Title: IAM Security Engineer
Company: Tampa Electric Company
Location: Bearss Operations Center
State and City: Florida - LUTZ
Shift: 8 Hr. X 5 Days
TITLE: IAM Security Technologist Progression
PERFORMANCE COACH: Manager/Sr. Manager Cyber Protection
COMPANY: Tampa Electric Company
DEPARTMENT: Technology
Note that this position can be hired at any level within the job family progression based in Education and years of Experience
FOCUS AREAS:
- Strong hands-on Saviynt IGA experience, including identity lifecycle management, access reviews, application onboarding and integrations
- CyberArk PAM experience
- Microsoft Entra ID / Active Directory, RBAC and access governance
- IAM integrations, connectors, APIs, scripting and automation
- Ability to work strategically while also being hands-on and extend support for implementations and activities outside the standard MSS scope
IAM Security Technologist Associate
POSITION CONCEPT
The IAM Security Technologist Associate is responsible for supporting the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Supports all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Assists with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing IT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing and possessing a solid understanding of exploits and vulnerabilities, resolving issues by following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across multiple Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
1. Assist in Developing and maintaining a roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
2. Assist in designing,implementing, and maintaining access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
3. Support Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
4. Assist with the deploymen, management and enhancement of SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
5. Assist with the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
6. Assist with the monitoring, troubleshooting and response to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAMN control issues.
7. Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integraions, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
SUPERVISION
Direct Supervision: None
Indirect Supervision: None
RELATIONSHIPS
Key Internal: Engaging multiple technology groups and business units. Interactive engagement may require communication with individual contributors, and middle management.
Key External: Little to no key external relationships.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university. An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: None.
Licenses/Certifications
Required: None
Preferred: CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Experience
Required: At least one (1) year of experience in IAM or related security engineering experience.
Preferred: Two (2) or more years of experience in IAM or related security engineering experience
Knowledge/Skills/Abilities (KSA)
Required:
• Understanding of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
• Knowledge of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
• Knowledge of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
• Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
• Experience or working knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
• Understanding of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
• Ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
• Knowledge of designing and implementing IAM solutions aligned with business requirements, security standards, and enterprise architecture.
• Understanding of access reviews, segregation of duties, excessive access, privileged access, and least-privilege principles.
• Ability to analyze IAM security issues and support remediation of access-related risks and control deficiencies.
• Working knowledge of security and regulatory requirements including NERC CIP, SOX, NIST, and other applicable security frameworks.
• Ability to collaborate effectively with application owners, business teams, Cyber Security, Infrastructure, Architecture, Compliance, implementation partners, and managed service providers.
Preferred:
• None
IAM Security Technologist
POSITION CONCEPT
The IAM Security Technologist is responsible for operating the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing on IT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
1. Support the development and maintenance of a strategic roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
2. Support the design, implementation and maintenance of access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
3. Support Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
4. Deploy, manage, and enhance SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
5. Support the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
6. Monitor, troubleshoot, and respond to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAMN control issues.
7. Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integraions, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
SUPERVISION
Direct Supervision: None
Indirect Supervision: May provide guidance and mentorship to associate-level technologists, contractors or co-ops assigned to the team.
RELATIONSHIPS
Key Internal: Engaging multiple technology groups and business units, including Finance and HR. Interactive engagement will require communication with individual contributors, middle management.
Key External: Engaging external contacts including vendors, contractors, regulatory agencies, industry associations, and other utility partners.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university. An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: Master’s Degree in Computer Science, Information Systems, or other technology-related field from an accredited college or university.
Licenses/Certifications
Required: Will require at least one certification in one of the following: CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Preferred: None
Experience
Required: 3 years of experience in IAM or related security engineering experience
Preferred: 4 or more year of experience in IAM or related security engineering experience.
Knowledge/Skills/Abilities (KSA)
Required:
• Understanding and demonstration of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
• Knowledge of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
• Knowledge of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
• Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
• Experience or working knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
• Understanding of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
• Demonstrated ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
• Knowledge of designing and implementing IAM solutions aligned with business requirements, security standards, and enterprise architecture.
• Understanding of access reviews, segregation of duties, excessive access, privileged access, and least-privilege principles.
• Ability to analyze IAM security issues and support remediation of access-related risks and control deficiencies.
• Working knowledge of security and regulatory requirements including NERC CIP, SOX, NIST, and other applicable security frameworks.
• Ability to collaborate effectively with application owners, business teams, Cyber Security, Infrastructure, Architecture, Compliance, implementation partners, and managed service providers.
Preferred:
• Knowledge of Saviynt IGA, including application onboarding, access requests, certifications, lifecycle workflows, and integrations.
• Experience with CyberArk PAM administration, privileged account onboarding, and credential management.
• Experience with Microsoft Entra ID and Active Directory, including authentication, SSO, MFA, and access management.
• Experience with REST APIs, PowerShell, connectors, or other IAM automation technologies.
• Experience supporting IAM solutions in a regulated enterprise or utility environment.
• Ability to work hands-on, supporting IAM implementations, operational improvements, and activities beyond standard managed service scope.
IAM Security Technologist Sr.
POSITION CONCEPT:
The IAM Security Technologist Sr is responsible for operating the company’s information security systems, ensuring that all procedures are followed on a daily, weekly, and monthly basis. Provides expert level support, within a team environment, for all systems used to secure the enterprise information technology assets, the scope includes all network infrastructure, operating systems, and web server platforms throughout TECO Energy and its subsidiaries. Direct assistance with the development and enhancing of IAM systems including SSO, authentication, and access controls ensuring confidentiality, integrity, and availability of IAM systems and data. Provides IAM Security support for the TECO environment primarily focusing onIT corporate applications and OT/NERC applications. Responsible for adhering to established policies, following best practices, developing, and possessing an in-depth understanding of exploits and vulnerabilities, resolving issues by taking the appropriate corrective action, or following the appropriate escalation procedures. Supports the enforcement of corporate, regulatory, and risk management policies and assists in developing, maintaining, and publishing corporate IAM security standards, procedures, and guidelines for enterprise computing platforms. Position will be responsible for collaborating with multiple business units across all Emera affiliates.
PRIMARY DUTIES AND RESPONSIBILITIES
1. Oversight of the development and implementation of a strategic roadmap for Identity and Access Management (IAM) including Governance and Administration (IGA), Privileged Access Management (PAM), authentication, SSO, directory services, and access governance. Collaborate closely with teams including Cyber Security, Human Resources, Technology, Architecture and Lines of Business (LoBs) to create efficient and user-friendly IAM solutions.
2. Leading efforts in designing,implementing, and maintaining access governance processes, including Joiner/Mover/Leaver workflows, access requests, RBAC, access certifications/reviews, application onboarding, and least-privilege controls. Support enterprise IGA capabilities, including Saviynt, and integrations with business applications and directories.
3. Leading Privileged Access Management (PAM) capabilities, including privileged account onboarding, credential management, access controls, and privileged access remediation with emphasis on platforms such as CyberArk.
4. Deploy, manage, and enhance SSO and authentication solutions, including integrations with enterprise applications, Microsoft Entra ID/Active Directory, and other identity platforms to provide secure and seamless authentication.
5. Lead and support the implementation and management of authentication and access control mechanisms, including multi-factor authentication, conditional access, and identity security controls.
6. Monitor, troubleshoot, and respond to identity and access-related incidents and technical issues. Support remediation of unauthorized access, excessive privileges, identity lifecycle failures, and other IAMN control issues.
7. Effectively collaborate with both technical and non-technical business owners, application teams, implementation partners, and managed service providers. Identify opportunities to improve IAM automation, integraions, processes and toolsets, and provide hands-on technical support for activities outside standard managed service scope.
8. Serve as the Subject Matter Expert (SME) for audit, compliance, and regulatory efforts related to IAM, SOX and PII through investigating, documenting, and reporting findings to management
SUPERVISION
Direct Supervision: None
Indirect Supervision: May provide guidance and mentorship to associate-level technologists and security technologists, contractors or co-ops assigned to the team.
RELATIONSHIPS
Key Internal: Engaging multiple I.T. groups and business units, including Finance and HR. Interactive engagement will require communication with individual contributors, middle management.
Key External: Engaging external contacts including vendors, contractors, regulatory agencies, industry associations, and other utility partners.
QUALIFICATIONS
Education
Required: Bachelor’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university.An associate’s degree with an additional 2 years of required experience may be considered in lieu of a bachelor’s degree. A high school diploma and an additional 4 years of required experience may be considered in lieu of a bachelor’s degree.
Preferred: Master’s Degree in Computer Science, Information Systems or other technology-related field from an accredited college or university.
Licenses/Certifications
Required: One or more of the following:CISSP, CISM, CIAM, ITIL, Sabiynt, CyberArk, Microsoft Identity/Entra, or other relevant IAM/security certifications
Preferred: Two or more of the above required certifications.
Experience
Required: 5 years of experience in IAM or related security engineering experience
Preferred: 6 or more year of experience in IAM or related security engineering experience.
Knowledge/Skills/Abilities (KSA)
• Advanced knowledge and deploymebt of Identity and Access Management concepts, including RBAC, least privilege, entitlement management, and access controls.
• Advanced of identity lifecycle management, including Joiner/Mover/Leaver processes, onboarding, offboarding, access changes, and automated provisioning/deprovisioning.
• Advanced of Identity Governance and Administration capabilities, including access requests, certifications/access reviews, role management, application onboarding, and governance processes.
• Understanding of Privileged Access Management concepts, including privileged account onboarding, credential management, access controls, and privileged access governance.
• Advanced knowledge of enterprise IAM technologies such as Saviynt, CyberArk, Microsoft Entra ID, Active Directory, SSO, and MFA.
• In-depth knowledge of connectors, REST APIs, scripts, and automation used to integrate IAM platforms with applications, directories, HR systems, and other enterprise technologies.
• Demonstrated ability to troubleshoot identity, authentication, provisioning, access, and integration-related issues.
• Demonstrated knowledge, design, and implementation of IAM solutions aligned with business requirements, security standards, and enterprise architecture.
• Execution of access reviews, segregation of duties, excessive access, privileged access, and least-privilege principles.
• Strong analysis of IAM security issues and support remediation of access-related risks and control deficiencies.
• Solid working knowledge of security and regulatory requirements including NERC CIP, SOX, NIST, and other applicable security frameworks.
• Effective collaboration and communication with application owners, business teams, Cyber Security, Infrastructure, Architecture, Compliance, implementation partners, and managed service providers.
Preferred:
• Hands-on experience with Saviynt IGA, including application onboarding, access requests, certifications, lifecycle workflows, and integrations.
• Experience with CyberArk PAM administration, privileged account onboarding, and credential management.
• Experience with Microsoft Entra ID and Active Directory, including authentication, SSO, MFA, and access management.
• Experience with REST APIs, PowerShell, connectors, or other IAM automation technologies.
• Experience supporting IAM solutions in a regulated enterprise or utility environment.
• Ability to work both strategically and hands-on, supporting IAM implementations, operational improvements, and activities beyond standard managed service scope.
WORKING CONDITIONS
Normal working condition with occasional weekend and overtime requirements, including on-call rotational support
PHYSICAL DEMANDS/ REQUIREMENTS
Normal physical demands related to an office workplace environment
TECO offers a competitive Benefits package!!
Competitive Salary *401k Savings plan w/ company matching * Pension plan * Paid time off* Paid Holiday time * Medical, Prescription Drug, & Dental Coverage *Tuition Assistance Program * Employee Assistance Program * Wellness Programs * On-site Fitness Centers * Bonus Plan and more!
#LI-SC1
#LI-SC1
Nearest Major Market: Tampa
Job Segment:
Information Technology, IT Architecture, Computer Science, ERP, Technical Support, Technology