- Salary
- $88k – $129k
- Location
- AEP Headquarters, United States of America · Austin, TX
- Type
- Full-time
- Department
- Security
- Education
- Bachelor
- Closing date
- Today
- Source
- Workday
Description
Job Posting End Date
09-21-2026Please note the job posting will close on the day before the posting end date.
Job Summary
The Security Readiness Specialist serves as a primary cybersecurity engagement partner for technology initiatives, business operations, vendor evaluations, proof-of-concepts, and major change efforts. This role helps ensure cybersecurity and compliance considerations are identified early, coordinated effectively, and incorporated into solution planning and delivery. The specialist works across business, technology, project, vendor, and cybersecurity teams to assess risk, route work to the right subject matter experts, document findings, coordinate remediation, and support secure delivery from idea through implementation.Job Description
We are seeking a Security Readiness Specialist to help build cybersecurity and compliance into technology initiatives from the earliest stages of planning through implementation and business operations. This role is ideal for a collaborative security professional who can assess risk, coordinate across teams, guide stakeholders through security requirements, and ensure initiatives receive the right level of cybersecurity engagement. The successful candidate will bring strong communication, risk management, and execution skills, along with the ability to translate cybersecurity expectations into practical guidance for business, technology, vendor, and project teams.
What you’ll do:
Essential Job Functions & Tasks
Key Responsibilities
Serve as a single point of contact for cybersecurity readiness across assigned portfolios, projects, business operations, and non-project initiatives.
Perform initial cyber and compliance risk assessments during portfolio planning, project scoping, demand intake, RFI/RFP activity, and proof-of-concept evaluation.
Partner with Portfolio BSAs, project managers, business unit partners, technology teams, vendors, and cybersecurity functional teams to right-size security engagement based on risk, scope, and complexity.
Review project charters, requirements, user stories, design documents, statements of work, vendor materials, third-party risk inputs, and existing security findings to identify required security involvement.
Coordinate cybersecurity and compliance readiness activities across security teams, including ownership, effort, timelines, dependencies, communications, and deliverables.
Provide guidance on cybersecurity policies, standards, compliance requirements, cloud patterns, generative AI governance, infrastructure changes, vendor reviews, and secure solution design.
Identify, assess, document, and manage project-related security findings and risks, including legacy findings that apply to current initiatives.
Support mitigation and remediation planning for vulnerabilities, penetration testing observations, policy deviations, operational findings, and security assessment outcomes.
Facilitate timely cybersecurity engagement through approved request channels, including ServiceNow Cyber Security and Compliance catalog requests and ARCS risk project activities where applicable.
Coordinate cyber kickoff activities, engagement surveys, risk determinations, and evidence of security review, including Cyber Security Risk Review deliverables or limited/no engagement confirmation when appropriate.
Triage security and compliance requests, answer general security questions, route inquiries to the appropriate teams, and escalate issues when specialized expertise is required.
Support non-project initiatives such as mobile app reviews, browser extension reviews, Partner Banner requests, Intune mobile app requests, proof-of-concepts, vendor evaluations, RFP reviews, and other role-based security requests.
Maintain clear communication with stakeholders regarding security expectations, risk decisions, remediation status, open issues, and required follow-up actions.
Promote early security engagement to reduce delivery delays, improve compliance outcomes, minimize organizational risk, and simplify coordination across cybersecurity teams.
Required Qualifications
Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Business, Risk Management, or a related field; or equivalent combination of education and relevant experience.
Experience supporting cybersecurity, technology delivery, risk management, compliance, project delivery, vendor review, or security operations activities.
Working knowledge of cybersecurity principles, risk assessment practices, security controls, vulnerability management, policy compliance, and secure technology delivery.
Ability to review technical and business documentation and translate security requirements into clear project guidance and actionable next steps.
Strong coordination, communication, facilitation, and stakeholder management skills across technical and non-technical audiences.
Demonstrated ability to manage multiple priorities, clarify ambiguous requests, track dependencies, and drive follow-through across teams.
Experience using enterprise workflow, risk, or project management tools such as ServiceNow, ARCS, project portfolio systems, or similar platforms.
Strong written communication skills, including the ability to document findings, summarize risks, prepare review evidence, and communicate decisions clearly.
Preferred Qualifications
Experience supporting technology portfolios, project intake, demand management, solution design reviews, or enterprise security engagement models.
Familiarity with third-party risk management, vendor security assessments, RFI/RFP reviews, statements of work, and proof-of-concept security evaluations.
Knowledge of cloud service models, SaaS application reviews, infrastructure security, identity and access management, mobile application governance, browser extension review, and AI acceptable use governance.
Experience coordinating vulnerability remediation, penetration testing results, policy exceptions, risk acceptance, or security finding closure.
Exposure to regulated environments, audit readiness, compliance programs, NERC CIP, SOX, or other security and operational risk frameworks.
Professional certification such as Security+, CISSP, CISM, CRISC, CISA, CCSP, or equivalent cybersecurity, risk, or compliance credential.
Core Competencies
Security-first mindset: Builds security and compliance into initiatives early to reduce risk and avoid late-stage delivery delays.
Consultative partnership: Works with business and technology teams to provide practical guidance aligned to organizational policies, standards, and delivery needs.
Risk-based decision making: Assesses engagement needs based on risk, complexity, scope, vendor involvement, technology type, and potential business impact.
Cross-functional coordination: Connects stakeholders with the right cybersecurity experts and keeps ownership, timelines, dependencies, and deliverables visible.
Clear communication: Translates security expectations, risks, findings, and remediation actions into concise language for project, business, technology, and leadership audiences.
Execution discipline: Tracks requests, findings, deliverables, and follow-ups through completion while maintaining accurate evidence of security review.
Key Stakeholders
Business unit partners and business process owners
Portfolio BSAs, project managers, demand managers, and project delivery teams
Technology application, infrastructure, cloud, telecom, mobility, operations, and support teams
Cybersecurity functional teams and subject matter experts
Third-party vendors, procurement partners, and third-party risk management teams
Security operations, risk management, compliance, audit, and governance partners
Expected Outcomes
Security and compliance requirements are identified early and incorporated into initiative scope and delivery planning.
Projects and non-project initiatives receive right-sized cybersecurity engagement based on risk and complexity.
Findings, vulnerabilities, and policy deviations are documented, communicated, and tracked with accountable owners.
Cybersecurity teams are coordinated efficiently, reducing confusion for business and technology stakeholders.
Security review evidence is delivered consistently through CSRRs, engagement records, findings documentation, or limited/no engagement communications.
Business and technology teams receive clear, practical guidance that supports secure, compliant, and timely delivery.
What We're Looking For:
Education requirements are listed below:
Bachelor's degree OR Associates degree with 2 years relevant experience in system administration/help desk/security (cyber or physical) OR High School Diploma/GED with 4 years relevant experience in IT system administration/help desk/security (cyber or physical); OR graduation from an approved Cybersecurity Program; alternatively may have non-degree qualifications (such as hands-on demonstrated ability in a technical interview/assessment).
Work Experience requirement listed below:
4 or more years of Information Technology related experience; OR 2 or more years of security related experience, which may include military/government work experience in addition to any experience identified above.
What You'll Get:
Base Salary from $87,633.00 - $128,688.00 /year. In addition to a competitive compensation, AEP offers a unique comprehensive benefits package that aims to support and enhance the overall well-being of our employees.
At AEP, we’re more than just an energy company — we’re a team of dedicated professionals committed to delivering safe, reliable, and innovative energy solutions. Guided by our mission to put the customer first, we strive to exceed expectations by listening, responding, and continuously improving the way we serve our communities. If you're passionate about making a meaningful impact and being part of a forward-thinking organization, this is the company for you!
Compensation Data
Compensation Grade:
SP20-008Compensation Range:
$87,633.00 - $128,688.00The Physical Demand Level for this job is: S – Sedentary Work: Exerting up to 10 pounds of force occasionally (Occasionally: activity or condition exists up to 1/3 of the time) and/or a negligible amount of force frequently. (Frequently: activity or condition exists from 1/3 to 2/3 of the time) to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time but may involve walking or standing for brief periods of time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Hear about it first! Get job alerts by email. Log in to your Candidate Home Account today! If you don't have an account, you can create one.
It is hereby reaffirmed that it is the policy of American Electric Power (AEP) to provide Equal Employment Opportunity in all respects of the employer-employee relationship including recruiting, hiring, upgrading and promotion, conditions and privileges of employment, company sponsored training programs, educational assistance, social and recreational programs, compensation, benefits, transfers, discipline, layoffs and termination of employment to all employees and applicants without discrimination because of race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, veteran or military status, disability, genetic information, or any other basis prohibited by applicable law. When required by law, we might record certain information or applicants for employment may be invited to voluntarily disclose protected characteristics.