Enterprise Cyber Security Solution Architect

TECO Energy

Tampa (FL)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive Salary
401k Savings plan with company matching
Pension plan
Paid time off
Medical, Prescription Drug, & Dental Coverage
Tuition Assistance Program
Employee Assistance Program
Wellness Programs
On-site Fitness Centers
Bonus Plan

Job summary

TECO Energy is looking for an Enterprise Cyber Security Solution Architect to design and govern cybersecurity solutions that protect critical assets. This role requires designing future state architectures and partnering with engineering teams while ensuring compliance with security standards.

The ideal candidate should have at least 8 years of relevant experience, particularly in IAM, PAM, DLP, and application security. The position is based in Tampa, Florida, and offers a competitive salary and multiple benefits.

Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, Engineering, or equivalent experience.
  • 8+ years of cybersecurity or IT experience with strong enterprise architecture exposure.
  • Demonstrated expertise in IAM/IGA, PAM, DLP, Application Security, and PKI.
  • Strong communication, documentation, and strategic planning skills.

Responsibilities

  • Responsible for enterprise architecture and maturity of Identity Management and Governance capabilities.
  • Define and lead the PAM maturity roadmap.
  • Serve as the solution architect for enterprise DLP capabilities.
  • Define secure application reference architectures and design patterns.
  • Provide architectural leadership for enterprise PKI and certificate management.

Skills

Cybersecurity expertise
Identity and Access Management (IAM)
Privileged Access Management (PAM)
Data Loss Prevention
Application Security
Secure Software Development Lifecycle (SDLC)
Cloud Security
Risk Assessment

Education

Bachelor’s Degree in Cybersecurity, Computer Science, Information Systems, Engineering

Tools

Microsoft Entra ID
CyberArk
Microsoft Purview
Saviynt

Job description

Title

Tampa Electric Company

Bearss Operations Center, Florida - Ybor City

Position Concept

The Enterprise Cyber Security Solution Architect is responsible for designing, maturing, and governing enterprise wide cybersecurity solutions that protect Tampa Electric’s critical information assets and infrastructure. This role serves as a solution architect and technical authority, defining future state architectures, security standards, and multi‑year roadmaps, while partnering with engineering teams, system integrators, and Managed Security Services (MSS) for execution and operations. This position provides architectural leadership across Identity and Access Management (IAM) and Identity Governance (IGA), Privileged Access Management (PAM), Data Loss Prevention (DLP), Application Security, Public Key Infrastructure (PKI), and other cross‑tower cybersecurity capabilities. The role focuses on architecture, integration, and governance and does not perform hands‑on implementation or day‑to‑day administration.

Storm Duty Requirements

Tampa Electric and its sister companies serve a role in providing critical services to our community during an emergency. Team members are required to participate in the response/recovery activities related to emergencies/disasters to maintain service to our Tampa Electric customers. Team members are required to work in their normal job duties or other assigned activities. Proper compensation will be made in accordance with the company's rules and procedures. Responding to storms will be considered a condition of employment.

Responsibilities
  • Identity Management & Identity Governance (IAM/IGA – Microsoft Entra ID & Saviynt) – 35%: Responsible for the enterprise architecture, strategy, and maturity of Identity Management and Identity Governance & Administration capabilities. Define and maintain IAM and IGA reference architectures, standards, and roadmaps aligned with Zero Trust and least privilege principles. Provide solution architecture leadership for Microsoft Entra ID, including passwordless authentication, Conditional Access, advanced SSO, and identity federation patterns. Architect and mature Saviynt IGA capabilities, including RBAC models, enterprise role catalogs, entitlement management, and access certifications. Design identity controls to mitigate BYOD exposure, leveraging Conditional Access, session controls, and device trust strategies. Lead enterprise integrations with CyberArk PAM, ServiceNow, SAP, and other business applications. Govern non‑human and workload identities in coordination with PAM and IGA platforms.
  • Privileged Access Management (PAM – CyberArk) – 25%: Serve as the enterprise PAM solution architect and design authority. Define and lead the PAM maturity roadmap, supporting pilot deployments, enterprise rollout, and transition to MSS (Managed Service Partner) operations. Architect advanced CyberArk capabilities including privileged session recording, Secure Credential Access (SCA), Secure Web Access (SWA), Just In Time (JIT) provisioning, access decoupling, and excessive privilege reduction. Establish PAM reference architectures and standards across on premises, cloud, hybrid, and OT environments. Provide architectural oversight and governance to system integrators to ensure scalable, secure, and compliant solutions.
  • Data Loss Prevention (DLP – Microsoft Purview and Other Tools) – 15%: Serve as the solution architect for enterprise DLP capabilities, including Microsoft Purview. Define architectural patterns for data classification, labeling, and protection across email, endpoints, cloud services, and data at rest. Align DLP designs with IAM, Conditional Access, and data governance requirements. Partner with Legal, Compliance, and Risk teams to ensure solutions meet regulatory and privacy requirements.
  • Application Security – Architecture & Secure SDLC Enablement – 15%: Define secure application reference architectures, design patterns, and secure coding standards. Partner with development and DevOps teams to integrate security into the Software Development Lifecycle (SDLC) through design reviews and secure by design principles. Provide architectural guidance for authentication, authorization, and secure data handling aligned with IAM, PAM, and DLP strategies. Support application security risk assessments and security architecture reviews for business critical and high risk systems.
  • PKI & Certificate Management – 5%: Provide architectural leadership and governance for enterprise PKI and certificate lifecycle management. Define standards for certificate issuance, renewal, revocation, and automation. Support certificate based authentication strategies, including passwordless initiatives.
  • Cyber Defense & Security Governance (Cross Tower) – 5%: Contribute to architecture and governance of cyber defense and detection capabilities, including threat detection and response alignment. Participate in development of enterprise security standards, policies, and control frameworks. Serve as a trusted advisor in security architecture reviews and enterprise risk discussions.
Qualifications
  • Bachelor’s Degree in Cybersecurity, Computer Science, Information Systems, Engineering, or equivalent experience
  • 8+ years of cybersecurity or IT experience with strong enterprise architecture exposure
  • Demonstrated expertise across IAM/IGA, PAM, DLP, Application Security, and PKI
  • Strong communication, documentation, and strategic planning skills
Licenses and Certifications

Required: From the list of certification vendors, two related Information Security professional certification or ability to obtain via self‑study within one year of hire date (ex: (ISC)2, GIAC, ISACA, CompTIA, e‑Council, etc.).

Preferred: ITIL v3 and three or more of the following or similar Information Security professional certifications (ex: ACE, CCE, CEH, CISA, CISM, CISSP, CRISC, EnCE, GCCC, GCDA, GCED, GCFA, GCFE, GCIA, GCIH, GCWN, GICSP, GMON, GNFA, GPEN, GPPA, GREM, GWAPT, GXPN, OSCP, SSCP).

Related Experience

Required: 8 years of related Cyber Security or IT experience (Information Systems Audit or Assessor role, Information Security role, systems management, systems administration, information systems security, system certification, risk analysis) with a focus on DLP and/or FIM solutions and security controls.

Core Knowledge and Skills
  • Expert level knowledge in cybersecurity, architecture, methodologies, and best practices for IAM, Data Protection, and Application and Infrastructure Security concepts, strategies, standards, functions, capabilities, and technologies.
  • Solid understanding of threat landscape, vulnerabilities, and risk management.
  • High‑level system/security engineering experience with broad technology knowledge.
  • Knowledge of systems security engineering (SSE) principles and practices.
  • Knowledge of secure software deployment principles and practices.
  • Knowledge of data classification tools and techniques.
  • Knowledge of enterprise architecture reference models, frameworks, principles, and practices.
  • Knowledge of OSI reference model.
  • Knowledge of configuration management tools and techniques.
  • Knowledge of CIAAN principles and practices.
  • Familiarity with NIST SP 800‑53, ISO 27001, and other security frameworks.
  • Knowledge of applicable laws, regulations, and privacy requirements.
  • Understanding of IT systems, network architecture, and common technologies for assessing security controls.
  • Knowledge of access controls, encryption, and incident response.
  • Knowledge of SIEM, IDS/IPS, endpoint protection, threat intelligence solutions.
  • Ability to conduct risk assessments and analyze security risks.
  • Technical assessment skills for vulnerability and security controls.
  • Strong communication skills for conveying findings to stakeholders.
  • Documentation skills for plans and recommendations.
  • Critical thinking and problem solving.
  • Attention to detail for identifying vulnerabilities.
  • Adaptability to evolving threats, technologies, and regulations.
  • Data analysis and trend identification skills.
  • Ethical and professional standards for handling sensitive information.
  • Stakeholder collaboration skills.
  • Commitment to continuous learning.
Working Conditions

Normal working condition with occasional weekend and overtime requirements, including on‑call rotational support.

Physical Demands

Normal physical demands related to an office workplace environment.

Benefits
  • Competitive Salary
  • 401k Savings plan with company matching
  • Pension plan
  • Paid time off
  • Paid Holiday time
  • Medical, Prescription Drug, & Dental Coverage
  • Tuition Assistance Program
  • Employee Assistance Program
  • Wellness Programs
  • On‑site Fitness Centers
  • Bonus Plan and more!
Equal Opportunity Employer

Tampa Electric is proud to be an Equal Opportunity Employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Enterprise Cyber Security Solution Architect
Enterprise Cyber Security Solution Architect

TECO Energy Inc. • Town of Florida (NY)

Hybrid
USD 120,000 - 150,000
401k
Pension
PTO
+1
Cyber Security Analyst, Security Operations, Progression
Cyber Security Analyst, Security Operations, Progression

TECO Energy • Lutz (FL)

On-site
USD 80,000 - 120,000
Competitive Salary
401k match
Pension plan
+7
Cyber Security Analyst, Security Operations, Progression
Cyber Security Analyst, Security Operations, Progression

TECO Energy Inc. • Lutz (FL)

On-site
USD 85,000 - 120,000
401k Savings
Pension plan
Paid time off
+2
Sr. Firewall Engineer, Progression
Sr. Firewall Engineer, Progression

TECO Energy Inc. • Tampa (FL)

On-site
USD 80,000 - 100,000
Competitive Salary
401(k) Savings Plan with company matching
Pension Plan
+4
Compliance & Risk Analyst, SOX Focus, Progression (Level II)
Compliance & Risk Analyst, SOX Focus, Progression (Level II)

TECO Energy, Inc. • Tampa (FL)

On-site
USD 90,000 - 120,000
Competitive Salary
401k Savings plan
Pension plan
+4
Compliance & Risk Analyst, SOX Focus, Progression (Level II)
Compliance & Risk Analyst, SOX Focus, Progression (Level II)

New Mexico Gas Co - Peoples Gas - Tampa Electric • Tampa (FL)

On-site
USD 85,000 - 115,000
Competitive Salary
401k Savings plan w/ company matching
Pension plan
+3
Data Analytics Architect
Data Analytics Architect

TECO Energy Inc. • Tampa (FL)

On-site
USD 95,000 - 120,000
Competitive Salary
401k Savings plan with company matching
Pension plan
+8
Enterprise Analytics Data Engineer
Enterprise Analytics Data Engineer

TECO Energy Inc. • Tampa (FL)

On-site
USD 100,000 - 120,000
401k Savings plan with company matching
Pension plan
Paid time off
+5
Enterprise Analytics Data Engineer
Enterprise Analytics Data Engineer

TECO Energy • Tampa (FL)

On-site
USD 90,000 - 120,000
401k Savings plan with company matching
Pension plan
Paid time off
+3
Firewall Engineer, Checkpoint & VPN Focus, Progression
Firewall Engineer, Checkpoint & VPN Focus, Progression

New Mexico Gas Co - Peoples Gas - Tampa Electric • Lutz (FL)

On-site
USD 110,000 - 165,000
Competitive Salary
401k Savings plan
Pension plan
+8