Cypress Creek Renewables

Cypress Creek Renewables

Information Security Manager

Durham, NC or Washington, DC · Exec

Sponsorship not specified$140k-$170kDetected 54 days ago
PythonPowerShellAWSAzureCloud PlatformsCybersecuritySIEMMicrosoft DefenderKQLSOC OperationsDetection EngineeringIncident ResponseComplianceHRCadenceCypressLeadershipCommunicationCISSP

About the role

  • The successful candidate brings a balance of deep technical execution and program-level compliance maturity.

Responsibilities

  • Network and access security: Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.
  • SIEM operations: Own SIEM tuning, detection engineering, log source onboarding, alerting, and incident workflows. Build dashboards and metrics that surface meaningful signals.
  • Digital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed.
  • NIST-based program: Maintain and continuously improve the company's NIST Cybersecurity Framework-aligned security program, including controls mapping, evidence collection, and gap remediation.
  • Policy management: Own the security policy library - ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business.
  • AI policy and guidance: Develop and maintain the company's AI usage policies, acceptable use guidance, and review process for new AI tools, in coordination with Counsels and IT.
  • System inventory: Build and maintain an authoritative inventory of systems, applications, data flows, and ownership. Keep it accurate as the environment evolves.
  • Audit and assessment support: Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure.
  • Risk management: Identify, document, and track information security risks

Requirements

  • Bachelor's degree in computer science, information systems, cybersecurity, or related field - or equivalent professional experience.
  • 5+ years of progressive experience in information security, with demonstrated depth in security operations, engineering, or a combination of both.
  • Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, Cloud).
  • Production experience operating Zscaler (ZIA and/or ZPA), including policy management and troubleshooting.
  • Working knowledge of digital forensics and incident response methodology.
  • Track record of writing, maintaining, and operationalizing security policies and standards.
  • Clear written and verbal communication, including the ability to explain technical risk to non-technical audiences.
  • Ability to work from the Durham, NC or Washington, DC office three days per week.

Nice to have

  • Industry certifications such as CISSP, CISM, GIAC (GCIH, GCFA, GCIA), or equivalent.
  • Experience operating in the energy, utility, or critical infrastructure sector.
  • Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.
  • Experience scripting or automating security workflows (Python, PowerShell, KQL).

Skills

  • Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises infrastructure.
  • Prioritize, track, and verify remediation in partnership with IT and engineering teams.

Compensation

  • The salary range for the position is $140,000 - $170,000 plus bonus and benefits.
  • Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location.

Benefits

  • 15 days of Paid Time Off, accrual up to 20 days, 11 observed holidays.
  • Comprehensive package including medical, dental, vision and health insurance
  • Wellness stipend, family planning stipend, and generous parental leave
  • Tuition Reimbursement
  • Phone Bill Reimbursement
  • Patch management: Maintain endpoint patching cadence and reporting, ensuring coverage, exception tracking, and SLA adherence.

Company info

  • Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program.
  • You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.
  • Any unsolicited resumes will be considered property of CCE and we are not responsible for any related fees.
  • We are committed to providing a workplace that is inclusive and values diversity, and we encourage candidates from all backgrounds to apply.

Equal opportunity

  • equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status.

This listing is sourced directly from Cypress Creek Renewables's careers page and normalized into a canonical job model.