting and advanced analytics using intelligence-driven methods.
  • Integrate threat intelligence into detection, hunting, and response workflows.
  • Drive automation and continuous improvement of monitoring and response capabilities.

Skills

Leadership
Threat monitoring
Incident response
Threat hunting
Security analytics
Automation
Cross-functional collaboration

Education

Bachelor's degree or higher in security/related field
HS diploma/GED with 4+ years of applicable experience

Tools

SIEM
EDR/XDR
NDR
Cloud security
OT security

Job description

Job Posting End Date 09-14-2026 Please note the job posting will close on the day before the posting end date.

Job Summary

The Cybersecurity Manager - Advanced Threat Mitigation leads AEP’s Advanced Threat Mitigation (ATM) team within the Intelligence & Defence organization. This team is responsible for enterprise cyber threat monitoring, detection engineering, incident response, threat hunting, and advanced cyber defense operations. The manager oversees a team of cybersecurity analysts, incident responders, detection engineers, and threat hunting professionals responsible for identifying, analyzing, containing, and mitigating cyber threats targeting AEP’s information technology (IT), operational technology (OT), cloud, and business environments. The Advanced Threat Mitigation team serves as AEP’s frontline cyber defense capability, leveraging security monitoring platforms, threat intelligence, advanced analytics, automation, and incident response processes to rapidly detect and respond to malicious activity. The Cybersecurity Manager is responsible for ensuring effective cyber threat detection, incident response coordination, threat hunting operations, and continuous enhancement of AEP’s defensive capabilities against evolving cyber threats. This role provides strategic leadership for the development of advanced cyber defense capabilities, integrating threat intelligence, detection engineering, response automation, and operational analytics to reduce cyber risk and improve AEP’s security posture. The position works closely with Cybersecurity Operations, Threat Intelligence, Vulnerability Management, Architecture, Digital Technology Services, OT Security, and business partners to safeguard critical systems and support AEP’s mission of delivering safe, reliable energy.

Job Description

What you’ll do: Essential Responsibilities (will span multiple areas below)

Leadership & Team Management

Lead and develop a team of cybersecurity professionals responsible for threat monitoring, incident response, threat hunting, detection engineering, and cyber defense operations. Provide coaching, mentoring, performance management, and professional development opportunities for team members. Foster a culture of operational excellence, accountability, continuous learning, innovation, and threat-informed defense. Ensure adequate staffing, training, operational readiness, and succession planning to support continuous cyber defense operations. Establish performance metrics, key risk indicators, and operational objectives that drive measurable improvements in cybersecurity effectiveness. Promote collaboration across cybersecurity functions including intelligence, engineering, architecture, vulnerability management, identity security, and incident response teams.

Threat Monitoring & Detection Operations

Direct daily cyber threat monitoring operations, ensuring timely detection, analysis, escalation, and response to cybersecurity events. Oversee the identification and investigation of potential security incidents affecting enterprise, cloud, operational technology, and third-party environments. Ensure effective utilization of SIEM, EDR/XDR, NDR, cloud security, identity monitoring, and threat intelligence platforms to identify malicious activity and emerging threats. Establish operational procedures that promote rapid triage, accurate threat identification, effective prioritization, and timely escalation. Drive continuous improvement of security monitoring coverage, alert fidelity, detection effectiveness, and operational efficiency. Ensure meaningful operational metrics and reporting are provided to leadership regarding threat activity, investigations, incidents, and response effectiveness.

Threat Detection Engineering & Security Analytics

Lead the strategic direction and maturity of AEP's detection engineering program. Oversee the design, development, testing, deployment, and lifecycle management of security detections across SIEM, EDR/XDR, NDR, cloud, identity, and OT security platforms. Ensure threat intelligence, threat hunting findings, incident investigations, and emerging threat research are translated into actionable detection content. Direct the creation and maintenance of detection rules, correlation searches, behavioral analytics, alerting mechanisms, and monitoring use cases. Establish processes to measure and validate detection effectiveness, ATT&CK framework coverage, and monitoring performance across the enterprise. Lead efforts to improve detection fidelity, reduce false positives, minimize alert fatigue, and optimize analyst effectiveness. Direct adversary emulation, purple team, detection validation, and continuous assessment activities to improve defensive effectiveness. Drive automation and advanced analytics initiatives that improve monitoring scalability, operational efficiency, and response speed.

Incident Response & Cyber Defense

Serve as the primary leadership escalation point for significant cybersecurity events and incidents. Direct response activities including investigation, containment, eradication, recovery, and post-incident analysis. Ensure incidents are managed in accordance with established cybersecurity response plans, regulatory requirements, legal obligations, and industry best practices. Coordinate cross-functional response efforts involving internal stakeholders, external partners, vendors, and government agencies when required. Support executive communications and provide leadership briefings during significant cybersecurity incidents. Lead operational readiness activities including cyber exercises, tabletop exercises, incident simulations, and response drills. Ensure lessons learned, threat intelligence findings, and incident response outcomes are incorporated into continually improving cyber defense capabilities.

Threat Hunting & Advanced Analysis

Lead proactive threat hunting operations focused on identifying adversary activity that may evade traditional security controls. Ensure threat hunting activities leverage intelligence‑driven and hypothesis‑based methodologies informed by current threat intelligence and emerging adversary tactics. Direct advanced investigations involving sophisticated threat actors, persistence mechanisms, insider threats, malware activity, and anomalous behavior. Promote the use of behavioral analytics, threat research, and operational intelligence to identify previously unknown threats. Ensure threat hunting findings are translated into enhanced detections, playbooks, monitoring capabilities, and response procedures. Drive continuous refinement of investigative methodologies, hunting techniques, and analytical workflows.

Threat Intelligence Integration

Ensure timely integration of internal, commercial, government, industry, and intelligence‑sharing partner reporting into security operations. Maintain awareness of emerging cyber threats affecting the energy sector, critical infrastructure, operational technology, and cloud environments. Drive integration of intelligence reporting into detection engineering, threat hunting, incident response, and cyber defense activities. Facilitate collaboration with federal agencies, intelligence organizations, Information Sharing and Analysis Centers (ISACs), peer utilities, industry partners, and critical infrastructure stakeholders. Ensure intelligence products support operational decision‑making, threat detection enhancements, and risk reduction initiatives. Translate intelligence insights into actionable defensive measures and operational priorities.

Technology, Automation & Continuous Improvement

Influence the cybersecurity technology ecosystem supporting monitoring, analytics, automation, orchestration, and incident response operations. Drive implementation of automation and orchestration capabilities to improve response consistency, operational scalability, and speed of execution. Evaluate emerging technologies, detection methodologies, and defensive capabilities to strengthen cyber resiliency. Lead continuous improvement initiatives that enhance operational effectiveness, efficiency, visibility, and cyber defense maturity. Support strategic planning, budgeting, workforce development, and capability roadmap initiatives for the Advanced Threat Mitigation team. Ensure cyber defense processes, technologies, and capabilities remain aligned with evolving threats, regulatory requirements, and business objectives.

Required Qualifications & Experience

Demonstrated leadership experience in one or more of the following disciplines: Security Operations Center (SOC) Leadership Computer Incident Response Center (CIRC) Leadership Detection Engineering Incident Response and Digital Forensics Threat Hunting Cyber Threat Intelligence Counterintelligence Adversary Emulation / Purple Team Operations Malware Analysis or Reverse Engineering Critical Infrastructure Cybersecurity Operational Technology (OT) Security Defensive Cyber Operations supporting regulated or high‑availability environments Security Clearance Current U.S. Government security clearance at the Secret level or higher, or the demonstrated ability to successfully obtain and maintain a government security clearance.

Preferred Certifications
  • CISSP
  • CISM
  • GCTI
  • GCIH
  • GCFA
  • GCED
  • GMON
  • GRID
  • GICSP
  • GXPN
  • OSCP
  • CTIA (Certified Threat Intelligence Analyst)
  • CTCA (Certified Threat Counterintelligence Analyst)
  • CREST Certified Incident Manager
  • Other advanced threat intelligence, threat hunting, incident response, cyber defense, or critical infrastructure security certifications
What We’re Looking For:

Education requirements are listed below: Bachelor's degree or Associate degree combined with a minimum of 2 years of applicable business/technical experience in Security (Cyber and/or Physical), Business Administration, Computer Science, or related field OR a HS diploma/GED combined with a minimum of 4 years of applicable business/technical experience preferably in Security (Cyber and/or Physical), Business Administration, Computer Science, or related field.

Work Experience requirement listed below: 10 or more years of Security (Physical and/or Cyber), business administration, computer science, or other technical experience, demonstrating steady progression in responsibilities including 4 or more years of direct supervision experience preferred (in addition to any experience identified above).

What You’ll Get:

Base Salary from $136,539.00 - $177,503.00/year. In addition to a competitive compensation, AEP offers a unique comprehensive benefits package that aims to support and enhance the overall well‑being of our employees. At AEP, we’re more than just an energy company — we’re a team of dedicated professionals committed to delivering safe, reliable, and innovative energy solutions. Guided by our mission to put the customer first, we strive to exceed expectations by listening, responding, and continuously improving the way we serve our communities. If you’re passionate about making a meaningful impact and being part of a forward‑thinking organization, this is the company for you!

Compensation Data

Compensation Grade: SP20-010 Compensation Range: $136,539.00 - $177,503.00

The Physical Demand Level for this job is: S – Sedentary Work: Exerting up to 10 pounds of force occasionally (Occasionally: activity or condition exists up to 1/3 of the time) and/or a negligible amount of force frequently. (Frequently: activity or condition exists from 1/3 to 2/3 of the time) to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time but may involve walking or standing for brief periods of time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.

It is hereby reaffirmed that it is the policy of American Electric Power (AEP) to provide Equal Employment Opportunity in all respects of the employer‑employee relationship including recruiting, hiring, upgrading and promotion, conditions and privileges of employment, company sponsored training programs, educational assistance, social and recreational programs, compensation, benefits, transfers, discipline, layoffs and termination of employment to all employees and applicants without discrimination because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, veteran or military status, disability, genetic information, or any other basis prohibited by applicable law. When required by law, we might record certain information or applicants for employment may be invited to voluntarily disclose protected characteristics. At American Electric Power, we provide more than electricity to our millions of customers - we energize possibilities. We’re redefining the future of energy by reducing our carbon footprint, empowering the communities we serve and building an engaged, talented workforce. All while delivering the reliable service our customers expect. It’s an exciting time in the energy industry. Are you ready to be part of it? We’re looking for team members to help create the grid of the future. Learn more about our commitment to creating a supportive, inclusive work culture that values different experiences.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Mgr - Advanced Threat Mitigation Team
Cybersecurity Mgr - Advanced Threat Mitigation Team

American Electric Power Co. • Northern (KY)

Hybrid
USD 137,000 - 178,000
Competitive benefits package
Security Specialist (Senior to Staff) – Data Loss Prevention (DLP)
Security Specialist (Senior to Staff) – Data Loss Prevention (DLP)

AEP • Northern (KY)

Hybrid
USD 99,000 - 129,000
Security Spec Lead - Digital Forensics Analyst
Security Spec Lead - Digital Forensics Analyst

American Electric Power Co. • Northern (KY)

Hybrid
USD 116,000 - 151,000
Security Specialist (Senior to Staff Level)
Security Specialist (Senior to Staff Level)

AEP • Columbus (OH)

On-site
USD 88,000 - 178,000
Security Spec Sr
Security Spec Sr

AEP • Columbus (OH), Northern (KY)

Hybrid
USD 88,000 - 110,000
Security Spec Lead
Security Spec Lead

American Electric Power Co. • Kentucky

On-site
USD 116,000 - 151,000
Security Operations IR/OT
Security Operations IR/OT

American Electric Power • Columbus (OH)

On-site
USD 99,000 - 129,000
Cyber Security Manager
Cyber Security Manager

American Electric Power Co. • Columbus (OH)

On-site
USD 137,000 - 178,000
Security Spec Lead
Security Spec Lead

American Electric Power Co. • Columbus (OH)

On-site
USD 116,000 - 151,000
Security Spec Sr
Security Spec Sr

American Electric Power Co. • Columbus (OH)

On-site
USD 88,000 - 110,000