'PoW which takes less energy' is an oxymoron. The whole point is to demonstrate cryptographically a certain amount of effort (combination of energy and efficiency of hardware implementing a deliberatly inefficient function) has taken place. The network adjusts the difficulty dynamically depending on the amount of effort being put in (basically the rewards are fixed: miners simply compete for a bigger slice of the pie by trying to put in more effort than their competitors). The only limit is when the miners stop making money off of it (and with the price of bitcoin they can buy a
lot of energy and still make a profit). This is all by design and the whole point is to make it a lot more profitable to secure the system than to attack it. The only way to really reduce the energy use of coin is to reduce the block rewards or reduce the price. But at a certain point it's more profitable to attack the system than secure it, so it's a difficult balancing act. This one which bitcoin makes no attempt at: the block reward is set to automatically decrease over time at a fixed rate and this hasn't and isn't likely to change. There's no particular reason bitcoin's rewards are either not overkill or sufficient to secure the network against an attacker. Etherium takes a more practical view: because the currency has built-in adjustments which can be made by the foundation, in theory it can adjust the block reward dynamically to the right amount, though there's both political issues in terms of appeasing the miners when you cut their profit and technical issues in actually working out what is good enough.
Likewise 'doing additional useful work' is not something you can actually do in a trustless manner like with proof of work (at least not most useful work: certainly there's no task which you could use for mining which anyone actually needs the kind of energy bitcoin uses throwing at it). You need something which is easily distributable relative the to the amount of computing power needed to do it (and even SETI/Folding @ home are really struggling at this point with modern hardware: computing power has outgrown bandwidth substantially), and easy verifiable that the work has been done. There are cryptocurrencies which try to distribute coins based on contributions to distributed computing, but they rely on a central authority to do so, defeating the whole point of cryptocurrencies.