1

Ciso Jobs in Colorado (NOW HIRING)

They will partner directly with the CISO, CRO, Head of CoE, and the broader organization to ensure that all AI use cases across the enterprise are identified, assessed, controlled, and deployed in a ...

... CISO (Chief Information Security Officer) of Client • Organizing and providing support and training. • Managing, developing, and motivating the IT team • Coordinating, developing, and ...

Comfortable selling to senior leaders - CTO, CISO, VP of engineering, head of IT * Experience using Gong, Salesforce, or similar, to collaborate internally and manage pipeline * Experience partnering ...

At Axos, our CISO organization is pioneering an AI-native security operations model. You will be expected to think like a builder, not just an operator. You will create AI agents that do repetitive ...

Vice President, Information Security

Denver, CO · On-site

$161K - $202K/yr

We are looking for a VP, Information Security (CISO) to drive our company forward, and help us lead the clean energy revolution! We are seeking a strategic VP, Information Security (CISO) to lead our ...

Vice President, Information Security

Boulder, CO · On-site

$165K - $206K/yr

We are looking for a VP, Information Security (CISO) to drive our company forward, and help us lead the clean energy revolution! We are seeking a strategic VP, Information Security (CISO) to lead our ...

next page

Showing results 1-20

Ciso information

See Colorado salary details

$52K

$115K

$165.6K

How much do ciso jobs pay per year?

As of Aug 2, 2026, the average yearly pay for ciso in Colorado is $114,986.00, according to ZipRecruiter salary data. Most workers in this role earn between $88,900.00 and $143,000.00 per year, depending on experience, location, and employer.

What is the difference between Ciso vs Security Manager?

AspectCisoSecurity Manager
CredentialsOften requires CISSP, CISM, or CISA certificationsTypically holds CISSP, Security+, or similar certifications
Work EnvironmentStrategic, executive-level, overseeing entire security postureOperational, managing security teams and implementing policies
Employer & Industry UsageUsed in large organizations, corporations, and government agenciesCommon in mid-sized to large companies across various industries
Search & Comparison IntentFocuses on high-level security leadershipFocuses on day-to-day security operations

The Ciso (Chief Information Security Officer) is a senior executive responsible for the overall security strategy, while a Security Manager handles daily security operations and team management. Both roles require relevant certifications and are vital in organizational security, but they differ in scope and strategic focus.

Can you make $200,000 in cyber security?

A Chief Information Security Officer (CISO) can earn $200,000 or more annually, especially with extensive experience, certifications like CISSP, and working in large organizations or high-demand industries. Salary levels depend on factors such as location, company size, and individual expertise, with senior cybersecurity roles often reaching or exceeding this figure.

What are the key skills and qualifications needed to thrive as a Chief Information Security Officer (CISO), and why are they important?

To thrive as a Chief Information Security Officer (CISO), you need deep expertise in information security, risk management, and regulatory compliance, typically supported by a degree in computer science or a related field and extensive experience in cybersecurity leadership. Familiarity with security frameworks (such as NIST, ISO 27001), incident response platforms, and certifications like CISSP or CISM are highly valued. Strong leadership, strategic thinking, and communication skills set top CISOs apart, enabling them to influence organizational culture and bridge gaps between technical and executive teams. These skills ensure effective protection of organizational assets, regulatory compliance, and resilience against evolving cyber threats.

What are the most common challenges faced by a Chief Information Security Officer (CISO) when aligning security initiatives with business objectives?

A CISO often faces the challenge of balancing robust security measures with the need for business agility and innovation. This includes translating technical risks into business terms that stakeholders understand and ensuring security initiatives support, rather than hinder, business goals. CISOs must also navigate competing priorities, manage limited resources, and foster a security-aware culture across departments. Regular collaboration with executive leadership and other business units is essential to align security strategies with organizational objectives and demonstrate the value of security investments.

What Does a CISO Do?

A chief information security officer (CISO) is an executive who ensures that the information, communications, and computer infrastructure of a company or organization remain secure. In this position, you are responsible for the overall information security strategy of your employer. Your responsibilities focus on ensuring that security measures are sufficient throughout the organization and that they meet operational needs and address current cybersecurity threats. Your duties include making high-level decisions about security practices, threat response strategies, and liaising with law enforcement and investigative agencies if necessary. You also ensure compliance with information privacy regulations.

What is the average salary for a CISO?

The average salary for a Chief Information Security Officer (CISO) typically ranges from $150,000 to $250,000 annually, depending on the industry, company size, and location. CISOs often have extensive experience in cybersecurity, leadership skills, and certifications such as CISSP or CISM, which can influence compensation levels.

What does a CISO do?

A Chief Information Security Officer (CISO) is responsible for developing and implementing an organization’s cybersecurity strategy, managing security policies, and overseeing risk management efforts. They coordinate security teams, ensure compliance with regulations, and often work with executive leadership to protect digital assets and infrastructure.

Is CISO a high paying job?

A Chief Information Security Officer (CISO) is typically a high-paying executive role, with salaries often exceeding six figures and varying based on industry, company size, and experience. CISOs are responsible for an organization's cybersecurity strategy and often require advanced certifications and extensive experience.
What are the most commonly searched types of Ciso jobs in Colorado? The most popular types of Ciso jobs in Colorado are:
What cities in Colorado are hiring for Ciso jobs? Cities in Colorado with the most Ciso job openings:
Infographic showing various Ciso job openings in Colorado as of July 2026, with employment types broken down into 92% Full Time, 6% Part Time, and 2% Contract. Highlights an 75% Physical, 6% Hybrid, and 19% Remote job distribution, with an average salary of $114,986 per year, or $55.3 per hour.

Chief Information Security Officer (CISO)

Tract Capital Management, LP

Denver, CO • On-site

$275 - $300/hr

Other

Medical, Dental, Vision, Retirement, PTO

Posted 10 days ago


Job description

Chief Information Security Officer (CISO) About this position Overview

Tract Capital adopts a unique approach to digital infrastructure investment. Leveraging experience and strategic insights honed over three decades of creating successful companies in the space, we excel in nurturing and advancing leading‑edge digital infrastructure enterprises. Our team of specialized experts is united by a singular purpose: to support the growth of digital infrastructure. Tract Capital goes beyond simple investment by acting as a strategic partner and catalyst for innovation within the sector, ensuring our engagements generate strong financial results while developing essential digital infrastructure to meet growing demands. We have introduced two digital infrastructure strategies: a horizontal, powered‑land strategy focused on creating master‑planned data center campuses called Tract, and a mega‑campus vertical development strategy called Fleet Data Centers.

Position Overview

The Chief Information Security Officer (CISO) is a senior leadership role responsible for establishing, maturing, and governing the enterprise information security program across Tract Capital Management and each of its individual investment strategies (Tract and Fleet Data Centers). Reporting directly to the CITO, the CISO will own information security governance, compliance, risk management, and controls, ensuring that TCM’s security posture satisfies the demands of institutional investors, hyperscale customers, regulatory bodies, and internal fiduciary obligations.

This hands‑on leadership position requires deep expertise in building information security programs within complex, multi‑entity investment structures. The CISO will work across corporate IT, operational technology (OT) environments, and third‑party ecosystems to deliver a unified governance model that scales with TCM’s rapid growth.

Job Responsibilities Information Security Governance
  • Design and lead TCM’s enterprise‑wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800‑53, covering corporate IT and OT environments across all entities.
  • Establish and chair an Information Security Governance Committee with representation from TCM, Tract, and Fleet Data Centers, integrating into the existing risk committee structure chaired by the Chief Legal Officer.
  • Own the information security policy framework across all entities, including the Acceptable Use Policy, AI Policy, Access Control Policy, Data Classification & Handling, Incident Response, and supporting Fleet policies (0034–0039).
  • Drive the adoption and operationalization of ISO 27001 certification and ISO 42001 (AI Management System) across appropriate entities.
  • Present security posture, risk exposure, and program maturity to the ELT Steering Committee (SteerCo), Risk Committees, and the CITO on a regular cadence.
  • Serve as the authoritative voice on information security during investor operational due diligence (ODD) processes, responding to DDQs (e.g., Future Fund ORR, SIG questionnaires) and representing TCM’s security posture to institutional investors.
Compliance & Regulatory
  • Build and operate the information security compliance program spanning TCM corporation, Tract (land/development), and Fleet Data Centers (critical infrastructure), recognizing the distinct regulatory and contractual obligations of each strategy.
  • Maintain and continuously improve alignment with applicable frameworks: ISO 27001, NIST 800‑53, SOC 2 Type II, GDPR, CCPA, and customer‑specific security requirements (hyperscaler contracts, FedRAMP where applicable).
  • Own TCM’s compliance posture scoring using Microsoft Purview Compliance Manager and equivalent tools, mapping internal controls to required frameworks.
  • Partner with the CLO and outside counsel (Kirkland & Ellis) to ensure information security practices align with securities regulations, fiduciary obligations, fund LPA requirements, and evolving data privacy legislation.
  • Manage the relationship with Trace3 Security Solutions and other third‑party assessors for independent penetration testing, vulnerability assessments, and security audits conducted against NIST 800‑115, OWASP, and MITRE ATT&CK methodologies.
  • Ensure compliance with EU data protection requirements (GDPR, Schrems II) as TCM expands its European investment footprint through Tract II.
Controls & Risk Management
  • Define, implement, and monitor information security controls at both the TCM enterprise level and within each investment strategy, ensuring appropriate segmentation and tailoring of controls to each entity’s risk profile.
  • Own the enterprise third‑party / vendor risk management program in coordination with the Technology Requirements Checklist, evaluating all vendors against 50+ controls spanning Authentication & Identity, Security & Compliance Certifications, Data Residency & Protection, Integration & API Security, and Operational Resilience.
  • Oversee data loss prevention (DLP), information classification, sensitivity labeling (Microsoft Purview), and data governance controls to protect investor data, financial information, deal pipeline data, proprietary design drawings, and other confidential information.
  • Manage the enterprise identity and access management (IAM) governance in partnership with the IT team — including Entra ID Conditional Access policies, RBAC enforcement, SCIM lifecycle automation, and Privileged Identity Management (PIM).
  • Lead the Insider Risk Management program using Microsoft 365 security stack capabilities, including behavioral analytics for data exfiltration, IP theft, and policy violations.
  • Maintain and exercise the Incident Response Plan and Disaster Recovery / Business Continuity Plans, coordinating with the CITO, CLO, and risk committee chairs for incident classification, escalation, and investor/customer notification per contractual timelines.
  • Govern the security awareness training program (KnowBe4), including phishing simulations, the Tract Capital Cyber Security Safety Guide, and new‑hire security onboarding.
Collaboration & Stakeholder Management
  • Partner with Fleet’s SVP of Physical, OT, & Cyber Security to align corporate IT security governance with converged physical/OT/cyber security operations at data center facilities.
  • Collaborate with the CFO and finance organization on controls relevant to fund accounting, capital call processes, wire transfer security, and investor portal security.
  • Support the CITO in AI governance, ensuring Enterprise‑Approved AI Tools (e.g., Glean) operate within security and data governance guardrails and that the AI Policy is enforced.
  • Interface with hyperscaler customer security teams to satisfy contractual security requirements and support customer due diligence processes.
  • Work with Investor Relations to maintain DDQ‑ready security documentation and ensure timely, accurate responses to ODD questionnaires.
Basic Qualifications
  • Bachelor’s degree in Information Security, Computer Science, Engineering, or related field.
  • 10+ years of progressive information security experience, with at least 5 years in a CISO, Deputy CISO, or equivalent senior security leadership role.
  • Demonstrated experience building and maturing information security programs in private equity, asset management, or financial services environments with multi‑entity / multi‑fund structures.
  • Deep working knowledge of ISO 27001, NIST 800‑53, SOC 2 Type II, and demonstrated experience leading organizations through certification and audit processes.
  • Expert‑level understanding of data protection regulations (GDPR, CCPA) and their application to investment management firms with cross‑border operations.
  • Hands‑on experience with Microsoft 365 security and compliance stack — Entra ID, Defender XDR, Purview (DLP, sensitivity labels, Insider Risk, Compliance Manager), Intune, and Conditional Access.
  • Strong background in third‑party risk management and vendor security assessment programs.
  • Experience with incident response planning, execution, and post‑incident reporting in environments with investor and regulatory notification obligations.
  • Proven ability to communicate security posture and risk to executive leadership, boards, and institutional investors — including experience with investor ODD/DDQ processes.
Preferred Qualifications
  • Experience with critical infrastructure security, including OT/ICS environments (data centers, utilities, industrial).
  • Familiarity with ISO 42001 (AI Management System) or demonstrated experience establishing AI governance frameworks.
  • Experience supporting SEC‑registered or SEC‑exempt investment advisers and understanding of related compliance obligations.
  • Knowledge of REIT structures, fund accounting controls, and the security considerations unique to real estate private equity.
  • Experience with FedRAMP requirements as they relate to customer contractual obligations.
  • Advanced degree (MBA, MS in Cybersecurity, or equivalent).
  • Active certifications: CISSP, CISM, CISA, CRISC, or equivalent.
Competency
  • Strategic Vision — Ability to translate business strategy and growth trajectory into a scalable security program that enables, rather than constrains, the business.
  • Multi‑Entity Governance — Comfort operating across distinct legal entities with different risk profiles, regulatory postures, and operational models under a unified governance umbrella.
  • Investor‑Grade Communication — Experience presenting security posture and controls to sophisticated institutional investors during due diligence.
  • Hands‑On Leadership — Willingness to operate at both strategic and tactical level, particularly as the security function matures and scales.
  • Collaborative Influence — Ability to drive outcomes across business units (TCM, Tract, Fleet) through influence rather than direct authority, partnering effectively with Legal, Finance, Operations, and Engineering stakeholders.
Annual Compensation Range

$275,000 – $300,000 Base Salary + Discretionary Bonus.

Tract Capital Employment

Employees enjoy competitive compensation and comprehensive benefits, including 100% employer‑covered medical, dental, and vision insurance, a 401(k) program, standard paid holidays, and unlimited PTO.

Equal Opportunity Employer

Tract Capital is proud to be an Equal Opportunity Employer. Qualified applicants are considered for employment regardless of age, race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or veteran status. If you need assistance applying for any of our open positions, please contact us at info@tractcapital.com.

#J-18808-Ljbffr