Jobs and Careers
TR

Chief Information Security Officer (CISO)

Tract Capital
United Statesfull_timeVerifiedPosted 16 Jul 2026
💰 $300,000/yr($275,000/yr$300,000/yr)

About the role

Overview

Tract Capital adopts a unique approach to digital infrastructure investment. Leveraging experience and strategic insights honed over three decades of creating successful companies in the space, we excel in nurturing and advancing leading-edge digital infrastructure enterprises. Our team of specialized experts are united by a singular purpose: to support the growth of digital infrastructure. Tract Capital goes beyond simple investment by acting as a strategic partner and catalyst for innovation within the sector. We ensure our engagements not only generate strong financial results but also develop essential digital infrastructure to meet growing demands. Tract Capital has introduced two digital infrastructure strategies. The first is a horizontal, powered land strategy focused on creating master planned data center campuses called Tract. The second is the mega-campus vertical development strategy called Fleet Data Centers.

Position Overview

The Chief Information Security Officer (CISO) is a senior leadership role responsible for establishing, maturing, and governing the enterprise information security program across Tract Capital Management and each of its individual investment strategies (Tract and Fleet Data Centers). Reporting directly to the CITO, the CISO will own information security governance, compliance, risk management, and controls — ensuring that TCM's security posture satisfies the demands of institutional investors, hyperscale customers, regulatory bodies, and internal fiduciary obligations.

This is a hands-on leadership position that requires deep expertise in building information security programs within complex, multi-entity investment structures. The CISO will work across corporate IT, operational technology (OT) environments, and third-party ecosystems to deliver a unified governance model that scales with TCM's rapid growth.


Job Responsibilities

The candidate will have experience and practical expertise in the following:

 Information Security Governance

  • Design and lead TCM's enterprise-wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800-53, covering corporate IT and OT environments across all entities.
  • Establish and chair an Information Security Governance Committee with representation from TCM, Tract, and Fleet Data Centers — integrating into the existing risk committee structure chaired by the Chief Legal Officer (CLO).
  • Own the information security policy framework across all entities, including the Acceptable Use Policy, AI Policy, Access Control Policy, Data Classification & Handling, Incident Response, and supporting Fleet policies (0034–0039).
  • Drive the adoption and operationalization of ISO 27001 certification and ISO 42001 (AI Management System) across appropriate entities.
  • Present security posture, risk exposure, and program maturity to the ELT Steering Committee (SteerCo), Risk Committees, and the CITO on a regular cadence.
  • Serve as the authoritative voice on information security during investor operational due diligence (ODD) processes, responding to DDQs (e.g., Future Fund ORR, SIG questionnaires) and representing TCM's security posture to institutional investors.

Compliance & Regulatory

  • Build and operate the information security compliance program spanning TCM corporation, Tract (land/development), and Fleet Data Centers (critical infrastructure) — recognizing the distinct regulatory and contractual obligations of each strategy.
  • Maintain and continuously improve alignment with applicable frameworks: ISO 27001, NIST 800-53, SOC 2 Type II, GDPR, CCPA, and customer-specific security requirements (hyperscaler contracts, FedRAMP where applicable).
  • Own TCM's compliance posture scoring using Microsoft Purview Compliance Manager and equivalent tools, mapping internal controls to required frameworks.
  • Partner with the CLO and outside counsel (Kirkland & Ellis) to ensure information security practices align with securities regulations, fiduciary obligations, fund LPA requirements, and evolving data privacy legislation.
  • Manage the relationship with Trace3 Security Solutions and other third-party assessors for independent penetration testing, vulnerability assessments, and security audits conducted against NIST 800-115, OWASP, and MITRE ATT&CK methodologies.
  • Ensure compliance with EU data protection requirements (GDPR, Schrems II) as TCM expands its European investment footprint through Tract II.

 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Tract Capital

View company profile →