Jobs · Finance · Florida

Compliance & Risk Analyst, SOX Focus, Progression (Level II)

Tampa Electric · Tampa, FL · 1 wk ago
FinanceFull-time

This position can be hired at any level within the job family of progression, based on education and experience, but is ideally suited for a Level II candidate.

About the Role

The Compliance & Risk Analyst/Advisor progression ensures all information systems products and services meet Technology organization standards and compliance obligations, including regulatory requirements, contractual requirements, and Emera requirements. Analysts are responsible for the maintenance, training, assurance, monitoring, and reporting of all IT standards and procedures, as well as Technology-related regulatory requirements for the Technology Department and individual business units.

Advancement to higher levels is performance-based, contingent on value added through increased duties, responsibilities, and accomplishments.

Responsibilities

  • Assurance and Information Management (25%):
    • Ensure quality methods and procedures are executed by the IT department to maintain compliance with regulatory requirements (e.g., NERC CIP, Sarbanes-Oxley, PCI DSS, DFARS, Emera, and customer requirements).
    • Manage compliance-related information and documentation consistent with retention requirements.
    • Support collection, review, and approval of compliance-related data.
    • Facilitate and track deliverables for root cause analysis, compliance reporting, technical feasibility exceptions, and NERC Alerts.
  • Controls & Monitoring (20%):
    • Administer IT Compliance Management Systems and Governance, Risk, and Compliance (GRC) tools.
    • Collect and sample evidence to support compliance demonstrations.
    • Escalate out-of-compliance items to senior management.
    • Participate in the implementation of technology-based tools (e.g., GRC) to support IT risk initiatives.
  • Reporting (20%):
    • Document quality problems and compliance issues, and assist in their resolution.
    • Perform quality audits across IT&T functions to ensure adherence to standards, procedures, and methodologies.
    • Monitor and report exceptions, risks, and exposures to Technology senior management.
  • Policies, Standards, and Processes (15%):
    • Analyze best-in-class processes (e.g., ITIL, NIST, COBIT) and stay current on regulatory and compliance issues.
    • Maintain Technology standards, procedures, and policies, including internal desk-level procedures.
  • Training and Communications (10%):
    • Develop and deliver quality process training to technical staff.
    • Act as an internal quality consultant to facilitate the use of Technology Standards and Procedures.
  • Performance Management (10%):
    • Establish and administer performance analysis activities (e.g., metrics) within assigned areas.

Level II Specific Responsibilities

  • Compliance Program Ownership (30%):
    • Responsible for one or more IT compliance programs (e.g., NERC CIP, PCI DSS, SOX, DFARS, Emera Cyber Security, DHS TSA Pipeline Security).
    • Facilitate and track deliverables for root cause analysis, violation reporting, technical feasibility exceptions, mitigation plan development, evidence reviews, external audit preparations, and NERC Alert responses.
    • Support the development of flow diagrams or illustrations for processes affected by regulations or contract terms.
    • Coordinate and facilitate audits (e.g., technical feasibility-exception audits, mitigation plan completion audits) with external auditors.
  • Policies & Procedures (25%):
    • Liaise with IT&T areas (e.g., IT Security, IT Project Management Office, IT Infrastructure) and business units to evaluate, design, and implement methodologies, procedures, and controls for compliance.
  • Additional Responsibilities (25%):
    • Provide updates to Business Strategy regarding cybersecurity and the impact of new legislation/regulatory requirements.
    • Work with technology teams and stakeholders to design, implement, and optimize IT risk assessment practices.
    • Act as a ruleset liaison and Subject Matter Expert (SME) for assigned compliance areas (e.g., Information Protection Program, NERC CIP).
    • Develop and facilitate compliance training for subject matter experts and contribute to IT Security awareness programs.
    • Coordinate cybersecurity awareness assessments via phishing campaigns.
  • Controls & Monitoring (20%):
    • Provide independent assessment and assurance of the IT control environment’s effectiveness and efficiency.
    • Administer and monitor the Tampa Electric compliance program by sampling compliance deliverables and assessing risk.
    • Utilize security tools to sample content and support IT compliance and risk initiatives.

Qualifications

  • Education: Bachelor’s degree in Computer Science, Information Systems, or a related field. Experience may be considered in lieu of formal education.
  • Certifications:
    • Required: Expected to obtain ITIL Certification within 6 months of employment.
    • Preferred: ITIL Certification, CISA, CISSP, CRISC, or CISM.
  • Experience:
    • Required: 5 years in information technology, audit, or a utility business environment, with at least 2 years in IT security, audit, or controls-based roles.
    • Preferred: IT security, IT audit, or controls experience.
  • Skills & Abilities:
    • Working knowledge of applicable regulatory requirements (e.g., SOX, SAP system landscape, configuration, or controls).
    • Ability to organize, document, and facilitate meetings.
    • Strong project management and analytical skills.
    • Ability to lead groups to consensus and handle complex situations with judgment and interpersonal skills.
    • High tolerance for stress.
    • Preferred: Proficiency in security tools (SIEM, EDR, TPAM), network protocols, security principles, and SharePoint document management.

Working Conditions

  • Normal office environment with occasional extended hours during the week and weekends.
  • Physical demands are typical of an office workplace.

Benefits

  • Competitive salary.
  • 401k Savings Plan with company matching.
  • Pension plan.
  • Paid time off and holidays.
  • Medical, prescription drug, and dental coverage.
  • Tuition Assistance Program.
  • Employee Assistance Program.
  • Wellness programs and on-site fitness centers.
  • Bonus plan and more.

Schedule

8-hour shifts, 5 days per week.

Similar jobs