Title: Compliance & Risk Analyst, SOX Focus, Progression (Level II)
Company: Tampa Electric Company
Location: Midtown East Tower
State and City: Florida - Tampa
Shift: 8 Hr. X 5 Days
Hiring Manager: Denise Toole
Recruiter: Mark Koener
TITLE: Compliance & Risk Analyst, SOX Focus, Progression
PERFORMANCE COACH: Lead Compliance & Risk Assurance / Manager
COMPANY: Tampa Electric Company
DEPARTMENT: Technology
Please note that this position can be hired at any level within the job family of progression, based on education and experience, but seeking ideally to hire this role at level II.
FOCUS AREAS
-
- Intermediate level knowledge of Sarbanes-Oxley regulatory requirements.
- Working knowledge of SAP system landscape, configuration or controls.
POSITION CONCEPT
The Compliance & Risk Analyst/Advisor progression carries out procedures to ensure all information systems products and services meet Technology organization standards and compliance obligations, including regulatory requirements, contractual requirements, and Emera requirements. Analysts are primarily responsible for the maintenance, training, assurance, monitoring and reporting of all IT standards and procedures, as well as Technology-related regulatory requirements for the Technology Department and individual business units as applicable.
Advancement to a higher level is based on value added to the Company through increased duties, responsibilities, and accomplishments. Advancement is not automatic, i.e. based solely on time in the job, but will be based on the employee’s performance, qualifications, and the technical needs of the department.
PRIMARY DUTIES AND RESPONSIBILITIES
1. Assurance and Information Management: Ensures that quality methods and procedures are executed by the IT department to stay in compliance with regulatory requirements, e.g., NERC Critical Infrastructure Protection (CIP), Sarbanes-Oxley (SOX), contractual requirements (e.g., Payment Card Industry (PCI) Data Security Standards (DSS), Defense Federal Acquisition Regulation System (DFARS) requirements, internal requirements, e.g., Emera, voluntary requirements, e.g. America Gas Association commitment to Department of Homeland Security (DHS) Transportation Safety Administration (TSA) Pipeline Security Guidelines, and customer requirements. Manages compliance related information and documentation consistent with retention requirements. Support collection, review and approval of compliance-related data. Facilitates and tracks deliverables for root cause analysis, compliance reporting, technical feasibility exceptions, and NERC Alerts. [25%]
2. Controls & Monitoring: Administers the IT Compliance Management Systems and Governance, Risk, and Compliance (GRC) tool(s). Collect and sample evidence to support demonstration of compliance. Escalates out of compliance items to senior management. Participate in the implementation of technology-based tools (e.g., GRC) to support IT risk initiatives. Additionally, analyst adheres to company confidentiality and security requirements. [20%]
3. Reporting: Documents all quality problems and compliance issues, and assists in their resolution. Performs quality audits across various IT&T functions to ensure quality standards, procedures, and methodologies are followed. Monitors and reports on exceptions, risks and exposures to Technology senior management. [20%]
4. Policies, standards, and processes: Analyzes best-in-class processes including IT Information Library (ITIL), National Institute of Standards and Technology (NIST) standards, and COBIT, and keeps current on all regulatory and compliance issues relating to Information Technology. Maintains all Technology standards, procedures and policies. Maintains internal desk-level procedures. [15%]
5. Training and Communications: Develops and delivers quality process training to technical staff and acts as an internal quality consultant to facilitate business or technical partners on the use of the Technology Standards and Procedures. [10%]
6. Performance Management: Establishes, and administers, activities of performance analysis (e.g., metrics) within assigned areas of responsibility. [10%]
SUPERVISION
Direct: No direct reports.
RELATIONSHIPS
Internal: Directly accountable to the IT Quality Assurance and Compliance Director. Indirectly accountable to the Lead Compliance Analyst for day-to-day and project activities. Interacts with all levels of TSI IT&T; selected individuals in Tampa Electric Energy Delivery, Energy Supply, Corporate Security, Facility Services, Human Resources, Emergency Management, Customer Experience, Regulatory Affairs, Audit Services, Corporate Accounting; PGS Compliance, Gas Operations; NMGC Compliance, Customer Service, Gas Operations; and Emera Compliance and Cyber Security.
External: Responsible for building and maintaining external relationships with vendors, contractors, and external auditors.
Compliance & Risk Analyst II
POSITION CONCEPT
The Compliance and Risk Analyst II, under general supervision, carries out procedures to ensure all information systems and services meet IT organization standards and compliance obligations, including regulatory requirements, contractual requirements, and Emera requirements. Primarily responsible for audit readiness, compliance issue investigation and reporting, compliance information management, and controls/monitoring for multiple stakeholder sets. Advises on IT projects to ensure an audit-ready compliance posture. Acts as subject matter expert for certain compliance obligations.
PRIMARY DUTIES AND RESPONSIBILITIES
In addition to those of Compliance & Risk Analyst I)
1. Responsible for one or more IT compliance programs (e.g., NERC CIP, PCI DSS, SOX, DFARS, Emera Cyber Security, DHS TSA Pipeline Security). This includes facilitation of and tracking of deliverables for root cause analysis, violation reporting, technical feasibility exceptions, mitigation plan development, evidence reviews, external audit preparations, and NERC Alerts responses. Support the development of flow diagrams or other illustrations showing key steps associated with a given process or sub-process affected by applicable regulations and/or contract terms. Coordinates and facilitates technical feasibility-exception audits, mitigation plan completion audits, and other audit spot checks with external auditors. [30%]
2. Policies & Procedures: Liaise with IT&T areas such as IT Security, IT Project Management Office, IT Infrastructure, Telecom, Access Administration, and affected corporate areas and business units to facilitate the evaluation, design and implementation of effective methodologies, procedures and controls to comply with new and existing regulatory requirements. [25%]
3. Responsible for one or more other areas within department, as assigned. [25%]:
a. Provides updates to Business Strategy related to cybersecurity and impact of new legislation/regulatory requirements on Tampa Electric business operations.
b. Risk Management: Work with technology teams and business stakeholders in the design, implementation, and optimization of IT risk assessment practices.
c. Policies & Procedures:
i. Act as ruleset liaison for assigned areas of compliance.
ii. Act as ruleset Subject Matter Expert (SME) for
1. Information Protection Program and assigned CIP compliance related to BES Cyber System Information.
2. NERC CIP Awareness Program.
3. NERC CIP Training Program.
4. NERC CIP Security Management Controls.
d. Training & Communication:
i. Ensure mandatory training is conducted, tracked, and recorded.
ii. Develop and facilitate compliance training for subject matter experts.
iii. Develops and/or provides input into IT Security awareness program.
e. Performance Management: Develops and coordinates the assessment of cybersecurity awareness via phishing campaigns utilizing tools.
4. Controls & Monitoring: Provide independent assessment and assurance of the effectiveness and efficiency of the IT control environment. Administers and monitors the execution of Tampa Electric compliance program by sampling compliance deliverables for acceptable content and assessing risk. Utilize security tools to further sample content. Participate in the implementation of technology-based tools (e.g., GRC) to support IT compliance and risk initiatives. [20%]
a.
SUPERVISION
Direct: No direct reports.
Indirect: N/A.
RELATIONSHIPS
Internal: Directly accountable to the IT Quality Assurance and Compliance Director. Indirectly accountable to the Lead Compliance Analyst for day-to-day and project activities. Interacts with all levels of TSI IT&T; selected individuals in Tampa Electric Energy Delivery, Energy Supply, Corporate Security, Facility Services, Audit Services, Human Resources, Emergency Management, Customer Experience, Regulatory Affairs, Corporate Accounting; PGS Compliance, Gas Operations; NMGC Compliance, Customer Service, Gas Operations; and Emera Compliance and Cyber Security.
External: Build and maintain external relationships with vendors, contractors, industry contacts, and external auditors.
QUALIFICATIONS
Education
Required: Bachelor’s degree in Computer Science, Information Systems or related field. Experience may be considered in lieu of formal education.
Licensing/Certification
Required: Expected to obtain Information Technology Infrastructure Library (ITIL) Certification within 6 months of employment in this position.
Preferred: Current ITIL Certification. Audit (Certified Information Systems Auditor [CISA] or security-related (Certified Information Systems Security Professional [CISSP], Certified in Risk and Information Systems Control [CRISC], Certified Information Security Manager [CISM]) certification.
Related Experience
Required: 5 years of experience in information technology, audit or utility business environment is required, with at least two years in IT security, audit or other controls-based role.
Preferred: IT security, IT audit or other controls experience.
Knowledge/Skills/Abilities
Required: Maintains a working level knowledge of applicable regulatory requirements. Ability to organize, document and facilitate meetings. Good project management skills. Must be able to complete highly complex duties involving a wide variety of situations requiring considerable analytical skills, judgment and interpersonal relationships. Ability to lead groups to consensus in a timely manner. High tolerance for stress.
Preferred: Proficient in security tools (SIEM, EDR, TPAM) with a strong understanding of network protocols and security principles. Knowledge of SharePoint document management and workflow.
WORKING CONDITIONS
Normal working conditions with occasional extended hours during the week and weekends.
PHYSICAL DEMANDS/REQUIREMENTS
Normal physical demands related to an office workplace environment.
TECO offers a competitive Benefits package!!
Competitive Salary *401k Savings plan w/ company matching * Pension plan * Paid time off* Paid Holiday time * Medical, Prescription Drug, & Dental Coverage *Tuition Assistance Program * Employee Assistance Program * Wellness Programs * On-site Fitness Centers * Bonus Plan and more!
#LI-SC1
Nearest Major Market: Tampa
Job Segment:
Pipeline, Project Manager, Computer Science, Telecom, Telecommunications, Energy, Technology