Job Summary
Security Controls Specialist is an individual contributor responsible for assessing, monitoring, and improving the effectiveness of cybersecurity controls across the organization. This role partners with Technology, Security, Compliance, Audit, and business stakeholders to identify and mitigate risk, evaluate control performance, support regulatory compliance efforts, and strengthen the organization's overall security posture. The position performs risk-based assessments, develops and maintains control documentation, evaluates control effectiveness, supports audit readiness activities, and drives continuous improvement initiatives through automation, metrics, and operational reporting. The Security Specialist serves as a trusted advisor to stakeholders by translating security requirements into practical, business-focused risk management solutions.
What You’ll Do:
Security Controls Management
- Execute and maintain administrative, technical, operational, and detective security controls to ensure consistent performance and regulatory compliance.
- Evaluate and assess the effectiveness of administrative, technical, operational, and detective security controls.
- Perform control testing, validation, and monitoring activities to verify compliance with established security requirements.
- Develop, maintain, and enhance control procedures, standards, and supporting documentation.
- Identify control gaps, weaknesses, or deficiencies and recommend appropriate remediation strategies.
- Support implementation of new controls and enhancements to improve operational efficiency and risk reduction.
- Collaborate with business and technology teams to ensure controls remain effective as systems and processes evolve.
Compliance & Audit Readiness
- Support internal and external audits by producing evidence, validating control execution, and coordinating stakeholder responses.
- Maintain audit-ready documentation and supporting artifacts.
- Assist with regulatory compliance activities aligned to applicable frameworks and standards.
- Review controls for ongoing compliance and identify opportunities for process improvement and automation.
- Participate in audit remediation activities and corrective action tracking.
Monitoring, Metrics & Reporting
- Develop and maintain security control metrics, dashboards, and reporting capabilities.
- Analyze trends and control performance data to identify areas requiring management attention.
- Partner with data and reporting teams to automate evidence collection and control monitoring activities.
- Produce reports that communicate risk exposure, compliance status, remediation progress, and overall security posture.
- Support the development of meaningful and repeatable performance indicators for security controls and compliance programs.
Stakeholder Engagement
- Serve as a liaison between cybersecurity, operational technology, technology support teams, and business stakeholders.
- Provide consultative guidance on security requirements, control implementation, and risk mitigation strategies.
- Educate stakeholders on security processes, controls, risk management principles, and compliance obligations.
- Support projects and initiatives by integrating security requirements throughout the project lifecycle.
- Build strong partnerships that promote a risk-aware and security-focused culture.
Required Qualifications and Skills
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.
- Associate's degree with 2 years relevant experience in security (cyber or physical); equivalent combination of education and relevant experience may be considered.
- Experience in cybersecurity, risk management, compliance, audit, or security controls management.
- Experience performing security assessments, risk analysis, or control testing activities.
- Experience supporting regulatory compliance or audit programs.
- Experience working with cross-functional technology and business teams.
- Excellent written and verbal communication skills, with strong analytical and critical-thinking ability.
- Ability to investigate handle sensitive and confidential information.
Preferred Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.
- Security governance, risk, and compliance (GRC) principles.
- Security control frameworks and assessment methodologies.
- Security monitoring and reporting processes.
- Risk assessment and remediation practices.
- Audit readiness and evidence management.
- Knowledge of regulatory frameworks such as NERC CIP, NIST CSF, NIST 800-53, CIS Controls, ISO 27001, or similar frameworks is preferred.
- Risk analysis and critical thinking.
- Security controls assessment.
- Analytical problem solving.
- Technical and business communication.
- Regulatory compliance knowledge.
- Stakeholder relationship management.
- Process improvement and automation.
- Report writing and presentation skills.
- Continuous improvement mindset.
What We're Looking For:
- Security Spec (SG6) Education and Work Experience requirements are listed below: Bachelor's degree OR Associates degree with one-year relevant experience in system administration/help desk/security (cyber or physical) OR High School Diploma/GED with 2 years relevant experience in IT system administration/help desk/security (cyber or physical); OR graduation from an approved Cybersecurity Program; alternatively, may have non-degree qualifications (such as hands-on demonstrated ability in a technical interview/assessment). No additional experience required in addition to experience identified above.
- Security Spec Sr (SG7) Education requirements are listed below: Bachelor's degree OR Associates degree with 2 years relevant experience in system administration/help desk/security (cyber or physical) OR High School Diploma/GED with 3 years relevant experience in IT system administration/help desk/security (cyber or physical); OR graduation from an approved Cybersecurity Program; alternatively may have non-degree qualifications (such as hands-on demonstrated ability in a technical interview/assessment). Work Experience requirement listed below: 2 or more years of Information Technology related experience; OR 1 or more years of security related experience, which may include military/government work experience in addition to any experience identified above.
- Security Spec Prin (SG8) Education requirements are listed below: Bachelor's degree OR Associates degree with 2 years relevant experience in system administration/help desk/security (cyber or physical) OR High School Diploma/GED with 4 years relevant experience in IT system administration/help desk/security (cyber or physical); OR graduation from an approved Cybersecurity Program; alternatively, may have non-degree qualifications (such as hands-on demonstrated ability in a technical interview/assessment). Work Experience requirement listed below: 4 or more years of Information Technology related experience; OR 2 or more years of security related experience, which may include military/government work experience in addition to any experience identified above.
- Security Spec Lead (SG9) Education requirements are listed below: Bachelor's degree OR Associates degree with 2 years relevant experience in system administration/help desk/security (cyber or physical) OR High School Diploma/GED with 4 years relevant experience in IT system administration/help desk/security (cyber or physical). Work Experience requirement listed below: 7 or more years of Information Technology related experience; OR 5 or more years of security related experience, which may include military/government work experience in addition to any experience identified above.
Compensation Data
Compensation Grade: SP20-006
Compensation Range: $74,551.00 - $151,132.50
Physical Demand Level
The Physical Demand Level for this job is: S - Sedentary Work: Exerting up to 10 pounds of force occasionally (Occasionally: activity or condition exists up to 1/3 of the time) and/or a negligible amount of force frequently. (Frequently: activity or condition exists from 1/3 to 2/3 of the time) to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time but may involve walking or standing for brief periods of time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Equal Employment Opportunity
It is hereby reaffirmed that it is the policy of American Electric Power (AEP) to provide Equal Employment Opportunity in all respects of the employer-employee relationship including recruiting, hiring, upgrading and promotion, conditions and privileges of employment, company sponsored training programs, educational assistance, social and recreational programs, compensation, benefits, transfers, discipline, layoffs and termination of employment to all employees and applicants without discrimination because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, veteran or military status, disability, genetic information, or any other basis prohibited by applicable law. When required by law, we might record certain information or applicants for employment may be invited to voluntarily disclose protected characteristics.
Company Culture and Mission
At AEP, we’re more than just an energy company - we’re a team of dedicated professionals committed to delivering safe, reliable, and innovative energy solutions. Guided by our mission to put the customer first, we strive to exceed expectations by listening, responding, and continuously improving the way we serve our communities. If you're passionate about making a meaningful impact and being part of a forward-thinking organization, this is the company for you! We’re looking for team members to help create the grid of the future. Learn more about our commitment to creating a supportive, inclusive work culture that values different experiences.