Intermediate Cybersecurity Risk Analyst
Job Fit Check
Base Career helps you apply smarter for this job.
Key skills for this role
Key Skills for This Role
Full Job Posting
NOTE: This role is HYBRID requiring 3 days on-site at one of our locations in: Louisville, KY or Allentown, PA. #INDPPL #LI-Hy
This role is responsible for executing cybersecurity and IT risk assessment activities, analyzing risk exposures, documenting findings, and supporting the development and tracking of risk mitigation strategies across the enterprise.
The analyst will work with cybersecurity, IT, and business stakeholders to evaluate risks, maintain risk information, and support continuous improvement of PPL's cybersecurity risk management program, including efforts that strengthen employee security awareness and risk-informed decision-making.
The Intermediate level performs routine to moderately complex work using established procedures, with moderate guidance from management or more senior team members
Core Responsibilities
- Support cybersecurity awareness activities, including coordinating phishing simulations, drafting awareness communications, tracking participation or engagement metrics, and helping identify opportunities to improve employee security behaviors and risk-informed decision-making.
- Collaborate with cybersecurity, IT, and business stakeholders to gather risk information, assess risk exposure, document conclusions, and support mitigation planning.
- Conduct cybersecurity and IT risk assessments for systems, applications, third parties, technologies, or business processes using established risk methodologies and guidance.
- Maintain risk register entries, assessment records, dashboards, and reporting inputs to support accurate and timely cybersecurity risk reporting.
- Analyze risk data, identify trends or recurring issues, and prepare clear summaries to support management review, escalation, and decision-making.
- Support the review, maintenance, and improvement of cybersecurity policies, standards, procedures, and risk management practices.
- Monitor emerging threats, vulnerabilities, control issues, and regulatory or framework changes, and assist in assessing potential impacts to cybersecurity and IT risk.
- Contribute to team knowledge sharing by documenting procedures, sharing lessons learned, and supporting onboarding or peer learning as needed.
- Support incident response and post-incident risk analysis by reviewing relevant information, documenting risk implications, and helping identify control gaps or improvement opportunities.
- All other duties and projects as assigned.
- Performs other duties as assigned.
- Complies with all policies and standards .
Bachelor'S Degree
in Cybersecurity, Information Technology, Risk Management, Computer Science, Computer Information Systems, Business, or a related field
Experience Details
2+ years
of related experience in cybersecurity, IT risk management, IT audit, information security, technology compliance, infrastructure, cloud, application security, or related IT field.
Working knowledge of cybersecurity risk management concepts, control frameworks, and risk assessment methodologies, such as NIST Cybersecurity Framework, NIST Risk Management Framework, CIS Controls, COBIT, ISO 27001, or FAIR.
Strong written and verbal communication skills, including the ability to translate technical risk information into clear business terms, prepare concise documentation, and escalate high-risk issues appropriately.
Preferred Qualifications
- 3+ years of experience in cybersecurity, IT risk management, IT audit, technology compliance, or related field.
- Relevant professional certification such as Security+, GSEC, SSCP, CRISC, CISA, CISM, CGRC, or equivalent.
- Experience preparing risk assessments, risk register entries, treatment plans, control observations, dashboards, or stakeholder reporting.
- Experience using GRC, IRM, audit, compliance, or risk management platforms such as ServiceNow IRM, Archer, and OneTrust.
- Familiarity with data analysis, reporting, automation, or scripting tools such as Python, PowerShell, Power BI, SQL, or similar technologies.
- Familiarity with enterprise technology environments, including cloud services, infrastructure, networking, identity and access management, applications, or hybrid environments.
About PPL Corporation
Energy utility holding company providing electricity and natural gas.
Visit company websiteJobs and hiring trendsApply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
More jobs at PPL Corporation
Summer 2025 - Accounting/Finance Intern - Rates & Regulatory Reporting (Hybrid)
Allentown, USA
Sr Digitl Tech Proc Specialist
Allentown, USA
Material Planner
Allentown, USA
Logistics Worker I
, USA
Project Manager-Regulatory
Allentown, USA
Summer 2025 - Accounting/Finance Intern - Rates & Regulatory Reporting (Hybrid)
Allentown, USA
Dist Service Tech - Trainee
Bloomsburg, USA
Field Supervisor Electrical
Lancaster, USA
Electrical Test Tech-Trainee
Northumberland, USA