Security Specialist - Security Controls Management

aep

Columbus (OH)

On-site

USD 90,000 - 120,000

Full time

5 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

American Electric Power is seeking a Security Controls Specialist to assess, monitor, and improve cybersecurity controls across the organization. You will partner with Technology, Security, Compliance, Audit, and business stakeholders to identify and mitigate risk and strengthen overall security posture.

The role conducts risk-based assessments, maintains control documentation, evaluates control effectiveness, supports audit readiness, and drives automation, metrics, and reporting to drive

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.
  • Associate's degree with 2 years relevant experience in security (cyber or physical).
  • Equivalent combination of education and relevant experience may be considered.
  • Experience in cybersecurity, risk management, compliance, audit, or security controls management.
  • Experience performing security assessments, risk analysis, or control testing activities.
  • Experience supporting regulatory compliance or audit programs.
  • Experience working with crossFunctional technology and business teams.

Responsibilities

  • Security Controls Management: Execute and maintain administrative, technical, operational, and detective security controls; evaluate effectiveness; test and monitor for compliance; develop procedures and documentation; identify gaps and remediation; support new controls and improvements; collaborate with teams as systems evolve.
  • Compliance & Audit Readiness: Support audits with evidence, maintain audit-ready docs, assist with regulatory activities, review controls for ongoing compliance, and participate in remediation tracking.
  • Monitoring, Metrics & Reporting: Develop security control metrics and dashboards; analyze trends; automate evidence collection; produce risk and compliance reports; develop repeatable KPIs.
  • Stakeholder Engagement: Liaise between cybersecurity, OT, tech support, and business stakeholders; provide guidance on security requirements and risk mitigation; educate on processes and compliance; support projects with security requirements.

Skills

Communication
Analytical thinking
Cross-functional collaboration
Security controls understanding
Risk management

Education

Bachelor's degree in Cybersecurity, IT, CS, Risk Management, Business
Associate's degree with 2 years security experience

Job description

Job Posting End Date

09-19-2026

Please note the job posting will close on the day before the posting end date.

Job Summary

Security Controls Specialist is an individual contributor responsible for assessing, monitoring, and improving the effectiveness of cybersecurity controls across the organization.

This role partners with Technology, Security, Compliance, Audit, and business stakeholders to identify and mitigate risk, evaluate control performance, support regulatory compliance efforts, and strengthen the organization's overall security posture.

The position performs risk-based assessments, develops and maintains control documentation, evaluates control effectiveness, supports audit readiness activities, and drives continuous improvement initiatives through automation, metrics, and operational reporting. The Security Specialist serves as a trusted advisor to stakeholders by translating security requirements into practical, business-focused risk management solutions.

What You’ll Do
  • Security Controls Management:
    • Execute and maintain administrative, technical, operational, and detective security controls to ensure consistent performance and regulatory compliance.
    • Evaluate and assess the effectiveness of administrative, technical, operational, and detective security controls.
    • Perform control testing, validation, and monitoring activities to verify compliance with established security requirements.
    • Develop, maintain, and enhance control procedures, standards, and supporting documentation.
    • Identify control gaps, weaknesses, or deficiencies and recommend appropriate remediation strategies.
    • Support implementation of new controls and enhancements to improve operational efficiency and risk reduction.
    • Collaborate with business and technology teams to ensure controls remain effective as systems and processes evolve.
  • Compliance & Audit Readiness:
    • Support internal and external audits by producing evidence, validating control execution, and coordinating stakeholder responses.
    • Maintain audit-ready documentation and supporting artifacts.
    • Assist with regulatory compliance activities aligned to applicable frameworks and standards.
    • Review controls for ongoing compliance and identify opportunities for process improvement and automation.
    • Participate in audit remediation activities and corrective action tracking.
  • Monitoring, Metrics & Reporting:
    • Develop and maintain security control metrics, dashboards, and reporting capabilities.
    • Analyze trends and control performance data to identify areas requiring management attention.
    • Partner with data and reporting teams to automate evidence collection and control monitoring activities.
    • Produce reports that communicate risk exposure, compliance status, remediation progress, and overall security posture.
    • Support the development of meaningful and repeatable performance indicators for security controls and compliance programs.
  • Stakeholder Engagement:
    • Serve as a liaison between cybersecurity, operational technology, technology support teams, and business stakeholders.
    • Provide consultative guidance on security requirements, control implementation, and risk mitigation strategies.
    • Educate stakeholders on security processes, controls, risk management principles, and compliance obligations.
    • Support projects and initiatives by integrating security requirements throughout the project lifecycle.
    • Build strong partnerships that promote a risk-aware and security-focused culture.
Required Qualifications and Skills:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.
  • Associate's degree with 2 years relevant experience in security (cyber or physical)
  • Equivalent combination of education and relevant experience may be considered.
  • Experience in cybersecurity, risk management, compliance, audit, or security controls management.
  • Experience performing security assessments, risk analysis, or control testing activities.
  • Experience supporting regulatory compliance or audit programs.
  • Experience working with cross-functional technology and business teams.
  • Excellent written and verbal communication skills, with strong analytical and critical‑thinking ability.
  • Ability to investigate handle sensitive and confidential information.
Preferred Qualifications:
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field.
  • Security governance, risk, and compliance (GRC) principles.
  • Security control frameworks and assessment methodologies.
  • Security monitoring and reporting processes.
  • Risk assessment and remediation practices.
  • Audit readiness and evidence management.
  • Knowledge of regulatory frameworks such as NERC CIP, NIST CSF, NIST 800-53, CIS Controls, ISO 27001, or similar frameworks is preferred.
  • Risk analysis and critical thinking
  • Security controls assessment
  • Analytical problem solving
  • Technica
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Controls Assessor
Cyber Security Controls Assessor

Heyer Expectations LLC • Oakland (CA)

On-site
USD 90,000 - 120,000
Senior Manager of Risk and Compliance
Senior Manager of Risk and Compliance

PTR Global • United States

On-site
USD 100,000 - 130,000
Sr. Security Governance, Risk & Compliance Specialist
Sr. Security Governance, Risk & Compliance Specialist

clarioclinical • United States

On-site
USD 120,000 - 180,000
Cybersecurity Specialist
Cybersecurity Specialist

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Cyber Security Specialist
Cyber Security Specialist

X-Bow Systems Inc. • Luling (TX)

On-site
USD 70,000 - 110,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Subject Matter Expert (SME) Cybersecurity Consultant – Control Testing
Subject Matter Expert (SME) Cybersecurity Consultant – Control Testing

Kaizen Lab Inc. • Charlotte (NC)

On-site
USD 120,000 - 180,000
Senior Cyber Security Analyst
Senior Cyber Security Analyst

Walker Digital Table Systems, LLC • Las Vegas (NV)

On-site
USD 90,000 - 120,000
Senior Information Security Analyst – CSIRT
Senior Information Security Analyst – CSIRT

Jobtailor • Mount Laurel Township (NJ)

On-site
USD 110,000 - 170,000