Compliance & Risk Analyst, SOX Focus, Progression (Level II)
Tampa Electric Company | |
paid time off, tuition assistance, 401(k)
| |
United States, Florida, Tampa | |
Aug 03, 2026 | |
|
Title: Compliance & Risk Analyst, SOX Focus, Progression (Level II) Hiring Manager: Denise Toole Recruiter: Mark Koener TITLE: Compliance & Risk Analyst, SOX Focus, Progression Please note that this position can be hired at any level within the job family of progression, based on education and experience, but seeking ideally to hire this role at level II. FOCUS AREAS
POSITION CONCEPT Advancement to a higher level is based on value added to the Company through increased duties, responsibilities, and accomplishments. Advancement is not automatic, i.e. based solely on time in the job, but will be based on the employee's performance, qualifications, and the technical needs of the department. PRIMARY DUTIES AND RESPONSIBILITIES 2. Controls & Monitoring: Administers the IT Compliance Management Systems and Governance, Risk, and Compliance (GRC) tool(s). Collect and sample evidence to support demonstration of compliance. Escalates out of compliance items to senior management. Participate in the implementation of technology-based tools (e.g., GRC) to support IT risk initiatives. Additionally, analyst adheres to company confidentiality and security requirements. [20%] 3. Reporting: Documents all quality problems and compliance issues, and assists in their resolution. Performs quality audits across various IT&T functions to ensure quality standards, procedures, and methodologies are followed. Monitors and reports on exceptions, risks and exposures to Technology senior management. [20%] 4. Policies, standards, and processes: Analyzes best-in-class processes including IT Information Library (ITIL), National Institute of Standards and Technology (NIST) standards, and COBIT, and keeps current on all regulatory and compliance issues relating to Information Technology. Maintains all Technology standards, procedures and policies. Maintains internal desk-level procedures. [15%] 5. Training and Communications: Develops and delivers quality process training to technical staff and acts as an internal quality consultant to facilitate business or technical partners on the use of the Technology Standards and Procedures. [10%] 6. Performance Management: Establishes, and administers, activities of performance analysis (e.g., metrics) within assigned areas of responsibility. [10%] SUPERVISION RELATIONSHIPS Internal: Directly accountable to the IT Quality Assurance and Compliance Director. Indirectly accountable to the Lead Compliance Analyst for day-to-day and project activities. Interacts with all levels of TSI IT&T; selected individuals in Tampa Electric Energy Delivery, Energy Supply, Corporate Security, Facility Services, Human Resources, Emergency Management, Customer Experience, Regulatory Affairs, Audit Services, Corporate Accounting; PGS Compliance, Gas Operations; NMGC Compliance, Customer Service, Gas Operations; and Emera Compliance and Cyber Security. External: Responsible for building and maintaining external relationships with vendors, contractors, and external auditors. Compliance & Risk Analyst II POSITION CONCEPT PRIMARY DUTIES AND RESPONSIBILITIES In addition to those of Compliance & Risk Analyst I) 1. Responsible for one or more IT compliance programs (e.g., NERC CIP, PCI DSS, SOX, DFARS, Emera Cyber Security, DHS TSA Pipeline Security). This includes facilitation of and tracking of deliverables for root cause analysis, violation reporting, technical feasibility exceptions, mitigation plan development, evidence reviews, external audit preparations, and NERC Alerts responses. Support the development of flow diagrams or other illustrations showing key steps associated with a given process or sub-process affected by applicable regulations and/or contract terms. Coordinates and facilitates technical feasibility-exception audits, mitigation plan completion audits, and other audit spot checks with external auditors. [30%] SUPERVISION Indirect: N/A. RELATIONSHIPS QUALIFICATIONS Education Required: Bachelor's degree in Computer Science, Information Systems or related field. Experience may be considered in lieu of formal education. Licensing/Certification Required: Expected to obtain Information Technology Infrastructure Library (ITIL) Certification within 6 months of employment in this position. Preferred: Current ITIL Certification. Audit (Certified Information Systems Auditor [CISA] or security-related (Certified Information Systems Security Professional [CISSP], Certified in Risk and Information Systems Control [CRISC], Certified Information Security Manager [CISM]) certification. Related Experience Required: 5 years of experience in information technology, audit or utility business environment is required, with at least two years in IT security, audit or other controls-based role. Preferred: IT security, IT audit or other controls experience. Knowledge/Skills/Abilities Required: Maintains a working level knowledge of applicable regulatory requirements. Ability to organize, document and facilitate meetings. Good project management skills. Must be able to complete highly complex duties involving a wide variety of situations requiring considerable analytical skills, judgment and interpersonal relationships. Ability to lead groups to consensus in a timely manner. High tolerance for stress. Preferred: Proficient in security tools (SIEM, EDR, TPAM) with a strong understanding of network protocols and security principles. Knowledge of SharePoint document management and workflow. WORKING CONDITIONS PHYSICAL DEMANDS/REQUIREMENTS TECO offers a competitive Benefits package!! Competitive Salary *401k Savings plan w/ company matching * Pension plan * Paid time off* Paid Holiday time * Medical, Prescription Drug, & Dental Coverage *Tuition Assistance Program * Employee Assistance Program * Wellness Programs * On-site Fitness Centers * Bonus Plan and more! #LI-SC1 | |
paid time off, tuition assistance, 401(k)
Aug 03, 2026