Information Security Manager
$140k - $155kCypress Creek Renewables
Information Security Manager
Durham, NC or Washington, DC
The energy industry is entering one of the most significant periods of growth and transformation in its history. Meeting the nation's growing demand for reliable electricity will require new ideas, new infrastructure, and talented people committed to building for the future.
At Cypress Creek Energy, we're meeting that challenge by developing and operating the energy infrastructure needed to power communities, support economic opportunity, and strengthen resilience. We believe our responsibility extends beyond the grid and that how we build matters just as much as what we build.
That same commitment extends to our employees. We invest in professional growth, encourage collaboration across teams, and provide opportunities to take ownership, expand your expertise, and advance your career. Our culture is grounded in safety, accountability, respect, and a shared commitment to deliver results. Join us and help meet one of the most important energy challenges of our time while building a rewarding career.
Cypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands-on individual contributor role designed for a senior technical security professional ready to take ownership of a complete program with the opportunity to grow into a leader of a team as the function scales.
The successful candidate brings a balance of deep technical execution and program-level compliance maturity. You will own the day-to-day security tooling stack, lead the company's NIST-based compliance program, shape policy in emerging areas including artificial intelligence, and maintain an accurate view of every system in the environment. You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.
Responsibilities
- Security Operations & Engineering
- Endpoint security: Administer and tune Microsoft Defender across the endpoint estate, including policy configuration, alert triage, response, and reporting.
- Network and access security: Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.
- SIEM operations: Own SIEM tuning, detection engineering, log source onboarding, alerting, and incident workflows. Build dashboards and metrics that surface meaningful signals.
- Vulnerability management: Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises infrastructure. Prioritize, track, and verify remediation in partnership with IT and engineering teams.
- Patch management: Maintain endpoint patching cadence and reporting, ensuring coverage, exception tracking, and SLA adherence.
- Digital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed.
- Compliance & Governance
- NIST-based program: Maintain and continuously improve the company's NIST Cybersecurity Framework-aligned security program, including controls mapping, evidence collection, and gap remediation.
- Policy management: Own the security policy library ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business.
- AI policy and guidance: Develop and maintain the company's AI usage policies, acceptable use guidance, and review process for new AI tools, in coordination with Counsels and IT.
- System inventory: Build and maintain an authoritative inventory of systems, applications, data flows, and ownership. Keep it accurate as the environment evolves.
- Audit and assessment support: Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure.
- Risk management: Identify, document, and track information security risks; propose mitigations and report on residual risk to leadership.
- Leadership & Cross-Functional Partnership
- Stakeholder engagement: Partner with IT, Counsels, HR, and business leaders on security matters, providing clear guidance that balances risk with business needs.
- Operational Technology (OT): Act as a partner and advisor to the OT team coordinating security and compliance initiatives across the company. Manage intersection of IT and OT endpoints, systems, and networks.
- Security awareness: Drive the security awareness program, including phishing simulations, training content, and ongoing communications.
- Vendor and third-party risk: Assess and manage security risk associated with vendors, contractors, and third-party service providers.
- Future team leadership: Lay the groundwork to scale the function. As the program matures, hire, mentor, and lead a team of security professionals.
Education & Experience Required
- Use of AI to enhance and scale security operations establish AI first Security Ops
- Bachelor's degree in computer science, information systems, cybersecurity, or related field or equivalent professional experience.
- 5+ years of progressive experience in information security, with demonstrated depth in security operations, engineering, or a combination of both.
- Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, Cloud).
- Production experience operating Zscaler (ZIA and/or ZPA), including policy management and troubleshooting.
- Strong SIEM experience building detections, tuning alerts, investigating incidents, and onboarding log sources.
- Vulnerability management experience across cloud environments, specifically AWS and Azure.
- Working knowledge of digital forensics and incident response methodology.
- Demonstrated experience operating a security program aligned to the NIST Cybersecurity Framework or NIST 800-53.
- Track record of writing, maintaining, and operationalizing security policies and standards.
- Clear written and verbal communication, including the ability to explain technical risk to non-technical audiences.
- Ability to work from the Durham, NC or Washington, DC office three days per week.
- Embrace and live by the mission and values of Cypress Creek Energy
Preferred Qualifications
- Industry certifications such as CISSP, CISM, GIAC (GCIH, GCFA, GCIA), or equivalent.
- Experience operating in the energy, utility, or critical infrastructure sector.
- Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.
- Experience scripting or automating security workflows (Python, PowerShell, KQL).
- Prior experience as a senior technical lead preparing to step into a manager role.
Location: The preferred location for this role is for our offices in Durham, NC and Washington, DC. Our team operates on a hybrid schedule, with in-office schedule of three days per week.
Compensation: The salary range for the position is $140,000 - $155,000 plus bonus and benefits. Compensation may vary outside of this range depending on a number of factors, including a candidate's qualifications, skills, competencies and experience, and location.
Benefits:
- 15 days of Paid Time Off, accrual up to 20 days, 11 observed holidays.
- 401(k) Match
- Comprehensive package including medical, dental, vision and health insurance
- Wellness stipend, family planning stipend, and generous parental leave
- Tuition Reimbursement
- Phone Bill Reimbursement
- Company Swag
Cypress Creek Energy is an equal opportunity employer and considers all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, or veteran status. We are committed to providing a workplace that is inclusive and values diversity, and we encourage candidates from all backgrounds to apply.
Cypress Creek Renewables- ...delivers high-impact, technical solutions to complex national security issues. With over 50 years of business expertise and... ..., and Future Force Assessments.SPA has a need for an Information Systems Security Manager to lead cybersecurity and Risk Management Framework activities...SuggestedFlexible hours
$146k - $234k
ResponsibilitiesPeraton is seeking an Information Systems Security Manager to support out customer onsite in Washington D.C. who will be responsible for the following but not limited to:Manage and oversee the security posture of all information systems. Implement and enforce...SuggestedContract workFor contractorsRemote workShift work$160k - $200k
Modern Technology Solutions, Inc. (MTSI) is seeking a Information Systems Security Manager to lead RMF lifecycle activities from system categorization through ATO.Your essential job functions will include but may not be limited to:Develop and maintain authorization packages...SuggestedContract work$83k - $166k
...Logistics Support /Full Time On-Site /On-siteInformation Systems Security Manager (ISSM) - SME Work Location: Washington, DC Employment Type:... ...and Logistics Support CGS is seeking a skilled Information Systems Security Manager (ISSM) - SME to support mission-critical...SuggestedFull time$120.9k - $184.5k
Job Type: RegularOverviewInformation Systems Security functionally manages the process to protect classified information. The Information Systems Security group’s primary function is to implement all classified security policy, procedures and security requirements as required...SuggestedFull timeWork experience placementMonday to Friday$112k - $179k
ResponsibilitiesPeraton is seeking an Information System Security Manager in support of Peraton Labs’ information assurance and information technology operations. This is a full-time on-site position working out of the Silver Spring, Maryland office.Responsibilities include...Full timeContract workWork experience placementWork at officeShift work$150k - $160k
...the Bank's technology governance, risk management, and compliance (GRC) program. Serves as... ...; ensure contract provisions address security, privacy, SLAs, and right-to-audit. Coordinates... ...for onsite meetings. ADDITIONAL INFORMATION:The wage range for the SVP & Director of...Contract workTemporary workWork at officeFlexible hours$175k - $200k
...: The Applied Research Laboratory for Intelligence & Security (ARLIS) at the University of Maryland is a University-Affiliated... ...an IT systems Engineer who will also serve as an Information Systems Security Manager (ISSM) to support advanced research programs at the...Work experience placementInterim roleWork at office$146k - $234k
ResponsibilitiesJob Description:Peraton is seeking an Sr Information Systems Security Officer to support our Federal Strategic Cyber programs.Location... ...ATO package artifacts.Apply expert knowledge of Risk Management Framework (RMF) v5 processes and workflows.Use eMASS to...Contract workWork experience placementShift work- ...Bureau of Investigation's Criminal Justice Information Services Division's Headquarters.... ...Location: Camp Springs, MD Who are you? Security-cleared Professional: Must be able to... ...do: The Information System Security Manager (ISSM) provides senior leadership for security...Temporary workWork at office
$140k - $170k
Modern Technology Solutions, Inc. (MTSI) is seeking an Information System Security Manager (ISSM) to work within the Autonomy Portfolio at Defense Innovation Unit (DIU). The DIU supports the Department of Defense's (DoD) efforts to create and foster commercial partnerships...Full timeContract workWork at officeImmediate startRemote workWorldwideFlexible hours- ...Information Systems Security Manager Type: Full Time Location: Washington DC Overtime Exempt: Yes Reports To: ARMADA HQ Security Clearance Required: TS/SCI w/ CI **********CONTINGENT UPON AWARDING OF GOVERNMENT CONTRACT******** The Information Systems Security Manager...Full timeContract workLocal area
$124k - $180k
...Information System Security Manager (ISSM) Istari is a digital engineering software company enabling our customers to turn the physical world into the digital to accomplish their specific mission or business objectives. Istari was founded with the vision of making...For contractorsWork at officeRemote workHome officeFlexible hours3 days per week$155k - $190k
...Title: Information System Security Manager (ISSM) KBR is seeking an Information System Security Manager (ISSM) to join our team. This position is primarily remote, however the ISSM be able to go into the DoD installation space for meetings and work on ad ad-hoc and sometimes...Temporary workFor contractorsLocal areaImmediate startRemote workRelocation packageFlexible hours- ...Job Description Job Description We are seeking a highly skilled Information Systems Security Manager to join our team. The successful candidate will be responsible for ensuring the security of our information systems and data in accordance with government regulations...
- ...Job Description Job Description Information Systems Security Manager (ISSM) Company Overview: KMS Solutions, LLC is a technical management / solutions company that specializes in engineering, analysis, and cyber security. Founded in 2005, KMS is a certified...Full timeContract workTemporary workWork at officeLocal areaRemote workFlexible hours
- ...Bureau of Investigation's Criminal Justice Information Services Division's Headquarters.... ...Position Location: Camp Springs, MDWho are you?Security-cleared Professional: Must be able to... ...you'll do:The Information System Security Manager (ISSM) provides senior leadership for...Temporary workWork at office
$141.08k - $241.84k
....00 to $241,844.00. Additional compensation may be possible based on experience and skills. Responsibilities The Information Security Manager is responsible for monitoring, analyzing and maintaining EagleBank's technical security engineering controls in support...Full timeFlexible hours$156k - $195k
...OnTrac is hiring a Senior Manager of IT & Cyber Security ! Are you eager to join a dynamic and expanding company where you can both learn and... ...The Must-Haves: ~ Bachelor’s degree in Cybersecurity, Information Security, Computer Science, Information Technology, or a...Contract workTemporary workImmediate startRemote workFlexible hoursShift work- ...Information Systems Security Manager (ISSM) ITCON Services is looking for a bright, motivated Information Systems Security Manager (ISSM) with FMCSA (Federal Motor Carrier Safety Administration) experience to join our team. An Information Systems Security Manager (ISSM...
- Company DescriptionProSidian is a Management And Operations Consulting Services firm that... ...Officer (OCHCO) / Office of the Chief Information Officer (OCIO) Generally Located In Alexandria... ...- Identifying, pursuing, and securing growth opportunities through strategic...Full timeContract workTemporary workFor contractorsH1bWork at officeFlexible hours
- ...Information Security Specialist Develops and administers information security procedures for systems in support of government agencies... ...customer expectations and minimizes security risks. Serves as management official and point-of-contact for all information system...For contractors
$260k - $390k
...join its Data Protection, Privacy and Security practice. This role offers the opportunity... ....Case/Transaction Assistance and Management: Assist/Manage a variety of complex cases... ...elements and to organize and present the information in a standardized way. It is not intended...Full timeWork at officeRelocationRelocation package$146k - $234k
...currently seeking a Cyber Incident Response Analyst Manager to support a government Cyber Security Operation Center (CSOC) onsite in Washington D.C. The... ...from various systems, review open and closed source information on related threats & vulnerabilities, diagnose...Contract workWork experience placementShift work- ...results that strengthen missions and drive lasting value. ResponsibilitiesLMI is seeking a skilled ISSM / RMF Lead to manage information systems security and Risk Management Framework (RMF) activities across a network of technical communications facilities. This...Full time
- ...deep expertise in cyber governance, risk management, and compliance with advanced... ...MAINTAINED "SECRET" (or higher) federal security clearance.Experience in cybersecurity risk... ...Management Professional (PMP)Certified Information Systems Security Professional (CISSP)Certified...Full timeWork experience placementFlexible hours
$148.2k - $292.3k
...Summary As a Full Stack Engineer Manager in Deloitte Cyber’s Digital Trust &... ...communicate effectively with business, security, privacy, legal, and compliance stakeholders... ...degree in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent...Local areaVisa sponsorship- ...Capabilities, Enthusiasm, and Team Focus.Opportunity for an Information System Security Officer (Active TS/SCI) to Join Our Team.Job Description:... ...the Privacy Act, and possess a working knowledge of Risk Management and associated Artifacts required by FISMACyberCore has,...
$107.9k - $195.05k
Job DescriptionInformation Systems Security Officer (ISSO) Leidos - Cyber & Analytics Business Area, Key Management & Analytics Division, Your Experience. A Critical Mission... ...an exciting opportunity for an experienced Information Systems Security Officer (ISSO) to join our...Full timeImmediate startRemote work$110.18k - $183.63k
...thinking organization, apply now.We are currently seeking a Information Systems Security Officer (ISSO) to join our team in Arlington, Virginia (US... ...ISSO ensures compliance with cybersecurity standards and manages system risk.Ensure assigned systems comply with NIST,...Full timeTemporary workWork at officeRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Manager. Be the first to apply!
- sr information security engineer Washington DC
- information technology security engineer Washington DC
- data center security officer Washington DC
- director information security Washington DC
- entry level information security analyst Washington DC
- information security Washington DC
- senior information security analyst Washington DC
- information security compliance analyst Washington DC
- information security lead Washington DC
- information system security engineer Washington DC


