Back to jobs

Information Security Manager

Hybrid / United StatesFull timeLead / Manager$140,000 – $155,000 / year
Apply

About the role

The Company

The energy industry is entering one of the most significant periods of growth and transformation in its history. Meeting the nation’s growing demand for reliable electricity will require new ideas, new infrastructure, and talented people committed to building for the future.

At Cypress Creek Energy, we’re meeting that challenge by developing and operating the energy infrastructure needed to power communities, support economic opportunity, and strengthen resilience. We believe our responsibility extends beyond the grid and that how we build matters just as much as what we build.

That same commitment extends to our employees. We invest in professional growth, encourage collaboration across teams, and provide opportunities to take ownership, expand your expertise, and advance your career. Our culture is grounded in safety, accountability, respect, and a shared commitment to deliver results. Join us and help meet one of the most important energy challenges of our time while building a rewarding career.

Overview

Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands-on individual contributor role designed for a senior technical security professional ready to take ownership of a complete program — with the opportunity to grow into a leader of a team as the function scales.

The successful candidate brings a balance of deep technical execution and program-level compliance maturity. You will own the day-to-day security tooling stack, lead the company's NIST-based compliance program, shape policy in emerging areas including artificial intelligence, and maintain an accurate view of every system in the environment. You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.

Responsibilities

Security Operations & Engineering

  • Endpoint security: Administer and tune Microsoft Defender across the endpoint estate, including policy configuration, alert triage, response, and reporting.
  • Network and access security: Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.
  • SIEM operations: Own SIEM tuning, detection engineering, log source onboarding, alerting, and incident workflows. Build dashboards and metrics that surface meaningful signals.
  • Vulnerability management: Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises infrastructure. Prioritize, track, and verify remediation in partnership with IT and engineering teams.
  • Patch management: Maintain endpoint patching cadence and reporting, ensuring coverage, exception tracking, and SLA adherence.
  • Digital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed.

Compliance & Governance

  • NIST-based program: Maintain and continuously improve the company's NIST Cybersecurity Framework-aligned security program, including controls mapping, evidence collection, and gap remediation.
  • Policy management: Own the security policy library — ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business.
  • AI policy and guidance: Develop and maintain the company's AI usage policies, acceptable use guidance, and review process for new AI tools, in coordination with Counsels and IT.
  • System inventory: Build and maintain an authoritative inventory of systems, applications, data flows, and ownership. Keep it accurate as the environment evolves.
  • Audit and assessment support: Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure.
  • Risk management: Identify, document, and track information security risks; propose mitigations and report on residual risk to leadership.

Leadership & Cross-Functional Partnership

  • Stakeholder engagement: Partner with IT, Counsels, HR, and business leaders on security matters, providing clear guidance that balances risk with business needs.
  • Operational Technology (OT): Act as a partner and advisor to the OT team coordinating security and compliance initiatives across the company. Manage intersection of IT and OT endpoints, systems, and networks.
  • Security awareness: Drive the security awareness program, including phishing simulations, training content, and ongoing communications.
  • Vendor and third-party risk: Assess and manage security risk associated with vendors, contractors, and third-party service providers.
  • Future team leadership: Lay the groundwork to scale the function. As the program matures, hire, mentor, and lead a team of security professionals.

Education & Experience Required

  • Use of AI to enhance and scale security operations – establish AI first Security Ops
  • Bachelor's degree in computer science, information systems, cybersecurity, or related field — or equivalent professional experience.
  • 5+ years of progressive experience in information security, with demonstrated depth in security operations, engineering, or a combination of both.
  • Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, Cloud).
  • Production experience operating Zscaler (ZIA and/or ZPA), including policy management and troubleshooting.
  • Strong SIEM experience — building detections, tuning alerts, investigating incidents, and onboarding log sources.
  • Vulnerability management experience across cloud environments, specifically AWS and Azure.
  • Working knowledge of digital forensics and incident response methodology.
  • Demonstrated experience operating a security program aligned to the NIST Cybersecurity Framework or NIST 800-53.
  • Track record of writing, maintaining, and operationalizing security policies and standards.
  • Clear written and verbal communication, including the ability to explain technical risk to non-technical audiences.
  • Ability to work from the Durham, NC or Washington, DC office three days per week.
  • Embrace and live by the mission and values of Cypress Creek Energy

Preferred Qualifications

  • Industry certifications such as CISSP, CISM, GIAC (GCIH, GCFA, GCIA), or equivalent.
  • Experience operating in the energy, utility, or critical infrastructure sector.
  • Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.
  • Experience scripting or automating security workflows (Python, PowerShell, KQL).
  • Prior experience as a senior technical lead preparing to step into a manager role.

Location:

The preferred location for this role is for our offices in Durham, NC and Washington, DC. Our team operates on a hybrid schedule, with in-office schedule of three days per week.

Compensation:

The salary range for the position is $140,000 - $155,000 plus bonus and benefits. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location.

Benefits

  • 15 days of Paid Time Off, accrual up to 20 days, 11 observed holidays.
  • 401(k) Match
  • Comprehensive package including medical, dental, vision and health insurance
  • Wellness stipend, family planning stipend, and generous parental leave
  • Tuition Reimbursement
  • Phone Bill Reimbursement
  • Company Swag

A note to Recruiting Agencies Cypress Creek Energy Human Resources team does not accept unsolicited resumes from third party recruiters, staffing firms, or related agencies. The Human Resources team coordinates all recruiting and hiring at our company. We do not accept resumes from third-party recruiters unless authorized by the Human Resources team and if a signed agreement is in place. Any unsolicited resumes will be considered property of CCE and we are not responsible for any related fees. All communication related to recruiting partnerships should ONLY be directed to the Human Resources team.

Cypress Creek Energy is an equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status. We are committed to providing a workplace that is inclusive and values diversity, and we encourage candidates from all backgrounds to apply.

Please be aware of recruiting scams—official communications will only come from @ccrenew.com, we will never request personal or financial information, and any suspicious activity should be reported to [email protected].

Search the jobs. Check the details. Make your move.

Compare recent openings by location, work format, pay, and experience level in one place.

Explore jobs
Smiling man pointing at a “Job offer!” notification on his phone

Excellent

Rated 4.8 out of 5 based on 617 reviewsTrustpilot

by Megan F.

Job seeker

The filters made it easier to see roles that actually matched the way I want to work. I could compare options without opening dozens of tabs.

by Daniel B.

Developer

I liked being able to narrow the search to remote roles and check the requirements before taking the next step.

by Rachel A.

People operations

The listings are easy to scan. Work format, location, and experience level are right where I expect them.

by Marcus H.

Data analyst

Salary and location filters helped me focus on roles that were worth a closer look.

by Aisha K.

QA engineer

I found the job details clear and useful. It was simple to see which skills mattered for each role.

by Olivia G.

Support specialist

The search felt straightforward, and I could quickly switch between different kinds of jobs.

by Kevin T.

Account manager

It is easy to revisit roles that fit my experience. I would like to see even more openings in my area.

by Sophia R.

Product designer

I could check work format and salary before reading the full description. That made my search feel much clearer.

by Hannah S.

Project coordinator

The job pages put the important details together, so I knew what to expect before deciding to continue.

by Victor A.

DevOps engineer

The remote filter is useful and the listings are quick to scan. A few more country options would make it even better.

by Brandon L.

Job seeker

After a break from work, a simple search and clear filters helped me start looking again without feeling overwhelmed.

by Jessica M.

Marketing coordinator

The search is straightforward. I can move from a short result to the full role description in one click.

by Christopher H.

Operations manager

I like seeing salary, location, and experience level next to each role. It saves time when comparing openings.

by Ethan M.

Sales representative

The layout is clean and the job cards are easy to read. I am looking forward to a larger selection of listings.

by David R.

Support specialist

I found the different work formats easy to browse and could quickly open roles that matched my schedule.

Frequently asked questions

Answers about finding your next role

What can I search for?

Search by job title or keyword, then browse remote, hybrid, and onsite openings in one list.

Where can I find remote jobs?

Browse remote openings on Remote Amigo. Search by job title or keyword, then choose Remote in the work format filter. Check each listing for location or country requirements.

How do I narrow the results?

Choose a country, work format, minimum annual salary, and experience level. You can change or clear the filters at any time.

What will I see on a job page?

Each listing shows the role, company, location, work format, salary when available, skills when provided, and a job description.

Do I need an account to browse jobs?

No. You can search and read the available listings without signing in.

Does this site submit job applications for me?

No. You can search and review listings here. The Apply button starts the job preference quiz; it does not submit an application to an employer.

Where do the jobs come from?

Listings are imported from public job feeds and job sites. Job details may change at the original source, so confirm the latest information before applying.

How recent are the listings?

Search results include listings with a publication date in the last 30 days. If a source provides no publication date, the import date is used; the actual posting may be older.

Can I search for remote jobs only?

Yes. Select Remote in the job type filter to show remote listings. You can switch to Hybrid or Onsite whenever you want.

What is the difference between remote, hybrid, and onsite?

Remote roles are intended to be done away from an office. Hybrid roles combine remote and office work. Onsite roles are based at a workplace. Always read the listing for its exact location requirements.

Can I filter jobs by country?

Yes. Choose a country in the search form to narrow the listings. A remote role may still have country restrictions, so check its description before applying.

Why do some jobs have no salary listed?

Some listings do not include pay information. We show a salary when it is available and leave it out when it is not provided.

Is the salary filter a monthly or annual amount?

The minimum salary field uses US dollars per year. It filters listings that have comparable salary information.

Can I change or clear my search filters?

Yes. Change the keyword, country, job type, salary, or level in the search form. You can clear individual fields and run a broader search again.