Chief Information Security Officer (CISO)
$300–$275,000 year
On-siteDenver, Colorado, United States
Job Summary
Design and lead the enterprise-wide Information Security Management System aligned to ISO/IEC 27001 and NIST 800-53 across corporate IT and OT environments. Establish the Information Security Governance Committee and own the policy framework covering access control, data classification, incident response, and AI governance. Present security posture and risk exposure to the ELT Steering Committee and institutional investors during due diligence. Build and operate the compliance program spanning TCM, Tract, and Fleet Data Centers, maintaining alignment with GDPR, CCPA, and customer-specific requirements. Manage third-party vendor risk assessments, oversee identity and access management, and lead the insider risk and incident response programs.
Required Qualifications
- Bachelor's degree in Information Security, Computer Science, Engineering, or related field
- 10+ years of progressive information security experience
- At least 5 years in a CISO, Deputy CISO, or equivalent senior security leadership role
- Demonstrated experience building and maturing information security programs in private equity, asset management, or financial services environments with multi-entity / multi-fund structures
- Deep working knowledge of ISO 27001, NIST 200-53, SOC 2 Type II
- Demonstrated experience leading organizations through certification and audit processes
- Expert-level understanding of data protection regulations (GDPR, CCPA)
- Application of data protection regulations to investment management firms with cross-border operations
- Hands-on experience with Microsoft 365 security and compliance stack — Entra ID, Defender XDR, Purview (DLP, sensitivity labels, Insider Risk, Compliance Manager), Intune, and Conditional Access
- Strong background in third-party risk management and vendor security assessment programs
- Experience with incident response planning, execution, and post-incident reporting in environments with investor and regulatory notification obligations
- Proven ability to communicate security posture and risk to executive leadership, boards, and institutional investors
- Experience with investor ODD/DDQ processes
Desired Qualifications
- Experience with critical infrastructure security, including OT/ICS environments (data centers, utilities, industrial)
- Familiarity with ISO 42001 (AI Management System)
- Demonstrated experience establishing AI governance frameworks
- Experience supporting SEC-registered or SEC-exempt investment advisers
- Understanding of related compliance obligations for SEC-registered or SEC-exempt investment advisers
- Knowledge of REIT structures, fund accounting controls, and the security considerations unique to real estate private equity
- Experience with FedRAMP requirements as they relate to customer contractual obligations
- Advanced degree (MBA, MS in Cybersecurity, or equivalent)
- Active certifications: CISSP, CISM, CISA, CRISC, or equivalent
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.