Information Security Manager
Listed on 2026-06-26
-
IT/Tech
Cybersecurity, Information Security
The Company
Cypress Creek Energy is powering a sustainable future, one project at a time. We develop, finance, own and operate utility-scale and distributed solar and storage projects across the country. Fostering a diverse group of innovative thinkers from all backgrounds, Cypress people are drawn to work in a purpose-driven organization. We hope you will join us.
OverviewCypress Creek Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. This is a hands‑on individual contributor role designed for a senior technical security professional ready to take ownership of a complete program — with the opportunity to grow into a leader of a team as the function scales.
The successful candidate brings a balance of deep technical execution and program‑level compliance maturity. You will own the day‑to‑day security tooling stack, lead the company's NIST-based compliance program, shape policy in emerging areas including artificial intelligence, and maintain an accurate view of every system in the environment. You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.
ResponsibilitiesSecurity Operations & Engineering
- Endpoint security:
Administer and tune Microsoft Defender across the endpoint estate, including policy configuration, alert triage, response, and reporting. - Network and access security:
Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems. - SIEM operations:
Own SIEM tuning, detection engineering, log source onboarding, alerting, and incident workflows. Build dashboards and metrics that surface meaningful signals. - Vulnerability management:
Run the vulnerability scanning program across AWS and Azure cloud environments and on‑premises infrastructure. Prioritize, track, and verify remediation in partnership with IT and engineering teams. - Patch management:
Maintain endpoint patching cadence and reporting, ensuring coverage, exception tracking, and SLA adherence. - Digital forensics & incident response:
Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed.
- NIST-based program:
Maintain and continuously improve the company's NIST Cybersecurity Framework‑aligned security program, including controls mapping, evidence collection, and gap remediation. - Policy management:
Own the security policy library — ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business. - AI policy and guidance:
Develop and maintain the company's AI usage policies, acceptable use guidance, and review process for new AI tools, in coordination with Counsels and IT. - System inventory:
Build and maintain an authoritative inventory of systems, applications, data flows, and ownership. Keep it accurate as the environment evolves. - Audit and assessment support:
Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure. - Risk management:
Identify, document, and track information security risks; propose mitigations and report on residual risk to leadership.
- Stakeholder engagement:
Partner with IT, Counsels, HR, and business leaders on security matters, providing clear guidance that balances risk with business needs. - Operational Technology (OT):
Act as a partner and advisor to the OT team coordinating security and compliance initiatives across the company. Manage intersection of IT and OT endpoints, systems, and networks. - Security awareness:
Drive the security awareness program, including phishing simulations, training content, and ongoing communications. - Vendor and third‑party risk:
Assess and manage security risk associated with vendors, contractors, and third‑party service providers. - Future team leadership:
Lay the groundwork to scale the function. As the program matures,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).