Demo

Application Security Lead Engineer

PPL
Louisville, KY Full Time
POSTED ON 2/14/2025
AVAILABLE BEFORE 2/10/2026

Company Summary Statement

As one of the largest investor-owned utility companies in the United States, PPL Corporation (NYSE : PPL), is committed to creating long-term, sustainable value for our 3.5 million customers, our shareowners and the communities we serve. Our high-performing regulated utilities — PPL Electric Utilities, Louisville Gas and Electric, Kentucky Utilities and Rhode Island Energy — provide an outstanding experience for our customers, consistently ranking among the best utilities in the nation. PPL’s companies are also addressing challenges head-on by investing in new infrastructure and technology that is creating a smarter, more reliable and resilient energy grid. We are committed to doing our part to advance a cleaner energy future and drive innovation that enables us to achieve net-zero carbon emissions by 2050 while maintaining energy reliability and affordability for the customers and communities we serve. PPL is a positive force in the cities and towns where we do business, providing support for programs and organizations that empower the success of future generations by helping to build and maintain strong, diverse communities today.

Overview

The Cybersecurity organization advances the overall state of security at PPL through critical initiatives and coordination of large security and customer-focused projects. The organization builds and procures technologies, tools, and processes to better enable teams at PPL to develop secure platforms and protect data and systems with appropriate security controls. IT Cybersecurity also develops systems to monitor and respond to attacks against our systems, provides educational awareness to the corporation on security best practices, and ensures data sharing relationships with third parties securely protect PPL information.

PPL is seeking a highly skilled Application Security Lead Engineer to join our Cybersecurity organization. In this role, you will work closely with our Product Cybersecurity Manager to ensure the security and integrity of our applications and software products. You will provide expert guidance, conduct security assessments, and help shape the security posture of our products. If you are passionate about application security and have a deep understanding of modern software development practices, this position is ideal for you. #LI-Hybrid

Responsibilities

Conduct security assessments of applications, including vulnerability scanning,penetration testing, and fuzzing.

Complete static and dynamic application security testing to identify vulnerabilities and weaknesses

Participate in code reviews to identify potential vulnerabilities, weaknesses, defects, etc.

Complete Threat Modeling assessments, analyze impact, and develop mitigation strategies.

Perform review and testing around Application Programming Interface security

Assist relevant parties on identified gaps based on analysis and execute strategies to mitigate / address the risk.

Integrate security into the software development pipeline using secure software development lifecycle processes.

Create and / or Improve Data Flow Mapping and System Interface Tracking in conjunction with the Product Development and Enterprise Architecture teams.

Collaborates with business and technical owners, while engaging relevant SME’s, to establish compliance standards and trackable metrics.

Maintain Knowledge and stay up to date on developing security technologies and integrate new technologies into architecture designs, where applicable.

All other duties and projects as assigned.

Qualifications

Education

  • Bachelor’s degree in Computer Science, Information Security, and / or a related field or an equivalent level of work related experience.

Experience

A minimum of 7 years of experience in cybersecurity with a focus on software development, secure by design principles, and / or security architecture.

Proficiency in conducting security testing, including vulnerability scanning, and static and dynamic code analysis.

Expertise in system hardening, including vulnerability assessment, penetration testing, and configuration management.

Expertise in designing secure architectures using established frameworks

Experience in application security tools and IDE Plug-in environments, including HP Fortify.

Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25.

Experience in the use of threat modeling tools,and understanding of frameworks such as STRIDE and PASTA.

Cloud Technology Expertise : Demonstrate a working knowledge of various enterprise technology stacks used to build applications in the cloud. Your understanding of cloud infrastructure will enable you to assess security aspects unique to cloud-based mobile applications and APIs.

Cloud Platform Experience : Possess working knowledge and practical experience in security testing within cloud platforms, particularly Azure. Your familiarity will be crucial for assessing the security of cloud-hosted mobile applications and APIs.

Experience in Cloud Native Security practices and technologies including Container security, Serverless security, Kubernetes security and Threat detection.

Experience in utilizing Cloud Native Security Tools and Platforms such as Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and Cloud Access Security Brokers (CASB).

Knowledge of federal compliance standards, including NIST 800-53 and NIST CSF.

Experience working in Agile teams and have knowledge of Agile principles and practices.

Ability to follow outlined processes and procedures with high degree of accuracy.

Strong analytical skills to assess risks and vulnerabilities in complex systems.

Strong leadership, communication, and interpersonal skills.

Collaborative and effective in cross-functional team environments.

Preferred Qualifications

Professional certifications such as CISSP, CSSLP, or CEH

Proficiency in scripting and automation for security testing.

Experience with AWS and Google Cloud services

Experience utilizing the Scaled Agile Framework (SAFe)

Experience in securing Artificial Intelligence, Machine Learning, etc and maintaining integrity of those powered solutions.

Education

  • Bachelor’s degree in Computer Science, Information Security, and / or a related field or an equivalent level of work related experience.
  • Experience

    A minimum of 7 years of experience in cybersecurity with a focus on software development, secure by design principles, and / or security architecture.

    Proficiency in conducting security testing, including vulnerability scanning, and static and dynamic code analysis.

    Expertise in system hardening, including vulnerability assessment, penetration testing, and configuration management.

    Expertise in designing secure architectures using established frameworks

    Experience in application security tools and IDE Plug-in environments, including HP Fortify.

    Experience with securing enterprise web applications and OWASP Top 10, CVSS, CWE, WASC, and SANS-25.

    Experience in the use of threat modeling tools,and understanding of frameworks such as STRIDE and PASTA.

    Cloud Technology Expertise : Demonstrate a working knowledge of various enterprise technology stacks used to build applications in the cloud. Your understanding of cloud infrastructure will enable you to assess security aspects unique to cloud-based mobile applications and APIs.

    Cloud Platform Experience : Possess working knowledge and practical experience in security testing within cloud platforms, particularly Azure. Your familiarity will be crucial for assessing the security of cloud-hosted mobile applications and APIs.

    Experience in Cloud Native Security practices and technologies including Container security, Serverless security, Kubernetes security and Threat detection.

    Experience in utilizing Cloud Native Security Tools and Platforms such as Cloud Security Posture Management (CSPM), Cloud Workload Protection Platforms (CWPP), and Cloud Access Security Brokers (CASB).

    Knowledge of federal compliance standards, including NIST 800-53 and NIST CSF.

    Experience working in Agile teams and have knowledge of Agile principles and practices.

    Ability to follow outlined processes and procedures with high degree of accuracy.

    Strong analytical skills to assess risks and vulnerabilities in complex systems.

    Strong leadership, communication, and interpersonal skills.

    Collaborative and effective in cross-functional team environments.

    Preferred Qualifications

    Professional certifications such as CISSP, CSSLP, or CEH

    Proficiency in scripting and automation for security testing.

    Experience with AWS and Google Cloud services

    Experience utilizing the Scaled Agile Framework (SAFe)

    Experience in securing Artificial Intelligence, Machine Learning, etc and maintaining integrity of those powered solutions.

    Conduct security assessments of applications, including vulnerability scanning,penetration testing, and fuzzing.

    Complete static and dynamic application security testing to identify vulnerabilities and weaknesses

    Participate in code reviews to identify potential vulnerabilities, weaknesses, defects, etc.

    Complete Threat Modeling assessments, analyze impact, and develop mitigation strategies.

    Perform review and testing around Application Programming Interface security

    Assist relevant parties on identified gaps based on analysis and execute strategies to mitigate / address the risk.

    Integrate security into the software development pipeline using secure software development lifecycle processes.

    Create and / or Improve Data Flow Mapping and System Interface Tracking in conjunction with the Product Development and Enterprise Architecture teams.

    Collaborates with business and technical owners, while engaging relevant SME’s, to establish compliance standards and trackable metrics.

    Maintain Knowledge and stay up to date on developing security technologies and integrate new technologies into architecture designs, where applicable.

    All other duties and projects as assigned.

    Remote Work

    The company reserves the right to determine if this position will be assigned to work on-site, remotely, or a combination of both. Assigned work location may change. In the case of remote work, physical presence in the office / on-site may be required to engage in face-to-face interaction and coordination of work among direct reports and co-workers.

    Equal Employment Opportunity

    Our company is an equal opportunity, affirmative action employer dedicated to diversity and the strength it brings to the workplace. All qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, national origin, protected veteran status, sexual orientation, gender identify, genetic information, disability status, or any other protected characteristic.

    If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
    Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

    What is the career path for a Application Security Lead Engineer?

    Sign up to receive alerts about other jobs on the Application Security Lead Engineer career path by checking the boxes next to the positions that interest you.
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $220,784 - $286,649
    Income Estimation: 
    $152,549 - $188,894
    Income Estimation: 
    $194,072 - $240,547
    Income Estimation: 
    $135,994 - $168,063
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $77,991 - $108,747
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $112,673 - $137,290
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    Income Estimation: 
    $111,725 - $147,313
    Income Estimation: 
    $139,945 - $168,577
    Income Estimation: 
    $140,233 - $181,029
    Income Estimation: 
    $161,209 - $233,553
    View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

    Job openings at PPL

    PPL
    Hired Organization Address Bedford, KY Intern
    Company Summary Statement Louisville Gas and Electric Company and Kentucky Utilities Company, part of the PPL Corporatio...
    PPL
    Hired Organization Address Ghent, KY Full Time
    Company Summary Statement As one of the largest investor-owned utility companies in the United States, PPL Corporation (...
    PPL
    Hired Organization Address Allentown, PA Full Time
    Directs, coordinates, and supervises the daily activities of engineers and technicians in single or closely related fiel...
    PPL
    Hired Organization Address Allentown, PA Full Time
    Company Summary Statement As one of the largest investor-owned utility companies in the United States, PPL Corporation (...

    Not the job you're looking for? Here are some other Application Security Lead Engineer jobs in the Louisville, KY area that may be a better fit.

    Application Security Engineer

    NTT DATA, Louisville, KY

    Application Security Engineer

    NTT DATA North America, Louisville, KY

    AI Assistant is available now!

    Feel free to start your new journey!