Compliance & Risk Analyst, SOX Focus, Progression (Level II)

New Mexico Gas Co - Peoples Gas - Tampa Electric

Tampa (FL)

On-site

USD 85,000 - 115,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Salary
401k Savings plan w/ company matching
Pension plan
Paid time off
Medical, Prescription Drug, & Dental
Tuition Assistance Program

Job summary

Tampa Electric Company is seeking a Compliance & Risk Analyst II in its Technology department in Tampa, FL. This role advances SOX, IT governance and regulatory compliance across IT systems, with emphasis on risk assessment, audit readiness and controls monitoring.

Ideal candidates bring 5+ years in IT/audit, ITIL familiarity and strong analytical skills. The position offers a clear progression path within the progression framework and opportunities to lead cross‑functional teams on complex

Qualifications

  • Bachelor’s degree in Computer Science, Information Systems or related field.
  • 5 years IT/audit experience with at least 2 years in IT security/audit or controls.
  • Knowledge of ITIL, NIST, COBIT and regulatory requirements.
  • Ability to lead groups, strong analytical and communication skills.

Responsibilities

  • Ensure IT compliance with SOX, NERC CIP, PCI DSS and related requirements.
  • Administer GRC tools and collect evidence to support compliance.
  • Document quality problems and assist in resolution; perform audits and reporting.
  • Develop and deliver compliance training for staff.
  • Support risk assessments and audit readiness for IT initiatives.

Skills

SOX compliance
IT governance
GRC tools
SAP knowledge
Security monitoring

Education

Bachelor's degree in Computer Science, Information Systems or related field

Tools

GRC tools
SAP
SIEM
EDR
TPAM
SharePoint

Job description

Select how often (in days) to receive an alert:

At Tampa Electric, dependable electricity starts with dedicated individuals whose talent, skill and passion drive our success. We’ve been lighting the way for West Central Florida for more than 125 years—and we’re just getting started.

Join us and build a rewarding career with competitive pay, comprehensive benefits and a culture that supports your growth. Your potential finds its purpose at Tampa Electric.

We proudly deliver 99.98% electric service reliability to nearly 860,000 customers across 2,000 square miles of Hillsborough County and parts of Polk, Pasco and Pinellas counties. Through innovation and strategic investments, we’re creating a cleaner, brighter energy future—whiledelivering exceptional service every step of the way.

We reflect the communities we serve and foster a workplace where every employee feels welcomed, valuedand engaged. Join our team of energy experts and help shape the future of power.

Storm Duty Requirements

Tampa Electric and its sister companies serve a role in providing critical services to our community during an emergency. Team members are required to participate in the response/recovery activities related to emergencies/disasters to maintain service to our Tampa Electric customers. Team members are required to work in their normal job duties or other assigned activities. Proper compensation will be made in accordance with the company's rules and procedures.

Responding to stormswill beconsidered a condition of employment.

Tampa Electric is proud to be an Equal Opportunity Employer.

Title: Compliance & Risk Analyst, SOX Focus, Progression (Level II)
Company: Tampa Electric Company
Location: Midtown East Tower
State and City: Florida - Tampa
Shift: 8 Hr. X 5 Days

TITLE: Compliance & Risk Analyst, SOX Focus, Progression
PERFORMANCE COACH: Lead Compliance & Risk Assurance / Manager
COMPANY: Tampa Electric Company
DEPARTMENT: Technology

Please note that this position can be hired at any level within the job family of progression, based on education and experience, but seeking ideally to hire this role at level II.

FOCUS AREAS
  • Intermediate level knowledge of Sarbanes-Oxley regulatory requirements.
  • Working knowledge of SAP system landscape, configuration or controls.

POSITION CONCEPT
The Compliance & Risk Analyst/Advisor progression carries out procedures to ensure all information systems products and services meet Technology organization standards and compliance obligations, including regulatory requirements, contractual requirements, and Emera requirements. Analysts are primarily responsible for the maintenance, training, assurance, monitoring and reporting of all IT standards and procedures, as well as Technology-related regulatory requirements for the Technology Department and individual business units as applicable.

Advancement to a higher level is based on value added to the Company through increased duties, responsibilities, and accomplishments. Advancement is not automatic, i.e. based solely on time in the job, but will be based on the employee’s performance, qualifications, and the technical needs of the department.

PRIMARY DUTIES AND RESPONSIBILITIES
  • Assurance and Information Management: Ensures that quality methods and procedures are executed by the IT department to stay in compliance with regulatory requirements, e.g., NERC Critical Infrastructure Protection (CIP), Sarbanes-Oxley (SOX), contractual requirements (e.g., Payment Card Industry (PCI) Data Security Standards (DSS), Defense Federal Acquisition Regulation System (DFARS) requirements, internal requirements (e.g., Emera, voluntary requirements, e.g. America Gas Association commitment to Department of Homeland Security (DHS) Transportation Safety Administration (TSA) Pipeline Security Guidelines, and customer requirements. Manages compliance related information and documentation consistent with retention requirements. Support collection, review and approval of compliance-related data. Facilitates and tracks deliverables for root cause analysis, compliance reporting, technical feasibility exceptions, and NERC Alerts. [25%]
  • Controls & Monitoring: Administers the IT Compliance Management Systems and Governance, Risk, and Compliance (GRC) tool(s). Collect and sample evidence to support demonstration of compliance. Escalates out of compliance items to senior management. Participate in the implementation of technology-based tools (e.g., GRC) to support IT risk initiatives. Additionally, analyst adheres to company confidentiality and security requirements. [20%]
  • Reporting: Documents all quality problems and compliance issues, and assists in their resolution. Performs quality audits across various IT&T functions to ensure quality standards, procedures, and methodologies are followed. Monitors and reports on exceptions, risks and exposures to Technology senior management. [20%]
  • Policies, standards, and processes: Analyzes best-in-class processes including IT Information Library (ITIL), National Institute of Standards and Technology (NIST) standards, and COBIT, and keeps current on all regulatory and compliance issues relating to Information Technology. Maintains all Technology standards, procedures and policies. Maintains internal desk-level procedures. [15%]
  • Training and Communications: Develops and delivers quality process training to technical staff and acts as an internal quality consultant to facilitate business or technical partners on the use of the Technology Standards and Procedures. [10%]
  • Performance Management: Establishes, and administers, activities of performance analysis (e.g., metrics) within assigned areas of responsibility. [10%]
RELATIONSHIPS

Internal: Directly accountable to the IT Quality Assurance and Compliance Director. Indirectly accountable to the Lead Compliance Analyst for day-to-day and project activities. Interacts with all levels of TSI IT&T; selected individuals in Tampa Electric Energy Delivery, Energy Supply, Corporate Security, Facility Services, Human Resources, Emergency Management, Customer Experience, Regulatory Affairs, Audit Services, Corporate Accounting, PGS Compliance, Gas Operations, NMGC Compliance, Customer Service, Gas Operations; and Emera Compliance and Cyber Security.

External: Responsible for building and maintaining external relationships with vendors, contractors, and external auditors.

Compliance & Risk Analyst II

POSITION CONCEPT

The Compliance and Risk Analyst II, under general supervision, carries out procedures to ensure all information systems and services meet IT organization standards and compliance obligations, including regulatory requirements, contractual requirements, and Emera requirements. Primarily responsible for audit readiness, compliance issue investigation and reporting, compliance information management, and controls/monitoring for multiple stakeholder sets. Advises on IT projects to ensure an audit-ready compliance posture. Acts as subject matter expert for certain compliance obligations.

PRIMARY DUTIES AND RESPONSIBILITIES

In addition to those of Compliance & Risk Analyst I)

  • Responsible for one or more IT compliance programs (e.g., NERC CIP, PCI DSS, SOX, DFARS, Emera Cyber Security, DHS TSA Pipeline Security). This includes facilitation of and tracking of deliverables for root cause analysis, violation reporting, technical feasibility exceptions, mitigation plan development, evidence reviews, external audit preparations, and NERC Alerts responses. Support the development of flow diagrams or other illustrations showing key steps associated with a given process or sub-process affected by applicable regulations and/or contract terms. Coordinates and facilitates technical feasibility-exception audits, mitigation plan completion audits, and other audit spot checks with external auditors. [30%]
  • Policies & Procedures: Liaise with IT&T areas such as IT Security, IT Project Management Office, IT Infrastructure, Telecom, Access Administration, and affected corporate areas and business units to facilitate the evaluation, design and implementation of effective methodologies, procedures and controls to comply with new and existing regulatory requirements. [25%]
  • Responsible for one or more other areas within department, as assigned. [25%]
  • Provides updates to Business Strategy related to cybersecurity and impact of new legislation/regulatory requirements on Tampa Electric business operations.
  • Risk Management: Work with technology teams and business stakeholders in the design, implementation, and optimization of IT risk assessment practices.
  • Policies & Procedures:
    • Act as ruleset liaison for assigned areas of compliance.
    • Act as ruleset Subject Matter Expert (SME) for
      • Information Protection Program and assigned CIP compliance related to BES Cyber System Information.
      • NERC CIP Awareness Program.
      • NERC CIP Training Program.
      • NERC CIP Security Management Controls.
  • Training & Communication:
    • Ensure mandatory training is conducted, tracked, and recorded.
    • Develop and facilitate compliance training for subject matter experts.
    • Develops and/or provides input into IT Security awareness program.
  • Performance Management: Develops and coordinates the assessment of cybersecurity awareness via phishing campaigns utilizing tools.
  • Controls & Monitoring: Provide independent assessment and assurance of the effectiveness and efficiency of the IT control environment. Administers and monitors the execution of Tampa Electric compliance program by sampling compliance deliverables for acceptable content and assessing risk. Utilize security tools to further sample content. Participate in the implementation of technology-based tools (e.g., GRC) to support IT compliance and risk initiatives. [20%]
INDIRECT

N/A.

RELATIONSHIPS

Internal: Directly accountable to the IT Quality Assurance and Compliance Director. Indirectly accountable to the Lead Compliance Analyst for day-to-day and project activities. Interacts with all levels of TSI IT&T; selected individuals in Tampa Electric Energy Delivery, Energy Supply, Corporate Security, Facility Services, Audit Services, Human Resources, Emergency Management, Customer Experience, Regulatory Affairs, Corporate Accounting; PGS Compliance, Gas Operations; NMGC Compliance, Customer Service, Gas Operations; and Emera Compliance and Cyber Security.

External: Build and maintain external relationships with vendors, contractors, industry contacts, and external auditors.

QUALIFICATIONS
  • Education: Required: Bachelor’s degree in Computer Science, Information Systems or related field. Experience may be considered in lieu of formal education.
  • Licensing/Certification: Required: Expected to obtain Information Technology Infrastructure Library (ITIL) Certification within 6 months of employment in this position.
  • Preferred: Current ITIL Certification. Audit (Certified Information Systems Auditor [CISA] or security-related (Certified Information Systems Security Professional [CISSP], Certified in Risk and Information Systems Control [CRISC], Certified Information Security Manager [CISM]) certification.
  • Related Experience: Required: 5 years of experience in information technology, audit or utility business environment is required, with at least two years in IT security, audit or other controls-based role.
  • Preferred: IT security, IT audit or other controls experience.
  • Knowledge/Skills/Abilities:
    • Required: Maintains a working level knowledge of applicable regulatory requirements. Ability to organize, document and facilitate meetings. Good project management skills. Must be able to complete highly complex duties involving a wide variety of situations requiring considerable analytical skills, judgment and interpersonal relationships. Ability to lead groups to consensus in a timely manner. High tolerance for stress.
    • Preferred: Proficient in security tools (SIEM, EDR, TPAM) with a strong understanding of network protocols and security principles. Knowledge of SharePoint document management and workflow.

WORKING CONDITIONS: Normal working conditions with occasional extended hours during the week and weekends.

PHYSICAL DEMANDS/REQUIREMENTS: Normal physical demands related to an office workplace environment.

Benefits
  • Competitive Salary
  • 401k Savings plan w/ company matching
  • Pension plan
  • Paid time off
  • Paid Holiday time
  • Medical, Prescription Drug, & Dental Coverage
  • Tuition Assistance Program
  • Employee Assistance Program
  • Wellness Programs
  • On-site Fitness Centers
  • Bonus Plan and more!
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Compliance & Risk Analyst, SOX Focus, Progression (Level II)
Compliance & Risk Analyst, SOX Focus, Progression (Level II)

TECO Energy, Inc. • Tampa (FL)

On-site
USD 90,000 - 120,000
Competitive Salary
401k Savings plan
Pension plan
+4
Compliance & Risk Analyst, SOX Focus, Progression (Level II)
Compliance & Risk Analyst, SOX Focus, Progression (Level II)

Tampa Electric Company • Tampa (FL)

On-site
USD 90,000 - 130,000
Competitive Salary
401k Savings plan w/ company matching
Pension plan
+7
Compliance & Risk Analyst, SOX Focus, Progression (Level II)
Compliance & Risk Analyst, SOX Focus, Progression (Level II)

Tampa Electric • Tampa (FL)

On-site
USD 80,000 - 120,000
Sr Manager, Rates and Cost of Service
Sr Manager, Rates and Cost of Service

Tampa Electric Co. • Tampa (FL), Northern (KY)

Hybrid
USD 120,000 - 170,000
Competitive Salary
401k Savings plan w/ company matching
Pension plan
+8
Sr Manager, Rates and Cost of Service
Sr Manager, Rates and Cost of Service

New Mexico Gas Co - Peoples Gas - Tampa Electric • Tampa (FL)

On-site
USD 110,000 - 160,000
Competitive Salary
401k Savings plan w/ company matching
Pension plan
+8
Sr Checkpoint Firewall Engineer, Progression
Sr Checkpoint Firewall Engineer, Progression

TECO Energy Inc. • Town of Florida (NY)

On-site
USD 90,000 - 130,000
401k with company matching
Pension plan
Paid time off
+3
Regulatory Rate Analyst, Progression
Regulatory Rate Analyst, Progression

TECO Energy, Inc. • Tampa (FL), Northern (KY)

Hybrid
USD 75,000 - 110,000
Competitive Salary
401k Savings plan w/ company matching
Pension plan
+8
IT Infrastructure Operations Analyst, Progression
IT Infrastructure Operations Analyst, Progression

New Mexico Gas Co - Peoples Gas - Tampa Electric • Lutz (FL)

On-site
USD 85,000 - 130,000
Competitive Salary
401k Savings plan w/ company matching
Pension plan
+4
Regulatory Rate Analyst, Progression
Regulatory Rate Analyst, Progression

New Mexico Gas Co - Peoples Gas - Tampa Electric • Tampa (FL)

On-site
USD 70,000 - 110,000
Competitive salary
401k matching
Pension plan
+1
Systems Analyst, AWS Focus, Progression
Systems Analyst, AWS Focus, Progression

TECO Energy Inc. • Tampa (FL)

On-site
USD 70,000 - 90,000
Competitive Salary
401(k) Savings plan with company matching
Pension plan
+7