Senior Director Cyber Operations & Threat Intelligence

Eetdbuyersguide

Allentown (Lehigh County)

On-site

USD 180,000 - 240,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

PPL is seeking a Senior Director of Cyber Operations to lead its enterprise cyber defense organization, including SOC, threat intelligence, detection engineering, and SOAR. This leader drives automation-first transformation and aligns operations to industry frameworks such as NIST CSF and AI RMF while overseeing risk for critical infrastructure.

The hybrid role requires 3 days onsite at one of our local offices: Allentown, PA; Providence, RI; or Louisville, KY.

Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; Master’s degree preferred but not required
  • 20+ years of experience in cybersecurity or related field, with senior leadership
  • Proven experience in managing cybersecurity operations and incident response
  • Strong leadership and project management skills
  • Excellent communication and collaboration abilities
  • In-depth knowledge of cybersecurity frameworks and best practices
  • Proficiency in security tools and technologies
  • Experience managing large, diverse teams and leading complex projects
  • Understanding of Agile principles and methods
  • Strong communication and collaboration skills with technical and non-technical stakeholders
  • Ability to adapt to new technologies and methodologies
  • Ability to align IT transformation initiatives with the overall business strategy

Responsibilities

  • Lead and evolve 24x7 SOC operations including monitoring, detection, and incident response
  • Direct cyber operations across SOC, Threat Intelligence, Detection Engineering, Security Engineering, SOAR
  • Drive operational maturity aligned to NIST CSF domains (Detect, Respond, Recover)
  • Maintain executive-ready visibility into cyber risk, operational performance, and incident posture
  • Lead enterprise cyber incident response and coordination for high-impact events
  • Establish and mature playbooks, escalation models, and executive communication protocols
  • Partner with legal, compliance, and business leadership during cyber events
  • Ensure readiness through exercises aligned to NERC CIP and resilience requirements
  • Operationalize threat intelligence into detection use cases
  • Lead detection engineering program to improve fidelity and reduce noise
  • Advance proactive threat hunting across enterprise and critical systems
  • Own design, implementation, and optimization of cyber tooling and platforms
  • Lead transition toward automation-first and Agentic SOC capabilities
  • Deploy and scale advanced SIEM and XDR capabilities, SOAR platforms
  • Ensure secure adoption and governance of AI in cyber operations aligned to NIST AI RMF
  • Establish integrated Attack Surface Management across enterprise
  • Lead risk-based vulnerability management prioritizing remediation by threat context
  • Integrate asset, exposure, and threat data to drive measurable risk reduction
  • Ensure cyber operations align with Regs like NERC CIP and support audits
  • Coordinate with OT/IT teams to protect grid operations

Skills

Leadership
Cybersecurity strategy
Incident response
Threat intelligence
Automation
NIST CSF

Education

Bachelor's in CS/IT/Cybersecurity
Master's degree preferred

Tools

SIEM
XDR
SOAR
MCP
Agentic SOC

Job description

Overview

NOTE: This is a hybrid role requiring 3 days onsite at one of our local offices: Allentown, PA; Providence, RI or Louisville, KY. #INDPPL #LI-Hybrid

The Senior Director of Cyber Operations leads PPL's enterprise cyber defense organization, responsible for Security Operations (SOC), Threat Intelligence, Detection Engineering, Security Engineering, and Security Orchestration, Automation, and Response (SOAR). This role oversees the day-to-day protection of a critical infrastructure environment and leads the ongoing transformation to a modern, intelligence-driven and automation-first cyber program. The leader will integrate emerging capabilities such as Agentic SOC architectures, Machine-driven Cyber Platforms (MCP), Attack Surface Management (ASM), and risk-based Vulnerability Management, while aligning operations to industry frameworks including NIST Cybersecurity Framework (CSF), NIST AI Risk Management Framework (AI RMF), and NERC CIP.

Responsibilities
Enterprise Cyber Operations Leadership
  • Lead and evolve PPL's 24x7 SOC operations, including monitoring, detection, and incident response
  • Direct cyber operations across:
    • Security Operations Center (SOC)
    • Threat Intelligence
    • Detection Engineering
    • Security Engineering
    • SOAR / automation platforms
  • Drive operational maturity aligned to NIST CSF domains (Detect, Respond, Recover)
  • Maintain executive-ready visibility into cyber risk, operational performance, and incident posture
Incident Response & Crisis Management
  • Lead enterprise cyber incident response and coordination, including high-impact events
  • Establish and mature playbooks, escalation models, and executive communication protocols
  • Partner with legal, compliance, and business leadership during cyber events
  • Ensure readiness through exercises aligned to NERC CIP and resilience requirements
Threat Intelligence & Detection Engineering
  • Operationalize intelligence-led defense by integrating threat intelligence into detection use cases
  • Lead detection engineering program to improve fidelity, reduce noise, and expand coverage
  • Advance proactive threat hunting capabilities across enterprise and critical systems
Security Engineering & Automation
  • Own design, implementation, and optimization of cyber tooling and platforms
  • Lead transition toward automation-first and Agentic SOC capabilities
  • Deploy and scale:
    • Advanced SIEM and XDR capabilities
    • SOAR platforms and playbook automation
    • MCP / AI-enabled cyber decision support systems
  • Ensure secure adoption and governance of AI in cyber operations aligned to NIST AI RMF
Attack Surface & Vulnerability Management
  • Establish integrated Attack Surface Management (ASM) across enterprise and external footprint
  • Lead risk-based vulnerability management program prioritizing remediation based on threat context and business criticality
  • Integrate asset, exposure, and threat data to drive measurable risk reduction
Critical Infrastructure & Regulatory Alignment
  • Ensure cyber operations align with NERC CIP requirements and broader regulatory obligations
  • Partner with compliance teams to support audits, evidence collection, and continuous improvement
  • Coordinate with OT/IT teams to protect grid operations and critical systems
Team Leadership & Culture
  • Lead a multi-disciplinary team spanning SOC, engineering, and threat intelligence functions
  • Develop talent, succession pipelines, and leadership bench strength
  • Foster a culture of accountability, innovation, and continuous improvement
  • Drive alignment with enterprise cybersecurity strategy and "Guardians of the Grid" mission
Qualifications
Required Education:
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; Master's degree preferred but not required
Required Experience:
  • 20+ years of experience in cybersecurity or a related field, with demonstrated experience in a senior leadership role.
  • Proven experience in managing cybersecurity operations and incident response
  • Strong leadership and project management skills
  • Excellent communication and collaboration abilities
  • In-depth knowledge of cybersecurity frameworks and best practices
  • Proficiency in security tools and technologies
  • Experience managing large, diverse teams and leading complex projects
  • Understanding of Agile principles and methods
  • Strong communication and collaboration skills with technical and non-technical stakeholders
  • Ability to adapt to new technologies and methodologies
  • Ability to align IT transformation initiatives with the overall business strategy
Preferred Qualifications:
  • Advanced degree or relevant certifications (e.g., CISSP, CISM, would be a plus)
  • Utilities industry experience
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Intermediate Cybersecurity Risk Analyst
Intermediate Cybersecurity Risk Analyst

Ppl-Corporation • Allentown

Hybrid
USD 80,000 - 120,000
Intermediate Cybersecurity Risk Analyst
Intermediate Cybersecurity Risk Analyst

PPL Corporation • Allentown

Hybrid
USD 80,000 - 110,000
Hybrid work model
Chief Cyber Operations & Threat Intelligence Lead
Chief Cyber Operations & Threat Intelligence Lead

Eetdbuyersguide • Allentown

Hybrid
USD 180,000 - 240,000
Manager - Executive Tech Support
Manager - Executive Tech Support

Ppl-Corporation • Allentown

Hybrid
USD 120,000 - 180,000
Sr Network Security Engineer
Sr Network Security Engineer

NEPSE Trading • Northern (KY)

Hybrid
USD 140,000 - 190,000
Senior Manager Modern Workplace Architecture
Senior Manager Modern Workplace Architecture

PPL Corporation • Louisville (KY)

Hybrid
USD 140,000 - 180,000
Sr Network Security Engineer
Sr Network Security Engineer

Ppl Llc • United States

On-site
USD 116,000 - 131,000
VP, Cloud Security Operations
VP, Cloud Security Operations

LPL Financial LLC • Austin (TX)

On-site
USD 154,000 - 258,000
401(k) matching
Health benefits
Employee stock options
+1
Cybersecurity Operations Manager
Cybersecurity Operations Manager

Jobtailor • Dearborn (MO)

On-site
USD 140,000 - 190,000
Lead, Cybersecurity Architecture & Operations
Lead, Cybersecurity Architecture & Operations

Culligan International • Northern (KY)

Hybrid
USD 140,000 - 180,000