Pipeline
Browse Jobs
Sign inSign up
Pipeline
Browse jobsSign inContactTermsPrivacyCookiesPreferences
Logos provided by Logo.dev

© 2026 Pipeline. All rights reserved.

  1. Home
  2. Jobs
  3. Information Technology
  4. Information Security Manager
Cypress Creek Renewables logo

Cypress Creek Renewables

Information Security Manager at Cypress Creek Renewables

Durham, NC or Washington, DCFull-timeInformation TechnologyPosted 13 days ago
Apply with Pipeline→

About the Role

<p><strong>The Company</strong></p> <p>Cypress Creek Energy is powering a sustainable future, one project at a time. We develop, finance, own and operate utility-scale and distributed solar and storage projects across the country. Fostering a diverse group of innovative thinkers from all backgrounds, Cypress people are drawn to work in a purpose-driven organization. We hope you will join us.</p> <p><strong>Overview</strong></p> <p><span data-contrast="none">Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance&nbsp;program. This is a hands-on individual contributor role designed for a senior technical security professional ready to take ownership of a complete program — with the opportunity to grow into a leader of a team as the function scales.</span><span data-ccp-props="{&quot;335559739&quot;:140}">&nbsp;</span></p> <p><span data-contrast="none">The successful candidate brings a balance of deep technical execution and program-level compliance maturity. You will own the day-to-day security tooling stack, lead the company's NIST-based compliance program, shape policy in emerging areas including artificial intelligence, and&nbsp;maintain&nbsp;an accurate&nbsp;view of every system in the environment. You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.</span><span data-ccp-props="{&quot;335559739&quot;:140}">&nbsp;</span></p> <p><strong>Responsibilities</strong></p> <p><span data-contrast="none">Security Operations &amp; Engineering</span><span data-ccp-props="{&quot;335559738&quot;:100,&quot;335559739&quot;:140}">&nbsp;</span></p> <ul> <li><span data-contrast="none">Endpoint security:&nbsp;</span><span data-contrast="none">Administer and tune Microsoft Defender across the endpoint estate, including policy configuration, alert triage, response, and reporting.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Network and access security:&nbsp;</span><span data-contrast="none">Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">SIEM operations:&nbsp;</span><span data-contrast="none">Own SIEM tuning, detection engineering, log source onboarding, alerting, and incident workflows. Build dashboards and metrics that surface meaningful signals.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Vulnerability management:&nbsp;</span><span data-contrast="none">Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises infrastructure. Prioritize, track, and verify remediation in partnership with IT and engineering teams.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Patch management:&nbsp;</span><span data-contrast="none">Maintain&nbsp;endpoint patching cadence and reporting, ensuring coverage, exception tracking, and SLA adherence.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Digital forensics &amp; incident response:&nbsp;</span><span data-contrast="none">Lead investigations into security events, perform forensic analysis, document findings, and coordinate&nbsp;response&nbsp;with internal teams and external partners as needed.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> </ul> <p><span data-contrast="none">Compliance &amp; Governance</span><span data-ccp-props="{&quot;335559738&quot;:180,&quot;335559739&quot;:140}">&nbsp;</span></p> <ul> <li><span data-contrast="none">NIST-based program:&nbsp;</span><span data-contrast="none">Maintain&nbsp;and continuously improve the company's NIST Cybersecurity Framework-aligned security program, including controls mapping, evidence collection, and gap remediation.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Policy management:&nbsp;</span><span data-contrast="none">Own the security policy library — ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">AI policy and guidance:&nbsp;</span><span data-contrast="none">Develop and&nbsp;maintain&nbsp;the company's AI usage policies, acceptable use guidance, and review&nbsp;process&nbsp;for new AI tools, in coordination with Counsels and IT.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">System inventory:&nbsp;</span><span data-contrast="none">Build and&nbsp;maintain&nbsp;an authoritative inventory of systems, applications, data flows, and ownership. Keep it&nbsp;accurate&nbsp;as the environment evolves.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Audit and assessment support:&nbsp;</span><span data-contrast="none">Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Risk management:&nbsp;</span><span data-contrast="none">Identify, document, and track information security risks; propose mitigations and report on residual risk to leadership.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> </ul> <p><span data-contrast="none">Leadership &amp; Cross-Functional Partnership</span><span data-ccp-props="{&quot;335559738&quot;:180,&quot;335559739&quot;:140}">&nbsp;</span></p> <ul> <li><span data-contrast="none">Stakeholder engagement:&nbsp;</span><span data-contrast="none">Partner with IT, Counsels, HR, and business leaders on security matters,&nbsp;providing&nbsp;clear guidance that balances risk with business needs.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Operational Technology (OT):&nbsp;</span><span data-contrast="none">Act as a partner and advisor to the OT&nbsp;team&nbsp;coordinating security and compliance initiatives across the company. Manage intersection of IT and OT endpoints, systems, and networks.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Security awareness:&nbsp;</span><span data-contrast="none">Drive the security awareness program, including phishing simulations, training content, and ongoing communications.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Vendor and third-party risk:&nbsp;</span><span data-contrast="none">Assess and manage security risk associated with vendors, contractors, and third-party service providers.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Future team leadership:&nbsp;</span><span data-contrast="none">Lay the groundwork to scale the function. As the program matures,&nbsp;hire,&nbsp;mentor, and&nbsp;lead&nbsp;a team of security professionals.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> </ul> <p><strong>Education &amp; Experience Required</strong></p> <ul> <li><span data-contrast="auto">Use of AI to enhance and scale security operations –&nbsp;establish&nbsp;AI first Security Ops</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Bachelor's degree in computer science, information systems, cybersecurity, or related field — or equivalent professional experience.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">5+ years of progressive experience in information security, with&nbsp;demonstrated&nbsp;depth in security operations, engineering, or a combination of both.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, Cloud).</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Production experience operating Zscaler (ZIA and/or ZPA), including policy management and troubleshooting.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Strong SIEM experience — building detections, tuning alerts, investigating incidents, and onboarding log sources.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Vulnerability management experience across cloud environments, specifically AWS and Azure.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Working knowledge of digital forensics and incident response&nbsp;methodology.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Demonstrated experience&nbsp;operating&nbsp;a security program aligned to the NIST Cybersecurity Framework or NIST 800-53.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Track record&nbsp;of writing,&nbsp;maintaining, and operationalizing security policies and standards.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Clear written and verbal communication, including the ability to explain technical risk to non-technical audiences.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Ability to work from the Durham, NC or Washington, DC office three days per week.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li>Embrace and live by the mission and values of Cypress Creek Energy</li> </ul> <p><span data-contrast="none"><span data-ccp-parastyle="heading 1">Preferred Qualifications</span></span><span data-ccp-props="{&quot;335559738&quot;:320,&quot;335559739&quot;:180}">&nbsp;</span></p> <ul> <li><span data-contrast="none">Industry certifications such as CISSP, CISM, GIAC (GCIH, GCFA, GCIA), or equivalent.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Experience&nbsp;operating&nbsp;in the energy, utility, or critical infrastructure sector.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Experience scripting or automating security workflows (Python, PowerShell, KQL).</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> <li><span data-contrast="none">Prior experience as a senior technical lead preparing to step into a manager role.</span><span data-ccp-props="{&quot;335559739&quot;:100}">&nbsp;</span></li> </ul> <p><strong>Location:</strong> The preferred location for this role is for our offices in Durham, NC and Washington, DC. Our team operates on a hybrid schedule, with in-office schedule of three days per week.</p> <p><strong>Compensation:</strong> The salary range for the position is $140,000 - $170,000 plus bonus and benefits. Compensation may vary outside of this range depending on a number of factors, including a candidate’s qualifications, skills, competencies and experience, and location.</p> <p><strong>Benefits:</strong></p> <ul> <li>15 days of Paid Time Off, accrual up to 20 days, 11 observed holidays.</li> <li>401(k) Match</li> <li>Comprehensive package including medical, dental, vision and health insurance</li> <li>Wellness stipend, family planning stipend, and generous parental leave</li> <li>Tuition Reimbursement</li> <li>Phone Bill Reimbursement</li> <li>Company Swag</li> </ul> <p><strong>A note to Recruiting Agencies Cypress Creek Energy Human Resources team does not accept unsolicited resumes from third party recruiters, staffing firms, or related agencies. The Human Resources team coordinates all recruiting and hiring at our company. We do not accept resumes from third-party recruiters unless authorized by the Human Resources team and if a signed agreement is in place. Any unsolicited resumes will be considered property of CCE and we are not responsible for any related fees. All communication related to recruiting partnerships should ONLY be directed to the Human Resources team.&nbsp;</strong></p> <p><strong>Cypress Creek Energy is an equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status. We are committed to providing a workplace that is inclusive and values diversity, and we encourage candidates from all backgrounds to apply.</strong></p> <p>&nbsp;</p> <p><em>Please be aware of recruiting scams—official communications will only come from @ccrenew.com, we will never request personal or financial information, and any suspicious activity should be reported to&nbsp;<a class="c-link" href="mailto:[email protected]" target="_blank" data-stringify-link="mailto:[email protected]" data-sk="tooltip_parent">[email protected]</a>.</em></p> <p>&nbsp;</p>

Related Roles

  • Senior Account Manager, Solar & BESS Services

    Cypress Creek Renewables

    Durham, NC
  • Senior Director/VP, Origination

    Cypress Creek Renewables

    Chicago, IL; Washington, DC; or New York City, NY
  • Senior Engineer, HV Engineering

    Cypress Creek Renewables

    Asheville, NC; Durham, NC; New York City, NY; or San Francisco, CA
  • Manager, Environmental Compliance

    Cypress Creek Renewables

    Asheville, NC; Durham, NC; or remoteRemote
  • Junior Engineer, AI Automation

    Cypress Creek Renewables

    Durham, NC or Washington, DC
  • Field Service Technician

    Cypress Creek Renewables

    Conover, NC; Claremont, NC; Maiden, NC