Cloud Security Principal - PPL Services Corporation
Allentown, PA 18101
About the Job
The Cybersecurity organization advances the overall state of security at PPL through critical initiatives and coordination of large security and customer-focused projects. The organization builds and procures technologies, tools, and processes to better enable teams at PPL to develop secure platforms and protect data and systems with appropriate security controls. IT Cybersecurity also develops systems to monitor and respond to attacks against our systems, provides educational awareness to the corporation on security best practices, and ensures data sharing relationships with third parties securely protect PPL information.
PPL is seeking a highly skilled Cloud Security Principal Architect to join our Cybersecurity organization. In this role, you will work closely with our Cloud Engineering team to ensure the security and configuration of the PPL cloud infrastructure, including Microsoft services and Azure cloud environment. You will have direct responsibility for the usage and monitoring of the cyber technology within the cloud environment as well as leading the cloud security strategy. You will provide expert guidance, conduct security assessments, and provide detailed design and implementation of secure cloud architecture. If you are passionate about cloud security and have a deep understanding of Microsoft Azure, M365, and other cloud infrastructure environments, this position is ideal for you.
Responsibilities:
- Develop and Implement a comprehensive cloud security strategy that aligns with the organization’s overall security objectives.
- Design and document secure cloud architectures that meet the organization's functional and security requirements.
- Design and/or evaluate current cloud infrastructure and incorporate security principles into all stages of the System Development Lifecycle.
- Utilize Infrastructure as Code (IaC) solutions to enhance efficiency and control of processes.
- Ensure user access and privileged account management to cloud resources is aligned to industry best practices and frameworks.
- Responsible for the governance of Cloud Security policies, procedures, and standards.
- Perform security reviews of cloud architecture, infrastructure, and applications, identify gaps, develop a security risk management plan, and execute strategies to mitigate/address identified risk.
- Collaborate with cross-functional teams to integrate security controls and processes into cloud infrastructure and applications.
- Assess and recommend security tools, technologies, and services that enhance cloud security posture.
- Serve as a Subject Matter Expert on Cloud Security related topics, best practices, emerging technologies and the evolving threat landscape.
- Identify and apply strategies to optimize resource utilization and minimize cost.
- Provide guidance, coaching, and support in the development of junior staff members.
- All other duties and projects as assigned.
Education
- Bachelor’s degree in Computer Science, Information Security, and/or a related field or an equivalent level of work related experience
Experience
- A minimum of 10+ years of direct cybersecurity cloud experience in the configuration and support of cloud applications and infrastructure
- Experience in the configuration and support of Microsoft 365 services including:
- Microsoft Endpoint Manager – Intune and Configuration Manager
- Microsoft Defender for Cloud
- Conditional Access
- Microsoft Identity and Access - Microsoft 365 Active Directory/Entra and ADFS.
- Understanding of modern cloud technology components and deployment patterns: virtual machines, containers, Kubernetes, serverless, IaC, etc.
- Demonstrated knowledge of Azure architecture and core services such as Virtual Machines, Group Policy, MFA, Azure Active Directory, Management Groups, Resource Groups, Azure Regions, Azure Functions, Azure Networking, Azure IPsec Connections, Network Security Groups, Azure VDI, and Firewalls.
- Experience with DevOps methodologies and tools
- Scripting and Programming: skills in scripting languages like PowerShell or Azure CLI for automation.
- Knowledge of network architectures, including VNETs, subnets, VPNs, and ExpressRoute, along with an understanding of Azure security tools and features like Azure Active Directory, Network Security Groups, and Azure Key Vault.
- Cloud Technology Expertise: demonstrate a working knowledge of various enterprise technology stacks used to build services in the cloud.
- Cloud Platform Experience: possess working knowledge and practical experience in security testing within cloud platforms, particularly Azure.
- Experience in Cloud Native Security practices and technologies including Container security, Serverless security, Kubernetes security and Threat detection.
- Experience in utilizing Cloud Native Security Tools and Platforms such as Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and Cloud Access Security Brokers (CASB).
- Experience in Security and/or Regulatory Frameworks such as NIST, Azure Security Center, CIS Benchmarks, SOX, NERC CIP, etc.
- Experience working in Agile teams and have knowledge of Agile principles and practices.
- Strong leadership, communication, and interpersonal skills.
- Collaborative and effective in cross-functional team environments.
- Strong analytical skills to assess risks and vulnerabilities in complex systems.
Preferred Qualifications
- Knowledge of programming languages like Python, .NET, or Java.
- Experience with AWS and Google Cloud services.
- Experience with building CI/CD pipelines to support application and infrastructure deployments.
- Understanding of data analytics and machine learning concepts.
- Proficiency in scripting and automation for security testing.
- Knowledge of Azure configuration best practices.
- Experience utilizing the Scaled Agile Framework (SAFe).
- Relevant cybersecurity certifications (e.g. CISSP, CISM, CISA, CCSP).
- Relevant Microsoft Certifications (e.g. Azure Administration Associate, Azure Security Engineer Associate, Azure Network Engineer Associate).