> Markdown version of [/jobs/ext/1207466-manager-information-security](https://www.wearedevelopers.com/jobs/ext/1207466-manager-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Manager, Information Security - **Company:** NovaSource Power Opco, Inc. - **Location:** Houston, TX, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** CompTIA Security+, Cyber Security, Information Systems, Identity and Access Management, IT Management, Security Information and Event Management, Software Vulnerability Management, Information Technology, Operational Systems, CIS Benchmarks - **Published:** July 8, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a013055b912e1f20 ## About the Role * 5+ years of experience in Information Security, Infrastructure Services, OT Security, or related fields. * 2+ years leading technical teams. * Experience implementing cybersecurity policies, procedures, and controls. * Experience supporting regulatory compliance programs, preferably NERC CIP. * Experience conducting security and risk assessments. * Experience with incident response, threat monitoring, IAM, and vulnerability management. Education and Certifications * Bachelor's degree in Cybersecurity, Computer Science, Engineering, Information Systems, or related discipline. * Relevant certifications preferred (CISSP, CISM, GIAC, Security+, PMP). * Advanced degree preferred but not required. Technical Qualifications * Experience managing cybersecurity vendors and security technologies. * Experience implementing and administering information security policies, technologies, controls, and management processes. * Knowledge of NERC CIP standards and data privacy requirements. * Experience with ITIL processes. * Strong analytical, problem-solving, and project management skills. * Experience with SIEM, endpoint security, vulnerability management, and identity governance platforms. * Knowledge of NIST CSF, CIS Controls, and ISO 27001 preferred., * Excellent communication and presentation skills. * Strong analytical and problem-solving abilities. * Experience managing distributed teams and collaborating with global stakeholders. Office Physical Requirements: All positions in our office require interaction with people and technology while either standing or sitting. In order to best serve our customers, internal and external, all associates must be able to communicate face-to-face and on the phone with or without reasonable accommodation. NovaSource is committed to compliance with its obligations under all applicable state and federal laws prohibiting employment discrimination. In keeping with this commitment, it attempts to reasonably accommodate applicants and employees in accordance with the requirements of the disability discrimination laws. It also invites individuals with disabilities to participate in a good faith, interactive process to identify reasonable accommodations that can be made without imposing an undue hardship. Potential candidates will meet the education and experience requirements provided on the above job description and excel in completing the listed responsibilities for this role. ## Description The Manager, Information Security is responsible for managing the day-to-day operations of the Information Security function, supporting the implementation of cybersecurity programs, maintaining security controls, and ensuring compliance with applicable regulatory and company security requirements. This role partners closely with Information Technology, Engineering, and Operations to protect corporate and operational technology environments while supporting the organization's overall cybersecurity strategy., * Manage the day-to-day activities of the Information Security team, providing coaching, guidance, and performance management. * Build, develop, and retain a high-performing information security organization. * Establish clear performance expectations, career-development plans, and succession strategies. * Foster a culture of accountability, continuous improvement, and cybersecurity awareness. * Promote business partnership and consultative engagement across the enterprise. * Support the execution of cybersecurity programs and initiatives that align with business objectives and regulatory requirements. * Manage security operations across corporate, cloud, and operational technology (OT) environments, including monitoring, incident response, identity and access management, and vulnerability management. * Implement and maintain security controls, standards, and procedures to protect company information systems and assets. * Coordinate cybersecurity activities supporting NERC CIP compliance, regulatory audits, and security assessments. * Conduct security risk assessments, identify vulnerabilities, and partner with stakeholders to implement remediation plans. * Support security architecture reviews, technology implementations, and system changes to ensure compliance with established security standards. * Partner with IT, Engineering, Operations, and business teams to address cybersecurity risks and support secure business operations. * Review and approve security requirements for infrastructure, cloud, application, and enterprise architecture initiatives. * Provide cybersecurity oversight for major technology projects and system changes. * Evaluate security technologies and recommend investments supporting risk reduction. * Lead the implementation and lifecycle management of enterprise security tools. * Manage cybersecurity vendors and technologies to ensure effective service delivery and continuous improvement of security operations. * Prepare operational security metrics, reports, and documentation to support leadership decision-making. * Promote cybersecurity awareness by supporting employee training and security awareness initiatives. * Maintain knowledge of emerging cybersecurity threats, technologies, and industry best practices to support continuous improvement. * Partner with Legal, HR, Compliance, and IT leadership on cybersecurity investigations and evidence preservation activities. * Coordinate litigation hold requirements involving cybersecurity incidents, employee investigations, electronic discovery, and regulatory inquiries. * Support forensic collection, chain-of-custody processes, and evidence management activities. * Ensure appropriate preservation and protection of security-related records and audit evidence. * Promote a culture of cybersecurity awareness, accountability, and continuous improvement. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers)