Intermediate Cybersecurity Risk Analyst

PPL Corporation

Allentown (Lehigh County)

Hybrid

USD 80,000 - 110,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Hybrid work model

Job summary

PPL Corporation in Allentown, PA seeks an Intermediate Cybersecurity Risk Analyst to execute cybersecurity and IT risk assessment activities, analyze risk exposures, document findings, and support risk mitigation across the enterprise. The role involves collaborating with cybersecurity, IT, and business stakeholders to evaluate risks and strengthen the risk management program.

The position emphasizes maintaining risk registers, dashboards, and reporting inputs, while monitoring threats and

Qualifications

  • Bachelor's Degree in Cybersecurity, Information Technology, Risk Management, Computer Science, Computer Information Systems, Business, or a related field.
  • 2+ years of related experience in cybersecurity, IT risk management, IT audit, information security, technology compliance, infrastructure, cloud, application security, or related IT field.
  • Working knowledge of cybersecurity risk management concepts, control frameworks, and risk assessment methodologies, such as NIST CSF, NIST RMF, CIS Controls, COBIT, ISO 27001, or FAIR.
  • Strong written and verbal communication skills, including the ability to translate technical risk information into clear business terms, prepare concise documentation, and escalation high‑risk issues appropriately.
  • 3+ years of experience in cybersecurity, IT risk management, IT audit, technology compliance, or related field.
  • Relevant professional certification such as Security+, GSEC, SSCP, CRISC, CISA, CISM, CGRC, or equivalent.
  • Experience preparing risk assessments, risk register entries, treatment plans, control observations, dashboards, or stakeholder reporting.
  • Experience using GRC, IRM, audit, compliance, or risk management platforms such as ServiceNow IRM, Archer, and OneTrust.
  • Familiarity with data analysis, reporting, automation, or scripting tools such as Python, PowerShell, Power BI, SQL, or similar technologies.
  • Familiarity with enterprise technology environments, including cloud services, infrastructure, networking, identity and access management, applications, or hybrid environments.

Responsibilities

  • Support cybersecurity awareness activities, including coordinating phishing simulations, drafting awareness communications, tracking participation or engagement metrics, and helping identify opportunities to improve employee security behaviors and risk‑informed decision‑making.
  • Collaborate with cybersecurity, IT, and business stakeholders to gather risk information, assess risk exposure, document conclusions, and support mitigation planning.
  • Conduct cybersecurity and IT risk assessments for systems, applications, third parties, technologies, or business processes using established risk methodologies and guidance.
  • Maintain risk register entries, assessment records, dashboards, and reporting inputs to support accurate and timely cybersecurity risk reporting.
  • Analyze risk data, identify trends or recurring issues, and prepare clear summaries to support management review, escalation, and decision‑making.
  • Support the review, maintenance, and improvement of cybersecurity policies, standards, procedures, and risk management practices.
  • Monitor emerging threats, vulnerabilities, control issues, and regulatory or framework changes, and assist in assessing potential impacts to cybersecurity and IT risk.
  • Contribute to team knowledge sharing by documenting procedures, sharing lessons learned, and supporting onboarding or peer learning as needed.
  • Support incident response and post‑incident risk analysis by reviewing relevant information, documenting risk implications, and helping identify control gaps or improvement opportunities.
  • All other duties and projects as assigned.
  • Performs other duties as assigned.
  • Complies with all policies and standards.

Skills

Communication skills
Risk management concepts
Analytical thinking

Education

Bachelor's Degree in Cybersecurity/IT/CS/related field

Tools

ServiceNow IRM
Archer
OneTrust
Power BI
SQL
Python
PowerShell

Job description

Company Summary Statement

As one of the largest investor-owned utility companies in the United States, PPL Corporation (NYSE: PPL), is committed to creating long-term, sustainable value for our 3.5 million customers, our shareowners and the communities we serve. Our high-performing regulated utilities — PPL Electric Utilities, Louisville Gas and Electric, Kentucky Utilities and Rhode Island Energy — provide an outstanding experience for our customers, consistently ranking among the best utilities in the nation. PPL’s companies are also addressing challenges head‑on by investing in new infrastructure and technology that is creating a smarter, more reliable and resilient energy grid. We are committed to doing our part to advance a cleaner energy future and drive innovation that enables us to achieve net‑zero carbon emissions by 2050 while maintaining energy reliability and affordability for the customers and communities we serve. PPL is a positive force in the cities and towns where we do business, providing support for programs and organizations that empower the success of future generations by helping to build and maintain strong, diverse communities today.

Overview

NOTE: This role is HYBRID requiring 3 days on‑site at one of our locations in: Louisville, KY or Allentown, PA. #INDPPL #LI-Hy

This role is responsible for executing cybersecurity and IT risk assessment activities, analyzing risk exposures, documenting findings, and supporting the development and tracking of risk mitigation strategies across the enterprise. The analyst will work with cybersecurity, IT, and business stakeholders to evaluate risks, maintain risk information, and support continuous improvement of PPL's cybersecurity risk management program, including efforts that strengthen employee security awareness and risk‑informed decision‑making. The Intermediate level performs routine to moderately complex work using established procedures, with moderate guidance from management or more senior team members

Responsibilities
  • Support cybersecurity awareness activities, including coordinating phishing simulations, drafting awareness communications, tracking participation or engagement metrics, and helping identify opportunities to improve employee security behaviors and risk‑informed decision‑making.
  • Collaborate with cybersecurity, IT, and business stakeholders to gather risk information, assess risk exposure, document conclusions, and support mitigation planning.
  • Conduct cybersecurity and IT risk assessments for systems, applications, third parties, technologies, or business processes using established risk methodologies and guidance.
  • Maintain risk register entries, assessment records, dashboards, and reporting inputs to support accurate and timely cybersecurity risk reporting.
  • Analyze risk data, identify trends or recurring issues, and prepare clear summaries to support management review, escalation, and decision‑making.
  • Support the review, maintenance, and improvement of cybersecurity policies, standards, procedures, and risk management practices.
  • Monitor emerging threats, vulnerabilities, control issues, and regulatory or framework changes, and assist in assessing potential impacts to cybersecurity and IT risk.
  • Contribute to team knowledge sharing by documenting procedures, sharing lessons learned, and supporting onboarding or peer learning as needed.
  • Support incident response and post‑incident risk analysis by reviewing relevant information, documenting risk implications, and helping identify control gaps or improvement opportunities.
  • All other duties and projects as assigned.
  • Performs other duties as assigned.
  • Complies with all policies and standards.
Qualifications
  • Bachelor's Degree in Cybersecurity, Information Technology, Risk Management, Computer Science, Computer Information Systems, Business, or a related field
  • 2+ years of related experience in cybersecurity, IT risk management, IT audit, information security, technology compliance, infrastructure, cloud, application security, or related IT field.
  • Working knowledge of cybersecurity risk management concepts, control frameworks, and risk assessment methodologies, such as NIST Cybersecurity Framework, NIST Risk Management Framework, CIS Controls, COBIT, ISO 27001, or FAIR.
  • Strong written and verbal communication skills, including the ability to translate technical risk information into clear business terms, prepare concise documentation, and escalation high‑risk issues appropriately.
  • 3+ years of experience in cybersecurity, IT risk management, IT audit, technology compliance, or related field.
  • Relevant professional certification such as Security+, GSEC, SSCP, CRISC, CISA, CISM, CGRC, or equivalent.
  • Experience preparing risk assessments, risk register entries, treatment plans, control observations, dashboards, or stakeholder reporting.
  • Experience using GRC, IRM, audit, compliance, or risk management platforms such as ServiceNow IRM, Archer, and OneTrust.
  • Familiarity with data analysis, reporting, automation, or scripting tools such as Python, PowerShell, Power BI, SQL, or similar technologies.
  • Familiarity with enterprise technology environments, including cloud services, infrastructure, networking, identity and access management, applications, or hybrid environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Intermediate Cybersecurity Risk Analyst
Intermediate Cybersecurity Risk Analyst

Ppl-Corporation • Allentown

Hybrid
USD 80,000 - 120,000
Senior Director Cyber Operations & Threat Intelligence
Senior Director Cyber Operations & Threat Intelligence

Eetdbuyersguide • Allentown

Hybrid
USD 180,000 - 240,000
Strategic Finance Analyst
Strategic Finance Analyst

PPL Corporation • Allentown

Hybrid
USD 70,000 - 90,000
Senior Manager Modern Workplace Architecture
Senior Manager Modern Workplace Architecture

PPL Corporation • Louisville (KY)

Hybrid
USD 140,000 - 180,000
Accounting/Finance Intern - Risk Management (Hybrid KY)
Accounting/Finance Intern - Risk Management (Hybrid KY)

Ppl-Corporation • Louisville (KY)

On-site
USD 21,000 - 30,000
Senior Manager EU Regulatory
Senior Manager EU Regulatory

PPL Corporation • Allentown

Hybrid
USD 140,000 - 200,000
Manager - Executive Tech Support
Manager - Executive Tech Support

Ppl-Corporation • Allentown

Hybrid
USD 120,000 - 180,000
Senior Manager EU Regulatory
Senior Manager EU Regulatory

Ppl-Corporation • Allentown

Hybrid
USD 140,000 - 170,000
Cybersecurity Risk Analyst (Hybrid) - Risk & Awareness
Cybersecurity Risk Analyst (Hybrid) - Risk & Awareness

PPL Corporation • Allentown

Hybrid
USD 80,000 - 110,000
Hybrid work model
Developer Team Lead
Developer Team Lead

PPL Corporation • Providence (RI)

Hybrid
USD 110,000 - 140,000