Software Guidance & Assistance, Inc., (SGA), is searching for a
Compliance & Risk Assurance Analyst I for a
CONTRACT assignment with one of our premier
Utility Services clients in
Tampa, FL.
Responsibilities:
Under general supervision, carries out procedures to ensure all information systems products and services meet IT&T organization standards and compliance obligations, including regulatory requirements, contractual requirements, and Emera requirements. Analyst is primarily responsible for the maintenance, training, assurance, monitoring and reporting of all IT standards and procedures, as well as IT&T related regulatory requirements for the TSI IT&T Department and individual business units as applicable.
- Responsible for one or more IT compliance programs (e.g., NERC CIP, PCI DSS, SOX, DFARS, Emera Cyber Security, DHS TSA Pipeline Security). This includes facilitation of and tracking of deliverables for root cause analysis, violation reporting, technical feasibility exceptions, mitigation plan development, evidence reviews, external audit preparations, and NERC Alerts responses. Support the development of flow diagrams or other illustrations showing key steps associated with a given process or sub-process affected by applicable regulations and/or contract terms. As needed, coordinates and facilitates technical feasibility exception audits, mitigation plan completion audits, and other audit spot checks with external auditors. [30%]
- Policies & Procedures: Liaise with IT&T areas such as IT Security, IT Project Management Office, IT Infrastructure, Telecom, Access Administration, and affected corporate areas and business units to facilitate the evaluation, design and implementation of effective methodologies, procedures, and controls to comply with new and existing regulatory requirements. [25%]
- Controls & Monitoring: Provide independent assessment and assurance of the effectiveness and efficiency of the IT control environment. Administers and monitors the execution of TEC compliance program by sampling compliance deliverables for acceptable content and assessing risk. Utilize security tools to further sample content. Participate in the implementation of technology-based tools (e.g., GRC) to support IT compliance and risk initiatives. [20%]
- Responsible for one or more other areas within department as assigned [25%]:
- As needed, provides updates to Business Strategy related to cybersecurity and impact of new legislation/regulatory requirements on TEC business operations.
- Risk Management: Work with technology teams and business stakeholders in the design, implementation, and optimization of IT risk assessment practices.
- Act as ruleset liaison for assigned areas of compliance.
- Act as ruleset Subject Matter Expert (SME) for
- Information Protection Program and assigned CIP compliance related to BES Cyber System Information.
- Ensure mandatory training is conducted, tracked, and recorded.
- Develop and facilitate compliance training for subject matter experts.
- Develops and/or provides input into IT Security awareness program.
- Performance Management: Develops and coordinates the assessment of cybersecurity awareness via phishing campaigns utilizing tool.
Required Skills:
- NERC CIP Awareness Program.
- NERC CIP Training Program.
- NERC CIP Security Management Controls.
SGA is a technology and resource solutions provider driven to stand out. We are a women-owned business. Our mission: to solve big IT problems with a more personal, boutique approach. Each year, we match consultants like you to more than 1,000 engagements. When we say let's work better together, we mean it. You'll join a diverse team built on these core values: customer service, employee development, and quality and integrity in everything we do. Be yourself, love what you do and find your passion at work. Please find us at .
SGA is an Equal Opportunity Employer and does not discriminate on the basis of Race, Color, Sex, Sexual Orientation, Gender Identity, Religion, National Origin, Disability, Veteran Status, Age, Marital Status, Pregnancy, Genetic Information, or Other Legally Protected Status. We are committed to providing access, equal opportunity, and reasonable accommodation for individuals with disabilities in employment, and our services, programs, and activities. Please visit our company to request an accommodation or assistance regarding our policy.