Information Security Manager- Remote

Cypress Creek Energy is powering a sustainable future, one project at a time. We develop, finance, own and operate utility-scale and distributed solar and storage projects across the country. Fostering a diverse group of innovative thinkers from all backgrounds, Cypress people are drawn to work in a purpose-driven organization.

Cypress Creek

Energy is hiring an Information Security Manager to lead the company's security operations and compliance program. You will own the day-to-day security tooling stack, lead the company's NIST-based compliance program, shape policy in emerging areas including artificial intelligence, and maintain an accurate view of every system in the environment. You will report directly to the Chief Technology Officer and partner closely with IT, Counsels, and business stakeholders across the company.

Security

Operations & Engineering Administer and tune Microsoft Defender across the endpoint estate, including policy configuration, alert triage, response, and reporting.

Network and access security: Manage the Zscaler platform (ZIA/ZPA), including policy development, traffic inspection, access controls, and integration with identity systems.

SIEM operations: Run the vulnerability scanning program across AWS and Azure cloud environments and on-premises infrastructure. Prioritize, track, and verify remediation in partnership with IT and engineering teams.

Digital forensics & incident response: Lead investigations into security events, perform forensic analysis, document findings, and coordinate response with internal teams and external partners as needed. Maintain and continuously improve the company's NIST Cybersecurity Framework-aligned security program, including controls mapping, evidence collection, and gap remediation.

Policy management: Own the security policy library — ensure policies and standards are current, reviewed on a defined cadence, approved through the right channels, and communicated to the business.

AI policy and guidance: Develop and maintain the company's AI usage policies, acceptable use guidance, and review process for new AI tools, in coordination with Counsels and IT. Build and maintain an authoritative inventory of systems, applications, data flows, and ownership.

Audit and assessment support: Lead responses to internal and external audits, customer security reviews, and regulatory inquiries. Manage remediation of identified findings through closure.

Risk management: Identify, document, and track information security risks; propose mitigations and report on residual risk to leadership. Leadership & Cross-Functional Partnership Partner with IT, Counsels, HR, and business leaders on security matters, providing clear guidance that balances risk with business needs. Manage intersection of IT and OT endpoints, systems, and networks.

Drive the security awareness program, including phishing simulations, training content, and ongoing communications. Vendor and third-party risk: Assess and manage security risk associated with vendors, contractors, and third-party service providers. Use of AI to enhance and scale security operations - establish AI first Security Ops Bachelor's degree in computer science, information systems, cybersecurity, or related field — or equivalent professional experience. 5+ years of progressive experience in information security, with demonstrated depth in security operations, engineering, or a combination of both.

Hands-on administration and tuning experience with Microsoft Defender (Endpoint, Identity, Cloud). Production experience operating Zscaler (ZIA and/or ZPA), including policy management and troubleshooting. Strong SIEM experience — building detections, tuning alerts, investigating incidents, and onboarding log sources.

Vulnerability management experience across cloud environments, specifically AWS and Azure. Working knowledge of digital forensics and incident response methodology. Demonstrated experience operating a security program aligned to the NIST Cybersecurity Framework or NIST 800-53.

Track record of writing, maintaining, and operationalizing security policies and standards. Clear written and verbal communication, including the ability to explain technical risk to non-technical audiences. Ability to work from the Durham, NC or Washington, DC office three days per week.

Familiarity with NERC CIP or other regulatory frameworks relevant to the power sector.

Experience scripting or automating security workflows (Python, PowerShell, KQL). Our team operates on a hybrid schedule, with in-office schedule of three days per week.

Compensation: The salary range for the position is $140,000 - $170,000 plus bonus and benefits. 15 days of Paid Time Off, accrual up to 20 days, 11 observed holidays. Comprehensive package including medical, dental, vision and health insurance Tuition Reimbursement Phone

Back to blog

Common Interview Questions And Answers

1. HOW DO YOU PLAN YOUR DAY?

This is what this question poses: When do you focus and start working seriously? What are the hours you work optimally? Are you a night owl? A morning bird? Remote teams can be made up of people working on different shifts and around the world, so you won't necessarily be stuck in the 9-5 schedule if it's not for you...

2. HOW DO YOU USE THE DIFFERENT COMMUNICATION TOOLS IN DIFFERENT SITUATIONS?

When you're working on a remote team, there's no way to chat in the hallway between meetings or catch up on the latest project during an office carpool. Therefore, virtual communication will be absolutely essential to get your work done...

3. WHAT IS "WORKING REMOTE" REALLY FOR YOU?

Many people want to work remotely because of the flexibility it allows. You can work anywhere and at any time of the day...

4. WHAT DO YOU NEED IN YOUR PHYSICAL WORKSPACE TO SUCCEED IN YOUR WORK?

With this question, companies are looking to see what equipment they may need to provide you with and to verify how aware you are of what remote working could mean for you physically and logistically...

5. HOW DO YOU PROCESS INFORMATION?

Several years ago, I was working in a team to plan a big event. My supervisor made us all work as a team before the big day. One of our activities has been to find out how each of us processes information...

6. HOW DO YOU MANAGE THE CALENDAR AND THE PROGRAM? WHICH APPLICATIONS / SYSTEM DO YOU USE?

Or you may receive even more specific questions, such as: What's on your calendar? Do you plan blocks of time to do certain types of work? Do you have an open calendar that everyone can see?...

7. HOW DO YOU ORGANIZE FILES, LINKS, AND TABS ON YOUR COMPUTER?

Just like your schedule, how you track files and other information is very important. After all, everything is digital!...

8. HOW TO PRIORITIZE WORK?

The day I watched Marie Forleo's film separating the important from the urgent, my life changed. Not all remote jobs start fast, but most of them are...

9. HOW DO YOU PREPARE FOR A MEETING AND PREPARE A MEETING? WHAT DO YOU SEE HAPPENING DURING THE MEETING?

Just as communication is essential when working remotely, so is organization. Because you won't have those opportunities in the elevator or a casual conversation in the lunchroom, you should take advantage of the little time you have in a video or phone conference...

10. HOW DO YOU USE TECHNOLOGY ON A DAILY BASIS, IN YOUR WORK AND FOR YOUR PLEASURE?

This is a great question because it shows your comfort level with technology, which is very important for a remote worker because you will be working with technology over time...