Information Security Manager
Indexed description
Information Security Manager
Durham, NC | Hybrid – 3 Days In Office
$140,000–$170,000 Base + Bonus + Benefits
THE COMPANY
A growing organization in the renewable energy and infrastructure space is seeking an Information Security Manager to help lead and scale its information security program.
The company develops, owns, and operates large-scale energy infrastructure across the United States and offers the opportunity to join a purpose-driven organization operating at the intersection of technology, energy, and critical infrastructure.
OVERVIEW
We are seeking an Information Security Manager to lead the company’s security operations and compliance program.
This is a hands-on individual contributor role designed for a senior technical security professional ready to take ownership of a complete security program, with the opportunity to grow into leadership of a team as the function scales.
The successful candidate will bring a balance of deep technical execution and program-level compliance maturity. You will own the day-to-day security tooling stack, lead the company’s NIST-based compliance program, help shape policy in emerging areas including artificial intelligence, and maintain an accurate view of systems across the environment.
Reporting directly to the Chief Technology Officer, you will partner closely with IT, Legal, Operational Technology, and business stakeholders across the organization.
RESPONSIBILITIES
Security Operations & Engineering
- Administer and tune Microsoft Defender across the endpoint environment, including policy configuration, alert triage, response, and reporting.
- Manage the Zscaler platform, including ZIA/ZPA, policy development, traffic inspection, access controls, troubleshooting, and identity integrations.
- Own SIEM operations, including detection engineering, alert tuning, log-source onboarding, incident workflows, dashboards, and security metrics.
- Lead vulnerability management across AWS, Azure, and on-premises infrastructure, prioritizing and tracking remediation with IT and engineering teams.
- Maintain endpoint patching cadence, coverage, exception tracking, reporting, and SLA adherence.
- Lead investigations into security events, perform digital forensic analysis, document findings, and coordinate incident response with internal and external stakeholders.
- Identify opportunities to leverage AI and automation to enhance and scale security operations.
Compliance & Governance
- Maintain and continuously improve a security program aligned with the NIST Cybersecurity Framework and/or NIST 800-53.
- Manage controls mapping, evidence collection, gap identification, and remediation.
- Own and maintain the company's information security policy and standards library.
- Develop and maintain policies and acceptable-use guidance around artificial intelligence and emerging technologies.
- Build and maintain an authoritative inventory of systems, applications, data flows, and ownership.
- Lead responses to internal and external audits, customer security assessments, and regulatory inquiries.
- Identify, document, track, and communicate information security risks and recommended mitigation strategies.
- Ensure security policies and standards remain current, actionable, and effectively communicated throughout the organization.
Leadership & Cross-Functional Partnership
- Partner with IT, Legal, HR, Operational Technology, and business leadership to provide practical security guidance that balances risk and business requirements.
- Act as a security partner to the OT organization, helping coordinate security and compliance initiatives across IT and operational environments.
- Manage the intersection of IT and OT endpoints, systems, networks, and security requirements.
- Drive the organization's security awareness program, including phishing simulations, training, and ongoing employee communications.
- Assess and manage security risks associated with vendors, contractors, and third-party service providers.
- Establish processes, standards, and operating rhythms that allow the security function to scale effectively.
- Help lay the foundation for future team growth, with the opportunity to hire, mentor, and lead security professionals as the program expands.
EDUCATION & EXPERIENCE REQUIRED
- 5+ years of progressive experience in information security, with demonstrated depth in security operations, security engineering, or a combination of both.
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or a related field, or equivalent professional experience.
- Hands-on experience administering and tuning Microsoft Defender across Endpoint, Identity, and/or Cloud.
- Production experience with Zscaler ZIA and/or ZPA, including policy management and troubleshooting.
- Strong SIEM experience, including building detections, tuning alerts, investigating incidents, and onboarding log sources.
- Vulnerability management experience across cloud environments, specifically AWS and Azure.
- Working knowledge of digital forensics and incident response methodologies.
- Demonstrated experience operating a security program aligned with the NIST Cybersecurity Framework and/or NIST 800-53.
- Experience writing, maintaining, and operationalizing information security policies and standards.
- Ability to identify opportunities to use AI and automation to improve and scale security operations.
- Strong written and verbal communication skills, including the ability to explain technical security risks to non-technical stakeholders.
- Ability to work from the Durham, NC or Washington, DC office three days per week.
PREFERRED QUALIFICATIONS
- Industry certifications such as CISSP, CISM, GIAC (GCIH, GCFA, GCIA), or equivalent.
- Experience within energy, utilities, renewable energy, or critical infrastructure.
- Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.
- Experience scripting or automating security workflows using Python, PowerShell, and/or KQL.
- Prior experience as a senior technical lead preparing to step into broader security management responsibility.
- Experience working within a smaller or mid-sized organization where security professionals are expected to operate across multiple areas of the security function.
Work Authorization: This position does not offer visa sponsorship. Candidates must be a U.S. Citizen or Green Card holder.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search