The Technical Compliance Architect serves as a dedicated technical compliance advisor for technology projects affecting JEA's regulated environments. Working as an individual contributor, this position partners with project managers, system architects, engineers, cybersecurity personnel, vendors, and business stakeholders to identify and address applicable regulatory requirements throughout the project lifecycle-from initial planning and design review through commissioning and project closeout.
Acting in an advisory and governance capacity, the Technical Compliance Architect reviews solution architectures, technical designs, security configurations, implementation plans, commissioning documents, and supporting evidence to evaluate alignment with applicable regulatory requirements and JEA standards. The position communicates identified compliance risks and practical recommendations while maintaining clear ownership of system design and implementation with the responsible technology organization. Provides independent technical compliance oversight, support compliance-by-design, and help project teams satisfy applicable requirements before systems or changes are commissioned into regulated environments.
- Establish credible, trusted working relationships with project managers, system architects, engineers, cybersecurity personnel, Operations, Compliance, and other stakeholders.
- Ensure project teams engage CIP Compliance early enough for regulatory requirements to influence planning, technical design, procurement, implementation, and commissioning activities.
- Identify applicable NERC CIP requirements, internal standards, and compliance risks early in the project lifecycle and communicate them in clear, practical terms.
- Provide timely, technically sound, and risk-based compliance guidance without assuming ownership of system design, implementation, or operations.
- Ensure applicable compliance requirements are incorporated into project plans, technical documentation, testing activities, and commissioning criteria before deployment into regulated environments.
- Identify compliance gaps, documentation deficiencies, and control weaknesses before production deployment or project closure, allowing the responsible project or technology team to address them.
- Validate that required compliance documentation and evidence are complete, accurate, traceable, and audit-ready before project turnover.
- Support secure IT and OT modernization while protecting the reliability, cybersecurity, and regulatory compliance of BES Cyber Systems and associated assets.
- Use recurring project issues and lessons learned to improve compliance review methods, commissioning checklists, technical standards, project governance, and compliance awareness among JEA architects and technical teams.
- Maintain and progressively expand technical and regulatory knowledge across relevant technologies, NERC CIP requirements, emerging risks, and industry practices
- Stay abreast of and complies with local, state, and federal legal requirements by studying existing and new legislation.
- Provide leadership and example in meeting JEA's safety and wellness goals.
- Perform other job-related duties as assigned.
Qualifications Education : A bachelor's degree in cybersecurity, information technology, computer science, engineering, information systems, or a related technical field
AND
Experience : Eight (8) years of progressively responsible experience supporting technology implementations, major upgrades, system replacements, infrastructure modernization, or other complex technical projects in one or more of the following areas:
- Network engineering or network security
- Cybersecurity or security engineering
- Windows, Linux, or enterprise systems administration
- Infrastructure or virtualization engineering
- Cloud technologies
- Operational Technology, Industrial Control Systems, or SCADA
- Technology risk, technical compliance, or control assessment
Must have experience participating in one or more of the following activities:
- Technical or engineering design reviews
- Cybersecurity assessments
- Architecture reviews
- System testing or commissioning
- Control validation
- Technical documentation or evidence review
Must have experience working with cross-functional technical and business stakeholders and communicating technical risks, requirements, findings, or recommendations. Experience within an electric utility, critical infrastructure organization, or other regulated technology environment is preferred.
License/Certifications/Registrations : Relevant technical, cybersecurity, compliance, or architecture certifications are preferred, including but not limited to:
- CISSP
- GICSP
- GIAC Response and Industrial Defense (GRID)
- CISA
- CRISC
- Security+
- Cisco certifications
- Microsoft or Azure certifications
- AWS certifications
- VMware certifications
- Red Hat or Linux certifications
- TOGAF
- SABSA
PHYSICAL REQUIREMENTS SittingUp to 8 hours per day
LiftingUp to 2 hours per day
WalkingUp to 5 hours per day
Up to 50 max. pounds
**StandingUp to 3 hours per day
PushingUp to 1 hour per day
BendingUp to 3 hours per day
Up to 50 max. pounds
**SquattingUp to 2 hours per day
PullingUp to 1 hour per day
StoopingUp to 2 hours per day
Up to 50 max. pounds
**ReachingUp to 2 hours per day
ClimbingUp to 1 hour per day
BalancingUp to 1 hour per day
StairsUp to 1 hour per day
TwistingUp to 1 hour per day
LadderUp to 1 hour per day
CrawlingUp to 1 hour per day
Step stoolUp to 1 hour per day
KneelingUp to 1 hour per day
Excessive heatUp to 5 hours per day
TypingUp to 5 hours per day
Excessive coldUp to 1 hour per day
Data EntryUp to 5 hours per day
DustUp to 1 hour per day
HumidityUp to 5 hours per day
Loud NoiseUp to 1 hour per day
Hands in WaterWill not generally apply
Unusual hearing or vision demands:None
Other physical demands or notes:**JEA employees should not attempt to lift, pull, or push a load in excess of 50lbs. without assistance. Care should always be taken when lifting, pushing, or pulling in an awkward position.