American Electric Power is one of the largest electric utilities in the United States, delivering power to over 5 million customers across 11 states. The company's transmission system covers more than 200,000 square miles of territory - a sprawling attack surface that includes electric transmission networks, energy infrastructure, and digital infrastructure. That's critical infrastructure on a continental scale, which means the threat model spans nation-state actors probing industrial control systems, ransomware targeting operational technology, and supply chain compromises across a massive vendor ecosystem.
Founded in 1906, AEP is now executing a $72 billion five-year capital plan, much of it aimed at grid modernization and cleaner energy. That kind of investment scales up both the digital footprint and the security challenge: more connected devices, more networked systems, more attack vectors converging on operational technology and IT alike. The cybersecurity team operating here isn't defending a SaaS product - they're protecting the physical grid, SCADA systems, and the digital infrastructure that keeps electricity flowing to homes and businesses.
The operational domain demands fluency in ICS/SCADA security, network segmentation for critical infrastructure, and compliance frameworks like NERC CIP that govern bulk electric system cybersecurity. This is a shop where security work has tangible, physical consequences - where a misconfigured firewall or a delayed patch doesn't just mean data loss, it means potential disruption to millions of people and the broader energy grid.





