Lead Cybersecurity Engineer - PPL Services Corporation
Allentown, PA 18101
About the Job
The Cybersecurity organization advances the overall state of security at PPL through critical initiatives and coordination of large security and customer-focused projects. The organization builds and procures technologies, tools, and processes to better enable teams at PPL to develop secure platforms and protect data and systems with appropriate security controls. IT Cybersecurity also develops systems to monitor and respond to attacks against our systems, provides educational awareness to the corporation on security best practices, and ensures data sharing relationships with third parties securely protect PPL information.
PPL is seeking a highly skilled Logging and Monitoring Lead Engineer to join our Cybersecurity organization. In this role, you will work closely in our Engineering team to ensure the security and configuration of logging and monitoring solutions at PPL. You will have direct responsibility for the usage, monitoring, and maintenance of the cyber technology used for logging and monitoring purposes to ensure data is being ingested completely and accurately, configurations are set up in accordance with expectations, and data is being analyzed. If you are passionate about setting up infrastructure to monitor and alert on anomalies, investigating those issues, and working on a team to respond and mitigate the risk,this position is ideal for you.
#INDPPL
Responsibilities:- Configure and manage monitoring tools to identify both security and operational related issues
- Maintain and support logging infrastructure (e.g., application, database, server, etc)
- Ensure data collected from various sources is complete and accurate
- Analyze network traffic data with other logs to gain understanding of cyber threats
- Define and implement standardized logging formats and practices
- Develop and maintain rules within the solutionto ensure configurations are appropriate.
- Assist in Investigations by analyzing logs and network traffic
- Develop, maintain, and enforce policies, procedures, and/or standards for logging and monitoring activities.
- Conduct regular reviews of the logging and monitoring infrastructure to identify areas for improvement.
- Collaborate with cross-functional teams to integrate security controls and processes into monitoring infrastructure and applications.
- Identify and apply strategies to optimize resource utilization and minimize cost
- Assist relevant parties on identified gaps based on analysis and execute strategies to mitigate/address the risk.
- All other duties and projects as assigned.
Education
- Bachelor’s degree in Computer Science, Information Security, and/or a related field or an equivalent level of work related experience.
Experience
- A minimum of 7+ years of cybersecurity experience in logging, monitoring, and network traffic analysis
- Expertise in logging and monitoring techniques (e.g., configuration, log aggregation, anomaly detection, investigation).
- Competency in using security solutions such as SIEM, IDS/IPS, firewall, and network monitoring systems.
- Proficiency in scripting languages (e.g., PowerShell)
- Experience in participating in Incident Response activities and exercises
- Experience in conducting investigations and communicating results to management
- Experience in Security and/or Regulatory Frameworks such as NIST
- Strong leadership, communication, and interpersonal skills.
- Collaborative and effective in cross-functional team environments.
- Strong analytical skills to assess risks and vulnerabilities in complex systems.
Preferred Qualifications
- Experience with threat intelligence and threat hunting techniques
- Relevant industry certifications (e.g,IBMQRadar Certified Administrator, Certified Network Security Architect (CNSA), Cisco Certified Network Associate Security (CCNA Security), Palo Alto Networks Certified Network Security Engineer (PCNSE))
- Experience working in Agile teams and have knowledge of Agile principles and practices.
- Experience utilizing the Scaled Agile Framework (SAFe)
- Certification in Cybersecurity is a plus (e.g., CISSP, CISM, CEH).
- Knowledge of cloud security technologies