Jobs and Careers
TE

IT Compliance & Risk Assurance Lead

TECO Energy
Ybor City, Florida, US, 33605, United Statesfull_timeVerifiedPosted 9 Jul 2024

About the role

Power up a career with us. Our people are our greatest investments. 

 

Be the light to help us keep our customers connected.  If you are interested in a career and not just a position, Tampa Electric is the place to be! Tampa Electric offers competitive pay, a comprehensive benefits package and opportunities for growth and development in a friendly and professional work environment. We embrace diversity and the inclusion of all. We believe our differences, unique perspectives and talents are our strengths and integral to the success of our company.

 

We’re honored to serve approximately 780,000 customers across West Central Florida and safely provide them with clean, affordable and reliable electricity. We’ve been doing it for more than 100 years, and there’s so much more ahead.  

 

Join our team of energy experts as we build on that legacy through innovation, continued solar investments, cost-effective and sustainable energy solutions all while keeping top-notch customer service at the center of all we do. 

 

Tampa Electric is a subsidiary of Emera Inc., a family of energy companies which also includes TECO Peoples Gas and New Mexico Gas Company. Emera provides energy to residential and commercial customers in the United States, Canada, and the Caribbean, with career opportunities available in all of these locations. 

 

 

TITLE:    IT Risk and Compliance Assurance Lead
PERFORMANCE COACH:     Manager, Compliance & Assurance

COMPANY:    Tampa Electric Company
DEPARTMENT:    IT Compliance and Assurance 

 

POSITION CONCEPT
Leads a team which does the following:  Responsible for supporting activities directly related to assuring and maintaining Tampa Electric’s adherence with the NERC CIP standards and requirements. Includes assessing and assuring relevant systems, assets, processes, controls, procedures, and evidence of compliance are accurate, demonstrate compliance with applicable requirements, are effective on a continuous basis, and that all periodic activities needed for ongoing compliance have been performed in a timely manner.  Ensures audit readiness and detects issues that may lead to non-compliance and act to prevent the non-compliance, as well as identify potential NERC CIP non-compliance issues. Creates and performs internal technical controls to produce evidence of ongoing compliance.

Utilizes critical thinking skills and in-depth understanding of the NERC CIP standards and requirements, expertise in the review, testing, and development of processes, procedures, technical controls, and evidence of compliance to demonstrate control effectiveness and compliance. 

 

PRIMARY DUTIES AND RESPONSIBILITIES INCLUDE, BUT ARE NOT LIMITED TO, THE FOLLOWING: 
1.    Oversee independent assessment and assurance of the effectiveness and efficiency of the NERC CIP control environment. Administers and monitors the execution of TEC compliance program by sampling compliance deliverables for acceptable content and assessing risk. Utilize technical security tools to further sample content. [30%]
a.    Lead the testing and validation of existing NERC CIP assets, processes, procedures, technology and people to assure their continued compliance with NERC CIP standards and requirements.
b.    Provides ongoing validation, guidance and oversight of work completed by NERC CIP stakeholders to ensure quality results.  
c.    Identify, evaluate, and recommend plans that assist in the mitigation/remediation areas of cyber security compliance risks and vulnerabilities identified during related assurance duties, especially key risk indicators and preventive controls including alerts and/or automation.
d.    Ensure compliance issues are investigated and reported to appropriate authority. 

2.    Advance assurance program.  Maintain, monitor, and report on status of the assurance program [including identification and monitoring of performance metrics.  [20%]
a.    Lead efforts to monitor, assess, detect, and report on the continued effectiveness of implemented security controls by leveraging administrative processes and technologies. 
b.    Coordinate and collaborate with affected stakeholders in response to identified control misconfigurations or systems in a potential non-compliant state (e.g., unauthorized ports, misconfigured password settings, etc.).
c.    Create new internal co

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

TECO Energy

View company profile →