Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Chief Information Security Officer (CISO)

$275k - $300k

Tract Capital

Chief Information Security Officer (CISO)Tract Capital Management and each of its individual investment strategies (Tract and Fleet Data Centers) are seeking a Chief Information Security Officer (CISO) to establish, mature, and govern the enterprise information security program. Reporting directly to the Chief Information Technology Officer (CITO), the CISO will own information security governance, compliance, risk management, and controls — ensuring that TCM's security posture satisfies the demands of institutional investors, hyperscale customers, regulatory bodies, and internal fiduciary obligations.This is a hands-on leadership position that requires deep expertise in building information security programs within complex, multi-entity investment structures. The CISO will work across corporate IT, operational technology (OT) environments, and third-party ecosystems to deliver a unified governance model that scales with TCM's rapid growth.Job ResponsibilitiesDesign and lead TCM's enterprise-wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800-53, covering corporate IT and OT environments across all entities.Establish and chair an Information Security Governance Committee with representation from TCM, Tract, and Fleet Data Centers — integrating into the existing risk committee structure chaired by the Chief Legal Officer (CLO).Own the information security policy framework across all entities, including the Acceptable Use Policy, AI Policy, Access Control Policy, Data Classification & Handling, Incident Response, and supporting Fleet policies (0034–0039).Drive the adoption and operationalization of ISO 27001 certification and ISO 42001 (AI Management System) across appropriate entities.Present security posture, risk exposure, and program maturity to the ELT Steering Committee (SteerCo), Risk Committees, and the CITO on a regular cadence.Serve as the authoritative voice on information security during investor operational due diligence (ODD) processes, responding to DDQs (e.g., Future Fund ORR, SIG questionnaires) and representing TCM's security posture to institutional investors.Build and operate the information security compliance program spanning TCM corporation, Tract (land/development), and Fleet Data Centers (critical infrastructure) — recognizing the distinct regulatory and contractual obligations of each strategy.Maintain and continuously improve alignment with applicable frameworks: ISO 27001, NIST 800-53, SOC 2 Type II, GDPR, CCPA, and customer-specific security requirements (hyperscaler contracts, FedRAMP where applicable).Own TCM's compliance posture scoring using Microsoft Purview Compliance Manager and equivalent tools, mapping internal controls to required frameworks.Partner with the CLO and outside counsel (Kirkland & Ellis) to ensure information security practices align with securities regulations, fiduciary obligations, fund LPA requirements, and evolving data privacy legislation.Manage the relationship with Trace3 Security Solutions and other third-party assessors for independent penetration testing, vulnerability assessments, and security audits conducted against NIST 800-115, OWASP, and MITRE ATT&CK methodologies.Ensure compliance with EU data protection requirements (GDPR, Schrems II) as TCM expands its European investment footprint through Tract II.Define, implement, and monitor information security controls at both the TCM enterprise level and within each investment strategy, ensuring appropriate segmentation and tailoring of controls to each entity's risk profile.Own the enterprise third-party / vendor risk management program in coordination with the Technology Requirements Checklist, evaluating all vendors against 50+ controls spanning Authentication & Identity, Security & Compliance Certifications, Data Residency & Protection, Integration & API Security, and Operational Resilience.Oversee data loss prevention (DLP), information classification, sensitivity labeling (Microsoft Purview), and data governance controls to protect investor data, financial information, deal pipeline data, proprietary design drawings, and other Confidential Information.Manage the enterprise identity and access management (IAM) governance in partnership with the IT team — including Entra ID Conditional Access policies, RBAC enforcement, SCIM lifecycle automation, and Privileged Identity Management (PIM).Lead the Insider Risk Management program using Microsoft 365 security stack capabilities, including behavioral analytics for data exfiltration, IP theft, and policy violations.Maintain and exercise the Incident Response Plan and Disaster Recovery / Business Continuity Plans, coordinating with the CITO, CLO, and risk committee chairs for incident classification, escalation, and investor/customer notification per contractual timelines.Govern the security awareness training program (KnowBe4), including phishing simulations, the Tract Capital Cyber Security Safety Guide, and new-hire security onboarding.Partner with Fleet's SVP of Physical, OT, & Cyber Security to align corporate IT security governance with converged physical/OT/cyber security operations at data center facilities.Collaborate with the CFO and finance organization on controls relevant to fund accounting, capital call processes, wire transfer security, and investor portal security.Support the CITO in AI governance, ensuring Enterprise-Approved AI Tools (e.g., Glean) operate within security and data governance guardrails and that the AI Policy is enforced.Interface with hyperscaler customer security teams to satisfy contractual security requirements and support customer due diligence processes.Work with Investor Relations to maintain DDQ-ready security documentation and ensure timely, accurate responses to ODD questionnaires.Basic QualificationsBachelor's degree in Information Security, Computer Science, Engineering, or related field.10+ years of progressive information security experience, with at least 5 years in a CISO, Deputy CISO, or equivalent senior security leadership role.Demonstrated experience building and maturing information security programs in private equity, asset management, or financial services environments with multi-entity / multi-fund structures.Deep working knowledge of ISO 27001, NIST 800-53, SOC 2 Type II, and demonstrated experience leading organizations through certification and audit processes.Expert-level understanding of data protection regulations (GDPR, CCPA) and their application to investment management firms with cross-border operations.Hands-on experience with Microsoft 365 security and compliance stack — Entra ID, Defender XDR, Purview (DLP, sensitivity labels, Insider Risk, Compliance Manager), Intune, and Conditional Access.Strong background in third-party risk management and vendor security assessment programs.Experience with incident response planning, execution, and post-incident reporting in environments with investor and regulatory notification obligations.Proven ability to communicate security posture and risk to executive leadership, boards, and institutional investors — including experience with investor ODD/DDQ processes.Preferred QualificationsExperience with critical infrastructure security, including OT/ICS environments (data centers, utilities, industrial).Familiarity with ISO 42001 (AI Management System) or demonstrated experience establishing AI governance frameworks.Experience supporting SEC-registered or SEC-exempt investment advisers and understanding of related compliance obligations.Knowledge of REIT structures, fund accounting controls, and the security considerations unique to real estate private equity.Experience with FedRAMP requirements as they relate to customer contractual obligations.Advanced degree (MBA, MS in Cybersecurity, or equivalent).Active certifications: CISSP, CISM, CISA, CRISC, or equivalent.CompetencyStrategic Vision — Ability to translate business strategy and growth trajectory into a scalable security program that enables, rather than constrains, the business.Multi-Entity Governance — Comfort operating across distinct legal entities with different risk profiles, regulatory postures, and operational models under a unified governance umbrella.Investor-Grade Communication — Experience presenting security posture and controls to sophisticated institutional investors (sovereign wealth funds, pensions, endowments) during due diligence.Hands-On Leadership — Willingness to operate at both the strategic and tactical level, particularly as the security function matures and scales.Collaborative Influence — Ability to drive outcomes across business units (TCM, Tract, Fleet) through influence rather than direct authority, partnering effectively with Legal, Finance, Operations, and Engineering stakeholders.Annual Compensation Range: $275,000-$300,000 Base

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the Chief Information Security Officer (CISO) in Denver, CO vacancy
  •  ...Chief Information Security Officer (CISO) About the Company Innovative provider of data safety & recovery solutions Industry Information Technology and Services Type Privately Held Founded 2024 Employees 51-200 Specialties cloud backup... 
    Suggested

    Confidential

    Denver, CO
    4 days ago
  •  ...Chief Information Security Officer (CISO), Information Security & Compliance About the Company Innovative artificial intelligence (AI) & marketing analytics platform Industry Information Technology and Services Type Public Company Founded 2014... 
    Suggested

    Confidential

    Denver, CO
    4 days ago
  •  ...Field Chief Information Security Officer (CISO) About the Company Industry leading provider of security & compliance solutions Industry Outsourcing/Offshoring Type Privately Held Founded 2020 Employees 501-1000 Funding $200+ million Categories... 
    Suggested
    Remote work

    Confidential

    Denver, CO
    2 days ago
  • $99.2k - $145k

     ...communities we serve.Bank of America is committed to an in-office culture that supports collaboration, engagement, and career...  ...opportunities to learn, grow, and make an impact. Join us!The Information Security Officer will be a member of the Business Information Security... 
    Suggested
    Full time
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Denver, CO
    4 days ago
  •  ...Information Security OfficerThe ISO will be responsible for protecting the bank's sensitive data,...  ...Reporting Structure: Reports to the SVP, Chief Information OfficerOffice Requirements:...  ...This position is required to be in the office 5 days per week. The position is open in... 
    Suggested
    Work at office

    Fortis Bank

    Denver, CO
    1 day ago
  • $99.2k - $145k

     ....Bank of America is committed to an in-office culture that supports collaboration, engagement...  ...an impact. Join us!Job Description:The Information Security Officer (ISO) will serve as a key...  ...with Global Banking & Markets (GBAM) Chief Information Officers (CIOs), Chief Technology... 
    Full time
    Work at office
    Flexible hours
    Day shift

    Bank of America

    Denver, CO
    4 days ago
  •  ...include, but not be limited to: Performing and/or managing Information Technology (IT) audits and security assessments in various industries with a focus in the...  ...with assessment/audit tools and Microsoft office suite.Superior attention to detail and conscientious... 
    Full time
    Work at office
    Flexible hours
    Night shift

    P&M Corporate Finance

    Denver, CO
    1 day ago
  •  ...Information Systems Security Officer (ISSO)We are seeking a detail-oriented and proactive Information Systems Security Officer (ISSO) to support and maintain the security of our information systems. In this role, you will be responsible for ensuring systems operate in... 
    Temporary work
    For contractors
    Immediate start

    Cymertek

    Aurora, CO
    1 day ago
  •  ...Information System Security OfficerWe are seeking a dedicated and detail-oriented Information System Security Officer (ISSO) to join our cybersecurity team. In this role, you will be responsible for maintaining the security posture of information systems, ensuring compliance... 
    Temporary work
    For contractors
    Immediate start

    Cymertek

    Aurora, CO
    3 days ago
  • $160k - $205k

     ...serve.Bank of America is committed to an in-office culture with specific requirements for...  ...is part of the Application Development Security Framework Program within Bank of America...  ...of internal and external threats on information systems and predict future threat behavior... 
    Full time
    Work at office
    Shift work
    Day shift

    Bank of America

    Denver, CO
    1 day ago
  •  ...Chief Trust Officer (CTO) About the Company Highly respected wealth management firm with boutique, client-centric service for sophisticated families. Industry Financial Services Type Privately Held About the Role The Company is in search of a Chief... 

    Confidential

    Denver, CO
    2 days ago
  • Congruex, a leader in broadband and wireless infrastructure, seeks a Project Manager, OSP to define scope, coordinate teams, and track progress for telecom projects in Denver, CO. The role requires experienced PM skills, strong SQL/Excel/Visio touchpoints, and a proven...

    Congruex LLC

    Denver, CO
    1 day ago
  •  ...Chief Impact Officer (CIO) About the Company International non-profit governing organization...  ...commercial fishing industry Industry Information Services Type Non Profit...  ...Specialties ocean conservation maritime security transparency data science... 
    Remote work
    Visa sponsorship

    Confidential

    Denver, CO
    2 days ago
  • $201.11k - $269.08k

     ...required to make them successful. They can engage credibly with Chief Data Officers, CIOs, Enterprise Architects, Data Governance leaders, and...  .... Please see our Candidate Privacy Statement for more information about how we use your personal data and your rights, including... 
    Full time
    Work at office

    Salesforce

    Denver, CO
    4 hours ago
  •  ...construction professionals. Build strong relationships with clients, consultants and industry partners. Identify, pursue and secure new business opportunities across Colorado. Take an active role in networking, client meetings and industry events. Oversee project... 

    Combined Selection Group Ltd

    Denver, CO
    1 day ago
  • $115.6k - $254.2k

     ...Senior Cyber Threat AnalystJob Category: Information TechnologyTime Type: Full timeMinimum...  ...LocalAnticipated Posting End: 9/30/2026Senior Cyber Security Analyst - 3rd Shift (Monday-Friday, 3 PM...  ....Frequent use of computers and standard office equipment.Regular communication with... 
    Contract work
    Work experience placement
    Work at office
    Immediate start
    Monday to Friday
    Flexible hours
    Night shift

    CACI International

    Aurora, CO
    4 days ago
  • $105.4k - $207.8k

     ...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for this...  ...:Bachelor's degree in Computer Science, Engineering, Information Technology, Cybersecurity, or equivalent demonstrated experience... 
    Local area
    Visa sponsorship

    Deloitte

    Denver, CO
    4 days ago
  • $105.4k - $207.8k

     ...Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to...  ...Qualifications Bachelor's degree in Computer Science, Cybersecurity, Information Technology, Engineering, Information Systems, or a related... 
    Local area
    Worldwide
    Visa sponsorship

    Deloitte

    Denver, CO
    4 days ago
  • $97.61k - $188.38k

     ...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 10/31/2026Work you’ll...  ...configure, and deploy Saviynt.Understand complex business and information technology management processes. Execute advanced services and... 
    Local area
    Visa sponsorship

    Deloitte

    Denver, CO
    4 days ago
  • $105.4k - $207.8k

     ...navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support...  ..., and resilient Google SecOps architectures for security information and event management (SIEM) and security orchestration, automation... 
    Local area
    Visa sponsorship

    Deloitte

    Denver, CO
    4 days ago
  • $105.4k - $207.8k

     ...Consultant - Cyber Defense and Resilience, you will help deliver security engineering solutions that modernize client security...  ...stakeholders to design and implement solutions across security information and event management, security orchestration automation and response... 
    Local area
    Visa sponsorship

    Deloitte

    Denver, CO
    3 days ago
  •  ...Managing Director, Chief Technology Officers Practice, Retained Search About the Company Dynamic executive search firm specializing in...  ...responsibilities. The position is pivotal in helping clients make informed leadership decisions and is suited to individuals who... 

    Confidential

    Denver, CO
    1 day ago
  •  ...Deputy Chief Technology Officer (CTO) About the Company Top-tier investment bank Industry Investment Banking Type Public Company...  ...scenarios. Hiring Manager Title CIO/CTO Functions Engineering Information Technology Confidential

    Confidential

    Denver, CO
    3 days ago
  •  ...Deputy Chief Technology Officer (CTO) About the Company Prominent political organization Industry...  ...the Chief Technology Officer, Chief Security Officer, and Heads of Data &...  ...Technology Officer Functions Engineering Information Technology Confidential
    Remote work

    Confidential

    Denver, CO
    5 days ago
  •  ...Regional Field Chief Technology Officer (CTO) About the Company Globally recognized provider of automated solutions for securing & managing open source software Industry Computer...  ...to translate complex technical information into clear narratives for both technical... 

    Confidential

    Denver, CO
    3 days ago
  • $300k - $350k

     ...million customers worldwide.* For more information, visit transamerica.com.  Job Description...  ...governance and management, and ensuring the security and stability of the company’s...  ...geography, work location designation (in-office, hybrid, remote) and operational needs.... 
    Full time
    Contract work
    Work experience placement
    Work at office
    Remote work
    Work from home
    Worldwide
    Visa sponsorship
    Flexible hours

    Transamerica

    Denver, CO
    3 days ago
  • $79k - $108k

     ...Degree and 3 years of relevant work experience Bachelor's Degree and 0-2 years of relevant work experience Experience in cyber security with a focus on red teaming, penetration testing, or threat hunting Why Join Cyber Defense Technologies? At CDT, we offer a collaborative... 
    Work experience placement

    Cyber Defense Technologies

    Denver, CO
    3 days ago
  •  ...OUR STORY TechInsights is the information Platform for the semiconductor industry....  ...center of that transformation is the Chief Technology Officer. As a member of the Executive Leadership...  ...Product, Sales, Operations, and Security & AI Governance to prioritize technology... 
    Permanent employment
    Work at office
    Remote work
    Flexible hours

    TechInsights

    Denver, CO
    5 days ago
  • $250k - $300k

     ...Chief Technology Officer East Daley Analytics is building the energy market intelligence platform...  ...foundation into a scalable, modern, secure, and extensible technology platform that...  ...ML capabilities inside a trusted B2B information product. This is a rare... 
    Temporary work
    Work at office
    Flexible hours

    East Daley Analytics

    Greenwood Village, CO
    2 days ago
  • $32 - $37 per hour

    Colorado State University Global invites applications for a part-time Course Instructor in Computer Science. You will conduct online courses, ensuring quality delivery aligned with university standards. We're looking for candidates with a Doctorate, extensive industry knowledge...
    Remote job
    Hourly pay
    Part time

    Colorado State University Global

    Denver, CO
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Chief Information Security Officer (CISO). Be the first to apply!