AYN

IT Infrastructure & Security Lead

O.R. Colan Associates · Charlotte, North Carolina · hybrid

USD 110,076 to 121,084 a year

Location: Charlotte, NC

Schedule: Full-time; Exempt

Travel: Candidate will primarily work remote and have the opportunity to work in-office at manager's discretion or as needed for team cohesion

Why Join ORC?

The Right Work. The Right People. The Right Culture.

Right of Way is where infrastructure meets innovation—shaping roads, utilities, and communities for the future. At ORC, we offer more than a job—we offer purpose, stability, and growth. You’ll join a team that values collaboration, workplace flexibility, and long-term opportunity.

About the RoleORC is growing, and our technology function is growing with it. We are looking for a hands-on IT Infrastructure & Security Lead to own our security and compliance program, strengthen the reliability of our core infrastructure, and set the security and governance standards that support a growing firm.

This role reports directly to our CIO and sits at the center of some of our most important work, including our SOC 2 certification, access governance, and the systems that keep a national workforce connected and secure. You will work closely with leaders across the firm to make security practical and part of how we operate.

This is a role for someone who has been in the trenches as a systems administrator, has led people or technical programs, and wants to shape how an IT function operates as it scales. For the right person, there is a real path into broader IT leadership as the function grows.

What You’ll Do- Own the security and compliance program- Serve as the day-to-day owner of our SOC 2 program, including control design, evidence collection, policy maintenance, and auditor coordination

- Manage our compliance tooling and keep controls operating consistently throughout audit observation periods

- Lead risk assessments and vendor security reviews

- Translate security and compliance requirements into clear, practical expectations for technical and non-technical audiences

- Govern access across the organization- Define and maintain access policies, including least privilege, privileged access, and onboarding and offboarding standards

- Run regular access reviews across critical systems and drive remediation

- Oversee identity and credential management practices, including MFA and credential vaulting

- Strengthen infrastructure and resilience- Lead infrastructure architecture and engineering across our Microsoft 365, Entra ID, endpoint, server, and network environments, staying hands-on during projects, incidents, and remediation

- Own backup, recovery, and business continuity testing

- Improve monitoring, logging, alerting, and incident response

- Document systems, configurations, and runbooks so knowledge is shared and resilient

- Bring discipline to how change happens- Establish change management standards for infrastructure changes, scripts, and automations

- Define testing, approval, and rollback expectations so changes are reliable and well documented

- Partner across the business- Build security awareness and practical guidance for employees across the firm

- Share security and systems expertise through training, documentation, and coaching

- Report on security posture and program progress to the CIO and executive leadership

- Provide input and collaborate across project management initiatives related to other functions

We’re Looking for Someone Who- Is organized, analytical, and detail-oriented

- Troubleshoots methodically and follows problems to the root cause

- Communicates technical concepts clearly to non-technical teammates

- Works efficiently under tight deadlines and keeps multiple priorities moving

- Documents work so others can build on it

- Picks up new systems and software quickly

Minimum Requirements- 6+ years of IT experience, including at least 5 years of hands-on systems administration

- 2+ years leading people or technical programs, such as a team lead, service desk lead, or technical project lead role

- Strong working knowledge of Microsoft 365, Entra ID (Azure AD), Intune or similar endpoint management, Windows Server, and core networking

- Experience implementing security controls and access governance in a production environment

- Experience supporting an audit or working within a security or compliance framework such as SOC 2, ISO 27001, or NIST CSF

- Sound judgment and a habit of thinking through consequences before acting

- The ability to explain technical risk in plain business language

Preferred - Experience with M&A and integrating acquired organizations

- Direct experience owning SOC 2 controls or supporting a SOC 2 Type II audit

- Experience with compliance automation platforms such as Secureframe, Vanta, or Drata

- Scripting and automation experience, such as PowerShell

- Experience with ITSM tools and service desk practices

- Relevant certifications such as CISSP, CISA, Microsoft Certified Administrator, or ITIL

- Experience in a growing, fast-paced environment with responsibilities leading a team of people

What We OfferThis posting covers a single level. The pay range is $110,076 – $121,084. Every candidate is assessed and evaluated during the hiring process to determine their level based on factors, such as training, transferable skills, work experience, business needs, and market demands. Your offer will reflect the level that best matches your experience.

Relocation and per diem are not provided.- Medical, dental, and vision coverage

- 401(k) with company match, plus disability coverage

- Paid time off, sick time, and paid holidays

- Tuition reimbursement and paid professional development

- ClassPass and Breethe memberships

- Recognition programs and real room to grow

That’s the quick version — learn more about benefits at ORC.Make your mark on projects that matter. Apply now to join a supportive team that invests in your future.

Employees must avoid any relationship or activity that might impair, or even appear to impair, their ability to make objective and fair decisions when performing their jobs. To avoid conflicts of interest, employees are prohibited from performing any services for clients or perceived clients during nonworking time that are normally performed by ORC, including the sale of real estate.

Physical Requirements: While performing the duties of this job, it requires a combination of office-based and field work. Employees will spend prolonged periods sitting and performing computer-based tasks, including typing, data entry, and virtual communication, while also regularly traveling to landowner properties, project sites, and government facilities, some of which may be in rural or remote locations with limited accessibility. Driving is an essential function of the role and may involve extended periods and long-distance travel. Fieldwork may require walking over uneven terrain, standing, or navigating outdoor environments, with routine exposure to varying weather conditions such as heat, cold, rain, and snow. The role also involves frequent interaction with a diverse range of individuals, including landowners, government officials, and members of the public, requiring the ability to communicate effectively and maintain professionalism across differing personalities and potentially challenging situations. Flexibility in scheduling is necessary to accommodate travel, site access, and stakeholder availability, along with adherence to safety protocols in both office and field settings.

Apply on the employer’s site