What are the responsibilities and job description for the Information Security Manager position at Ecotal?
Information Security Manager
Durham, NC | Hybrid, 3 Days In Office
$140,000-$170,000 Base Bonus Benefits
THE COMPANY
A growing organization in the renewable energy and infrastructure space is seeking an Information Security Manager to help own and scale its IT security environment. The company develops, owns, and operates large-scale energy infrastructure across the United States and offers the opportunity to join a growing organization operating at the intersection of technology, energy, and critical infrastructure.
OVERVIEW
We are looking for a hands-on systems and security professional who has built their career across IT infrastructure, systems administration, cloud, identity, networking, and cybersecurity.
This is not a traditional GRC-focused security management position. The ideal candidate will have a strong technical foundation in systems and infrastructure and be comfortable personally troubleshooting, configuring, administering, and securing the environment.
You will take ownership of day-to-day security operations while working closely with the broader IT environment across Microsoft 365, Azure, identity and access management, endpoints, cloud infrastructure, networks, vulnerability management, SIEM, and security tooling.
This is currently an individual contributor position with significant ownership and visibility, reporting directly to the Chief Technology Officer. As the organization continues to scale, there will be an opportunity to help build and eventually lead the security function.
RESPONSIBILITIES
Systems, Infrastructure & Security Operations
- Serve as a hands-on technical resource across Microsoft 365, Azure/Entra ID, Active Directory, endpoint management, identity, cloud infrastructure, networking, and security platforms.
- Administer and improve endpoint security and EDR tooling, including Microsoft Defender and similar platforms.
- Manage identity and access controls, including MFA, SSO, conditional access, privileged access, user lifecycle management, and access policies.
- Support and secure Windows-based infrastructure, endpoints, servers, cloud environments, and core network services.
- Own SIEM operations, including alert tuning, log-source onboarding, detection engineering, investigations, dashboards, and security metrics.
- Lead vulnerability management across AWS, Azure, endpoints, servers, and on-premises infrastructure.
- Partner directly with IT and engineering teams on patching, remediation, infrastructure hardening, and technical troubleshooting.
- Troubleshoot security and infrastructure issues across endpoints, identity, cloud, networking, and applications.
- Lead security investigations and coordinate incident response and remediation.
- Administer and support secure access technologies such as Zscaler ZIA/ZPA or comparable platforms.
- Use PowerShell, Python, KQL, or other automation tools to improve repetitive IT and security processes.
- Identify opportunities to use AI and automation to improve security operations.
Security Program & Compliance
- Maintain and continuously improve the organization's security program in alignment with NIST CSF and/or NIST 800-53.
- Manage controls, evidence collection, gap identification, risk tracking, and remediation.
- Maintain practical security policies, standards, and operating procedures.
- Build and maintain visibility into systems, applications, endpoints, data flows, and ownership.
- Support internal and external audits, customer security assessments, and regulatory requirements.
- Identify and communicate information security risks and recommended mitigation strategies.
- Develop appropriate security guidance around AI and emerging technologies.
Leadership & Partnership
- Work closely with IT, Legal, HR, Operational Technology, and business leadership to solve technical and security challenges.
- Serve as a technical security partner to the OT organization across infrastructure, endpoints, networks, identity, and compliance.
- Own security awareness initiatives, phishing simulations, and employee training.
- Assess security risks associated with vendors and third-party providers.
- Establish repeatable processes and technical standards as the organization grows.
- Help build the foundation for future security team growth, with the opportunity to eventually hire, mentor, and lead additional team members.
EDUCATION & EXPERIENCE REQUIRED
- 5 years of progressive experience across systems administration, infrastructure engineering, IT operations, security engineering, or cybersecurity.
- Strong hands-on experience with Microsoft environments, including Microsoft 365, Azure/Entra ID, Active Directory, Group Policy, and/or Intune.
- Experience administering or supporting Windows Server, endpoints, cloud infrastructure, networking, firewalls, DNS, DHCP, VPN, or related infrastructure technologies.
- Hands-on experience with endpoint security/EDR platforms such as Microsoft Defender, CrowdStrike, SentinelOne, or similar.
- Experience with SIEM platforms, including investigating alerts, working with log sources, and supporting detection and incident response.
- Experience with identity and access management, including SSO, MFA, RBAC, conditional access, or privileged access.
- Experience with vulnerability management, patching, remediation, and infrastructure hardening.
- Working knowledge of NIST CSF, NIST 800-53, or similar security frameworks.
- Ability to personally troubleshoot technical problems while also taking ownership of broader security initiatives.
- Strong communication skills and the ability to work directly with technical teams and executive stakeholders.
- Ability to work from the Durham, NC or Washington, DC office three days per week.
PREFERRED QUALIFICATIONS
- Career progression from Systems Administrator, Systems Engineer, Network Engineer, Infrastructure Engineer, or IT Operations into security.
- Experience working in a smaller or mid-sized organization where IT and security responsibilities overlap.
- Experience with PowerShell, Python, KQL, or infrastructure/security automation.
- Experience with AWS and/or Azure.
- Experience with Zscaler ZIA/ZPA or comparable secure access technologies.
- Experience within energy, utilities, renewable energy, or critical infrastructure.
- Familiarity with NERC CIP or other power-sector regulatory frameworks.
- CISSP, CISM, GIAC, Security , CySA , CCSP, or similar certifications.
- Previous technical leadership, mentorship, or team-lead experience.
Work Authorization: This position does not offer visa sponsorship. Candidates must be a U.S. Citizen or Green Card holder.
Salary : $140,000 - $170,000