Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Chief Information Security Officer (CISO)

$275k - $300k

Tract Capital Management, LP

Chief Information Security Officer (CISO)

About this position

Overview

Tract Capital adopts a unique approach to digital infrastructure investment. Leveraging experience and strategic insights honed over three decades of creating successful companies in the space, we excel in nurturing and advancing leading‑edge digital infrastructure enterprises. Our team of specialized experts is united by a singular purpose: to support the growth of digital infrastructure. Tract Capital goes beyond simple investment by acting as a strategic partner and catalyst for innovation within the sector, ensuring our engagements generate strong financial results while developing essential digital infrastructure to meet growing demands. We have introduced two digital infrastructure strategies: a horizontal, powered‑land strategy focused on creating master‑planned data center campuses called Tract, and a mega‑campus vertical development strategy called Fleet Data Centers.

Position Overview

The Chief Information Security Officer (CISO) is a senior leadership role responsible for establishing, maturing, and governing the enterprise information security program across Tract Capital Management and each of its individual investment strategies (Tract and Fleet Data Centers). Reporting directly to the CITO, the CISO will own information security governance, compliance, risk management, and controls, ensuring that TCM’s security posture satisfies the demands of institutional investors, hyperscale customers, regulatory bodies, and internal fiduciary obligations.

This hands‑on leadership position requires deep expertise in building information security programs within complex, multi‑entity investment structures. The CISO will work across corporate IT, operational technology (OT) environments, and third‑party ecosystems to deliver a unified governance model that scales with TCM’s rapid growth.

Job Responsibilities

Information Security Governance

  • Design and lead TCM’s enterprise‑wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800‑53, covering corporate IT and OT environments across all entities.
  • Establish and chair an Information Security Governance Committee with representation from TCM, Tract, and Fleet Data Centers, integrating into the existing risk committee structure chaired by the Chief Legal Officer.
  • Own the information security policy framework across all entities, including the Acceptable Use Policy, AI Policy, Access Control Policy, Data Classification & Handling, Incident Response, and supporting Fleet policies (0034–0039).
  • Drive the adoption and operationalization of ISO 27001 certification and ISO 42001 (AI Management System) across appropriate entities.
  • Present security posture, risk exposure, and program maturity to the ELT Steering Committee (SteerCo), Risk Committees, and the CITO on a regular cadence.
  • Serve as the authoritative voice on information security during investor operational due diligence (ODD) processes, responding to DDQs (e.g., Future Fund ORR, SIG questionnaires) and representing TCM’s security posture to institutional investors.

Compliance & Regulatory

  • Build and operate the information security compliance program spanning TCM corporation, Tract (land/development), and Fleet Data Centers (critical infrastructure), recognizing the distinct regulatory and contractual obligations of each strategy.
  • Maintain and continuously improve alignment with applicable frameworks: ISO 27001, NIST 800‑53, SOC 2 Type II, GDPR, CCPA, and customer‑specific security requirements (hyperscaler contracts, FedRAMP where applicable).
  • Own TCM’s compliance posture scoring using Microsoft Purview Compliance Manager and equivalent tools, mapping internal controls to required frameworks.
  • Partner with the CLO and outside counsel (Kirkland & Ellis) to ensure information security practices align with securities regulations, fiduciary obligations, fund LPA requirements, and evolving data privacy legislation.
  • Manage the relationship with Trace3 Security Solutions and other third‑party assessors for independent penetration testing, vulnerability assessments, and security audits conducted against NIST 800‑115, OWASP, and MITRE ATT&CK methodologies.
  • Ensure compliance with EU data protection requirements (GDPR, Schrems II) as TCM expands its European investment footprint through Tract II.

Controls & Risk Management

  • Define, implement, and monitor information security controls at both the TCM enterprise level and within each investment strategy, ensuring appropriate segmentation and tailoring of controls to each entity’s risk profile.
  • Own the enterprise third‑party / vendor risk management program in coordination with the Technology Requirements Checklist, evaluating all vendors against 50+ controls spanning Authentication & Identity, Security & Compliance Certifications, Data Residency & Protection, Integration & API Security, and Operational Resilience.
  • Oversee data loss prevention (DLP), information classification, sensitivity labeling (Microsoft Purview), and data governance controls to protect investor data, financial information, deal pipeline data, proprietary design drawings, and other confidential information.
  • Manage the enterprise identity and access management (IAM) governance in partnership with the IT team — including Entra ID Conditional Access policies, RBAC enforcement, SCIM lifecycle automation, and Privileged Identity Management (PIM).
  • Lead the Insider Risk Management program using Microsoft 365 security stack capabilities, including behavioral analytics for data exfiltration, IP theft, and policy violations.
  • Maintain and exercise the Incident Response Plan and Disaster Recovery / Business Continuity Plans, coordinating with the CITO, CLO, and risk committee chairs for incident classification, escalation, and investor/customer notification per contractual timelines.
  • Govern the security awareness training program (KnowBe4), including phishing simulations, the Tract Capital Cyber Security Safety Guide, and new‑hire security onboarding.

Collaboration & Stakeholder Management

  • Partner with Fleet’s SVP of Physical, OT, & Cyber Security to align corporate IT security governance with converged physical/OT/cyber security operations at data center facilities.
  • Collaborate with the CFO and finance organization on controls relevant to fund accounting, capital call processes, wire transfer security, and investor portal security.
  • Support the CITO in AI governance, ensuring Enterprise‑Approved AI Tools (e.g., Glean) operate within security and data governance guardrails and that the AI Policy is enforced.
  • Interface with hyperscaler customer security teams to satisfy contractual security requirements and support customer due diligence processes.
  • Work with Investor Relations to maintain DDQ‑ready security documentation and ensure timely, accurate responses to ODD questionnaires.

Basic Qualifications

  • Bachelor’s degree in Information Security, Computer Science, Engineering, or related field.
  • 10+ years of progressive information security experience, with at least 5 years in a CISO, Deputy CISO, or equivalent senior security leadership role.
  • Demonstrated experience building and maturing information security programs in private equity, asset management, or financial services environments with multi‑entity / multi‑fund structures.
  • Deep working knowledge of ISO 27001, NIST 800‑53, SOC 2 Type II, and demonstrated experience leading organizations through certification and audit processes.
  • Expert‑level understanding of data protection regulations (GDPR, CCPA) and their application to investment management firms with cross‑border operations.
  • Hands‑on experience with Microsoft 365 security and compliance stack — Entra ID, Defender XDR, Purview (DLP, sensitivity labels, Insider Risk, Compliance Manager), Intune, and Conditional Access.
  • Strong background in third‑party risk management and vendor security assessment programs.
  • Experience with incident response planning, execution, and post‑incident reporting in environments with investor and regulatory notification obligations.
  • Proven ability to communicate security posture and risk to executive leadership, boards, and institutional investors — including experience with investor ODD/DDQ processes.

Preferred Qualifications

  • Experience with critical infrastructure security, including OT/ICS environments (data centers, utilities, industrial).
  • Familiarity with ISO 42001 (AI Management System) or demonstrated experience establishing AI governance frameworks.
  • Experience supporting SEC‑registered or SEC‑exempt investment advisers and understanding of related compliance obligations.
  • Knowledge of REIT structures, fund accounting controls, and the security considerations unique to real estate private equity.
  • Experience with FedRAMP requirements as they relate to customer contractual obligations.
  • Advanced degree (MBA, MS in Cybersecurity, or equivalent).
  • Active certifications: CISSP, CISM, CISA, CRISC, or equivalent.

Competency

  • Strategic Vision — Ability to translate business strategy and growth trajectory into a scalable security program that enables, rather than constrains, the business.
  • Multi‑Entity Governance — Comfort operating across distinct legal entities with different risk profiles, regulatory postures, and operational models under a unified governance umbrella.
  • Investor‑Grade Communication — Experience presenting security posture and controls to sophisticated institutional investors during due diligence.
  • Hands‑On Leadership — Willingness to operate at both strategic and tactical level, particularly as the security function matures and scales.
  • Collaborative Influence — Ability to drive outcomes across business units (TCM, Tract, Fleet) through influence rather than direct authority, partnering effectively with Legal, Finance, Operations, and Engineering stakeholders.

Annual Compensation Range

$275,000 – $300,000 Base Salary + Discretionary Bonus.

Tract Capital Employment

Employees enjoy competitive compensation and comprehensive benefits, including 100% employer‑covered medical, dental, and vision insurance, a 401(k) program, standard paid holidays, and unlimited PTO.

Equal Opportunity Employer

Tract Capital is proud to be an Equal Opportunity Employer. Qualified applicants are considered for employment regardless of age, race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or veteran status. If you need assistance applying for any of our open positions, please contact us at View email address on click.appcast.io.

#J-18808-Ljbffr

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Chief Information Security Officer (CISO) in Denver, CO vacancy
  •  ...Chief Information Security Officer (CISO) About the Company Fast-growing provider of energy-efficient data center services Industry Financial Services Type Privately Held Employees 11-50 About the Role The Company is seeking a Chief Information... 
    Suggested

    Confidential

    Denver, CO
    4 days ago
  •  ...Chief Information Security Officer (CISO) About the Company Trusted provider & publisher of consumer insights about car models & auto brands Industry Market Research Type Privately Held, Private Equity-backed Founded 1968 Employees 1001-5000... 
    Suggested

    Confidential

    Denver, CO
    1 day ago
  •  ...Chief Impact Officer (CIO) About the Company International non-profit governing organization...  ...commercial fishing industry Industry Information Services Type Non Profit...  ...Specialties ocean conservation maritime security transparency data science... 
    Suggested
    Remote work
    Visa sponsorship

    Confidential

    Denver, CO
    1 day ago
  • $160k - $205k

     ...Manual Ethical Hacking is part of the Application Development Security Framework Program within Bank of America's Cyber Security Assurance...  ...Perform assigned analysis of internal and external threats on information systems and predict future threat behavior. Incorporate threat... 
    Suggested
    Shift work
    Day shift

    Koitecc Solutions

    Denver, CO
    1 day ago
  • $79k - $108k

     ...Degree and 3 years of relevant work experience Bachelor's Degree and 0-2 years of relevant work experience Experience in cyber security with a focus on red teaming, penetration testing, or threat hunting Why Join Cyber Defense Technologies? At CDT, we offer a... 
    Suggested
    Work experience placement

    Cyber Defense Technologies

    Denver, CO
    1 day ago
  • Cyber Defense Technologies is seeking a Junior Penetration Tester to support a government customer in Denver, Colorado. Candidates must have an active Top Secret/SCI clearance and preferably OSCP certification. The role involves performing vulnerability scanning, identifying...

    Cyber Defense Technologies

    Denver, CO
    2 days ago
  •  ...GuidePoint Security provides trusted cybersecurity expertise, solutions and services that...  ...security event and incident correlation using information gathered from a variety of sources...  ...to occasionally move about inside the office to access file cabinets, office... 
    Full time
    For contractors
    Work at office
    Remote work
    Flexible hours
    Shift work

    Guidepoint Security

    Aurora, CO
    14 hours ago
  •  ...Deputy Chief Technology Officer (CTO) About the Company Prominent political organization...  ...the Chief Technology Officer, Chief Security Officer, and Heads of Data & Engineering...  ...Chief Technology Officer Functions Engineering Information Technology... 
    Remote work

    Confidential

    Denver, CO
    3 days ago
  • $60k - $90k

     ...as well as ensuring that you have the financial stability and security to think long term. Underpinning all of this is a clear set of...  ...an innovative force, where healthcare meets retail. For more information, visit   Business Structure The Joint Corp. is a franchisor... 
    Full time
    Part time

    The Joint Chiropractic

    Aurora, CO
    1 day ago
  • $85k - $105k

     ...k per year (depending on experience and position) Benefits: • PTO|Vacation and Paid Holidays • Health Insurance with HSA • Free in office chiropractic care for employee and their immediate family and employee discounts • IRA • Professional advancement with potential buy... 
    Full time
    Work at office
    Immediate start

    National Coalition of Healthcare Recruiters

    Thornton, CO
    5 days ago
  •  ...Deputy Chief Technology Officer (CTO) About the Company Top-tier investment bank Industry Investment Banking Type Public Company...  ...scenarios. Hiring Manager Title CIO/CTO Functions Engineering Information Technology Confidential

    Confidential

    Denver, CO
    2 days ago
  • $190k - $205k

     ...applications, operational technology, and end‑user support across a portfolio of operational offices. Director of Information Technology (IT) Location: Denver, Colorado Reports To: Chief Innovation Officer Direct Reports: 4 IT Team Members In addition to managing day‑to‑day... 
    Temporary work
    Flexible hours

    National Corporate Housing

    Greenwood Village, CO
    4 days ago
  •  ...as long-term performance, reliability, security, and scalability. Administer and improve...  ...controls, retention, quality) and promote data-informed decision-making. Oversee physical-...  ...driven style — eager to step away from the office and partner with colleagues across... 
    Full time
    Temporary work
    Summer holiday
    Work at office
    Remote work
    Afternoon shift
    3 days per week

    The Association of Colorado Independent Schools

    Denver, CO
    5 days ago
  • $160k - $194k

    Overview Gartner Executive Programs (ExP) is a service within Gartner Executive Technology Services (ETS) and is the indispensable tool for digital leaders. It is an exclusive, membership‑based organization serving over 8,500 CIOs and senior IT leaders across 87 countries...
    Worldwide

    Gartner

    Denver, CO
    1 day ago
  •  ...Chief Mission Officer (CMO) About the Company Acclaimed voluntary health organization supporting the research of terminal conditions...  ...ensuring that the lived experiences of individuals and families inform decision-making. The CMO will also be the external... 
    Summer work

    Confidential

    Denver, CO
    5 days ago
  • $32 - $37 per hour

    Colorado State University Global invites applications for a part-time Course Instructor in Computer Science. You will conduct online courses, ensuring quality delivery aligned with university standards. We're looking for candidates with a Doctorate, extensive industry knowledge...
    Remote job
    Hourly pay
    Part time

    Colorado State University Global

    Denver, CO
    1 day ago
  •  ...Chief Technology Officer (CTO) About the Company Industry-leading provider of technology intelligence & IP services Industry Information Services Type Privately Held, VC-backed Founded 1989 Employees 201-500 Specialties... 

    Confidential

    Denver, CO
    1 day ago
  • $250k - $300k

     ...Chief Technology Officer East Daley Analytics is building the energy market intelligence platform...  ...foundation into a scalable, modern, secure, and extensible technology platform that...  ...ML capabilities inside a trusted B2B information product. This is a rare... 
    Temporary work
    Work at office
    Flexible hours

    East Daley Analytics

    Greenwood Village, CO
    14 hours ago
  •  ...OUR STORY TechInsights is the information Platform for the semiconductor industry....  ...center of that transformation is the Chief Technology Officer. As a member of the Executive Leadership...  ...Product, Sales, Operations, and Security & AI Governance to prioritize technology... 
    Permanent employment
    Work at office
    Remote work
    Flexible hours

    TechInsights

    Denver, CO
    4 days ago
  •  ...Chief Technology Officer (CTO) About the Company High-growth enterprise SaaS company serving...  ...leading an organization that builds secure, scalable, cloud-native software. Key...  ...commitment to the role. Functions Engineering Information Technology Confidential

    Confidential

    Denver, CO
    2 days ago
  •  ...Chief Technology Officer (CTO) About the Company Esteemed philanthropic organization empowering teachers to teach consumer-related programs...  ...education. Hiring Manager Title President and CEO Functions Engineering Information Technology Confidential

    Confidential

    Denver, CO
    2 days ago
  •  ...Chief Technology Officer (CTO) About the Company Prominent financial services firm specializing in investment management, research & trading...  ...responsible for the delivery of cloud-native applications, secure infrastructure, and automation pipelines to support agile... 

    Confidential

    Denver, CO
    4 days ago
  •  ...Chief Technology Officer (CTO) About the Company Emerging defense technology company Industry...  ...inference frameworks and edge acceleration technologies. Security clearance or eligibility is also a plus. Functions Engineering Information Technology Confidential

    Confidential

    Denver, CO
    4 days ago
  •  ...Chief Technology Officer (CTO) About the Company Fast-growing retail & e-commerce company...  ...overseeing IT and infrastructure to ensure a secure, reliable, and high-uptime...  ...performance and conversion. Functions Engineering Information Technology Confidential

    Confidential

    Denver, CO
    14 hours ago
  •  ...Chief Technology Officer (CTO) About the Company Venture-backed fintech startup. Industry...  ...responsible for ensuring the reliability, security, and scalability of the products, as...  ...-edge technology. Functions Engineering Information Technology Confidential

    Confidential

    Denver, CO
    14 hours ago
  •  ...Chief Information Officer (CIO) About the Company Prominent government agency Industry Government Administration Type Government Agency Founded 1956 Employees 1001-5000 About the Role The Company is seeking a Chief Information... 

    Confidential

    Thornton, CO
    5 days ago
  •  ...Chief Technology Officer (CTO) About the Company Growing enterprise SaaS company delivering AI-enabled software for Fortune 500 customers...  ...teams and drive the adoption of modern AI technologies. Functions Engineering Information Technology Confidential

    Confidential

    Denver, CO
    3 days ago
  •  ...Chief Technology Officer (CTO) About the Company Respectable philanthropic organization Industry Non-Profit...  ...to reach more communities and make better-informed decisions. The CTO will also be tasked with security and AI governance, as well as growing and leading... 
    Hourly pay

    Confidential

    Denver, CO
    4 days ago
  •  ...Chief Technology Officer (CTO) About the Company Pioneering media company focused on news & educational information about financial technology & cryptocurrency Industry Newspapers...  ...team, and ensuring the platform is secure, compliant, and ready for enterprise... 

    Confidential

    Denver, CO
    1 day ago
  •  ...Chief Information Officer (CIO) About the Company Innovative Web3 infrastructure startup Industry Internet Type Privately...  ...'s mission to create a decentralized identity that is secure, interoperable, and user-friendly across various digital platforms... 

    Confidential

    Denver, CO
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Chief Information Security Officer (CISO). Be the first to apply!