Overview Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands-on individual contributor role designed for a ...
Overview Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands-on individual contributor role designed for a ...
Information Security Manager
Durham, NC · On-site
Overview Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands-on individual contributor role designed for a ...
Information Security Manager
Durham, NC · On-site
Overview Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands-on individual contributor role designed for a ...
Information Security Specialist
Raleigh, NC · On-site
$131K/yr
As a Information Security Specialist, you will perform information system security manager responsibilities for the Office of the Chief Information Officer (OCIO). Location of position: The Office of ...
Information Security Specialist
Raleigh, NC · On-site
$131K/yr
As a Information Security Specialist, you will perform information system security manager responsibilities for the Office of the Chief Information Officer (OCIO). Location of position: The Office of ...
The NCDOT IT Information Security Office (ISO) requires a senior information security professional, specializing in database vulnerability and threat management (VTM) utilizing and administrating IBM ...
The NCDOT IT Information Security Office (ISO) requires a senior information security professional, specializing in database vulnerability and threat management (VTM) utilizing and administrating IBM ...
Senior Director, Information Security
Chapel Hill, NC · On-site +1
$190K - $230K/yr
Senior Director, Information Security (Security Officer) Reporting to: VP, Legal & General Counsel ... As the Security Officer for Well, you will collaborate with executive management and key ...
Senior Director, Information Security
Chapel Hill, NC · On-site +1
$190K - $230K/yr
Senior Director, Information Security (Security Officer) Reporting to: VP, Legal & General Counsel ... As the Security Officer for Well, you will collaborate with executive management and key ...
Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories). Controls Monitoring & Assurance * Establish ...
Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories). Controls Monitoring & Assurance * Establish ...
Establish Information Security and Risk Management programs. Some of the responsibilities include developing, implementing and maintaining DES information security enterprise standards, processes ...
Establish Information Security and Risk Management programs. Some of the responsibilities include developing, implementing and maintaining DES information security enterprise standards, processes ...
Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories). Controls Monitoring & Assurance * Establish ...
Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories). Controls Monitoring & Assurance * Establish ...
Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories). Controls Monitoring & Assurance * Establish ...
Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories). Controls Monitoring & Assurance * Establish ...
Information Security Engineer
$69 - $74/hr
Information Security Engineer (Contingent) - Findings Management Location: Charlotte, NC; Chandler (Phoenix), AZ; Irving (Dallas), TX About the Role We are seeking an experienced Information Security ...
Information Security Engineer
$69 - $74/hr
Information Security Engineer (Contingent) - Findings Management Location: Charlotte, NC; Chandler (Phoenix), AZ; Irving (Dallas), TX About the Role We are seeking an experienced Information Security ...
Information Security Analyst with Security Clearance
Raleigh, NC · Hybrid
$100K - $115K/yr
... management and remediation tracking Contribute to SOC reporting and metrics Requirements of the Information Security Analyst: Active Secret Clearance (required) 1-3 years of SOC or security analyst ...
Information Security Analyst with Security Clearance
Raleigh, NC · Hybrid
$100K - $115K/yr
... management and remediation tracking Contribute to SOC reporting and metrics Requirements of the Information Security Analyst: Active Secret Clearance (required) 1-3 years of SOC or security analyst ...
Senior Security Engineer - IAM Identity Services
$120K - $150K/yr
Lead the implementation of new information security technologies or integration of existing technologies including initial configuration, installation, change management, and operational handoff
Senior Security Engineer - IAM Identity Services
$120K - $150K/yr
Lead the implementation of new information security technologies or integration of existing technologies including initial configuration, installation, change management, and operational handoff
Certified Information Systems Security Professional, Certified Information Security Manager, or Certified Information Systems Auditor certification * 2+ years of experience with Oracle Enterprise ...
Certified Information Systems Security Professional, Certified Information Security Manager, or Certified Information Systems Auditor certification * 2+ years of experience with Oracle Enterprise ...
Qualifications Required Experience *5+ years of experience in one or more of the following information security domains: access management, cryptography, data loss prevention (DLP), emerging ...
Qualifications Required Experience *5+ years of experience in one or more of the following information security domains: access management, cryptography, data loss prevention (DLP), emerging ...
IT Security Professional I
Durham, NC · On-site
Information Security Services, is responsible for advancing and supporting the university's cybersecurity, governance, risk management, and compliance initiatives. The office works collaboratively ...
IT Security Professional I
Durham, NC · On-site
Information Security Services, is responsible for advancing and supporting the university's cybersecurity, governance, risk management, and compliance initiatives. The office works collaboratively ...
Google Information Security Analyst
Cary, NC · On-site
$85 - $90/hr
Google Information Security Analyst Type of Engagement : 4-week contract Work Location: Onsite ... Assess identity and access management controls. * Review Google Drive sharing and collaboration ...
Google Information Security Analyst
Cary, NC · On-site
$85 - $90/hr
Google Information Security Analyst Type of Engagement : 4-week contract Work Location: Onsite ... Assess identity and access management controls. * Review Google Drive sharing and collaboration ...
Represent Information Security in executive and product leadership forums, articulating the business value of proactive risk management. * Partner with colleagues across Product, Technology ...
Represent Information Security in executive and product leadership forums, articulating the business value of proactive risk management. * Partner with colleagues across Product, Technology ...
Represent Information Security in executive and product leadership forums, articulating the business value of proactive risk management. * Partner with colleagues across Product, Technology ...
Represent Information Security in executive and product leadership forums, articulating the business value of proactive risk management. * Partner with colleagues across Product, Technology ...
Represent Information Security in executive and product leadership forums, articulating the business value of proactive risk management. * Partner with colleagues across Product, Technology ...
Represent Information Security in executive and product leadership forums, articulating the business value of proactive risk management. * Partner with colleagues across Product, Technology ...
Represent Information Security in executive and product leadership forums, articulating the business value of proactive risk management. * Partner with colleagues across Product, Technology ...
Represent Information Security in executive and product leadership forums, articulating the business value of proactive risk management. * Partner with colleagues across Product, Technology ...
Information Security Manager information
See Raleigh, NC salary details
$60.8K - $72.9K
3% of jobs
$72.9K - $85.1K
5% of jobs
$85.1K - $97.2K
10% of jobs
$106.7K is the 25th percentile. Wages below this are outliers.
$97.2K - $109.4K
9% of jobs
$109.4K - $121.5K
13% of jobs
The median wage is $129.7K / yr.
$121.5K - $133.7K
15% of jobs
$133.7K - $145.8K
13% of jobs
$152.1K is the 75th percentile. Wages above this are outliers.
$145.8K - $158K
14% of jobs
$158K - $170.1K
12% of jobs
$170.1K - $182.3K
6% of jobs
$182.3K - $194.4K
0% of jobs
$60.8K
$132.3K
$194.4K
How much do information security manager jobs pay per year?
What are some common challenges Information Security Managers face when implementing new security protocols within an organization?
What are the key skills and qualifications needed to thrive as an Information Security Manager, and why are they important?
What is the difference between Information Security Manager vs Security Analyst?
| Aspect | Information Security Manager | Security Analyst |
|---|---|---|
| Certifications | CISSP, CISM, CISA | CompTIA Security+, GIAC Security Essentials |
| Work Environment | Oversees security policies, manages teams, strategic planning | Monitors security systems, analyzes threats, implements security measures |
| Employer & Industry Usage | Used in organizations with dedicated security teams across industries | Common in IT departments, security operations centers |
The main difference is that the Information Security Manager focuses on strategic security management and team leadership, while the Security Analyst handles day-to-day security monitoring and threat analysis. Both roles require relevant certifications and are vital in maintaining organizational security, but they differ in scope and responsibilities.
What does an Information Security Manager do?
What Is an Information Security Manager?
The job duties of an information security manager involve overseeing the effort to protect networks, computers, and data from cyber attacks, viruses, and other security breaches. In this career, your responsibilities include creating IT security features that can protect your company’s data. In addition to building systems to protect against hacking, you must also be ready to lead the response when a security breach occurs. As an information security manager, you are responsible for creating and implementing practices and policies that employees can use to protect their employer's networks and data.

Other
Medical, Dental, Vision, Retirement, PTO
Posted 18 days ago
Job description
Cypress Creek Energy is powering a sustainable future, one project at a time. We develop, finance, own and operate utility-scale and distributed solar and storage projects across the country. Fostering a diverse group of innovative thinkers from all backgrounds, Cypress people are drawn to work in a purpose-driven organization. We hope you will join us.
Overview
Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands-on individual contributor role designed for a senior technical security professional ready to take ownership of a complete program - with the opportunity to grow into a leader of a team as the function scales.
The successful candidate brings a balance of deep technical execution and program-level compliance maturity. You will own the day-to-day security tooling stack, lead the company's NIST-based compliance program, shape policy in emerging areas including artificial intelligence, and maintain an accurate view of every system in the environment. You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.
Responsibilities
Security Operations & Engineering
- Endpoint security: Administer and tune Microsoft Defender across the endpoint estate, including policy configuration, alert triage, response, and reporting.
- Network and access security: Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.
- SIEM operations: Own SIEM tuning, detection engineering, log source onboarding, alerting, and incident workflows. Build dashboards and metrics that surface meaningful signals.
- Vulnerability management: Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises infrastructure. Prioritize, track, and verify remediation in partnership with IT and engineering teams.
- Patch management: Maintain endpoint patching cadence and reporting, ensuring coverage, exception tracking, and SLA adherence.
- Digital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed.
- NIST-based program: Maintain and continuously improve the company's NIST Cybersecurity Framework-aligned security program, including controls mapping, evidence collection, and gap remediation.
- Policy management: Own the security policy library - ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business.
- AI policy and guidance: Develop and maintain the company's AI usage policies, acceptable use guidance, and review process for new AI tools, in coordination with Counsels and IT.
- System inventory: Build and maintain an authoritative inventory of systems, applications, data flows, and ownership. Keep it accurate as the environment evolves.
- Audit and assessment support: Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure.
- Risk management: Identify, document, and track information security risks; propose mitigations and report on residual risk to leadership.
- Stakeholder engagement: Partner with IT, Counsels, HR, and business leaders on security matters, providing clear guidance that balances risk with business needs.
- Operational Technology (OT): Act as a partner and advisor to the OT team coordinating security and compliance initiatives across the company. Manage intersection of IT and OT endpoints, systems, and networks.
- Security awareness: Drive the security awareness program, including phishing simulations, training content, and ongoing communications.
- Vendor and third-party risk: Assess and manage security risk associated with vendors, contractors, and third-party service providers.
- Future team leadership: Lay the groundwork to scale the function. As the program matures, hire, mentor, and lead a team of security professionals.
- Use of AI to enhance and scale security operations - establish AI first Security Ops
- Bachelor's degree in computer science, information systems, cybersecurity, or related field - or equivalent professional experience.
- 5+ years of progressive experience in information security, with demonstrated depth in security operations, engineering, or a combination of both.
- Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, Cloud).
- Production experience operating Zscaler (ZIA and/or ZPA), including policy management and troubleshooting.
- Strong SIEM experience - building detections, tuning alerts, investigating incidents, and onboarding log sources.
- Vulnerability management experience across cloud environments, specifically AWS and Azure.
- Working knowledge of digital forensics and incident response methodology.
- Demonstrated experience operating a security program aligned to the NIST Cybersecurity Framework or NIST 800-53.
- Track record of writing, maintaining, and operationalizing security policies and standards.
- Clear written and verbal communication, including the ability to explain technical risk to non-technical audiences.
- Ability to work from the Durham, NC or Washington, DC office three days per week.
- Embrace and live by the mission and values of Cypress Creek Energy
- Industry certifications such as CISSP, CISM, GIAC (GCIH, GCFA, GCIA), or equivalent.
- Experience operating in the energy, utility, or critical infrastructure sector.
- Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.
- Experience scripting or automating security workflows (Python, PowerShell, KQL).
- Prior experience as a senior technical lead preparing to step into a manager role.
Compensation: The salary range for the position is $140,000 - $170,000 plus bonus and benefits. Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location.
Benefits:
- 15 days of Paid Time Off, accrual up to 20 days, 11 observed holidays.
- 401(k) Match
- Comprehensive package including medical, dental, vision and health insurance
- Wellness stipend, family planning stipend, and generous parental leave
- Tuition Reimbursement
- Phone Bill Reimbursement
- Company Swag
A note to Recruiting Agencies Cypress Creek Energy Human Resources team does not accept unsolicited resumes from third party recruiters, staffing firms, or related agencies. The Human Resources team coordinates all recruiting and hiring at our company. We do not accept resumes from third-party recruiters unless authorized by the Human Resources team and if a signed agreement is in place. Any unsolicited resumes will be considered property of CCE and we are not responsible for any related fees. All communication related to recruiting partnerships should ONLY be directed to the Human Resources team.
Cypress Creek Energy is an equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status. We are committed to providing a workplace that is inclusive and values diversity, and we encourage candidates from all backgrounds to apply.
Please be aware of recruiting scams-official communications will only come from @ccrenew.com, we will never request personal or financial information, and any suspicious activity should be reported to HR@ccrenew.com.
About Cypress Creek Renewables
Sourced by ZipRecruiter
Industry
Clean energy power generation
Company size
201 - 500 Employees
Headquarters location
Durham, NC, US
Year founded
2014