Position Overview The Chief Information Security Officer (CISO) is a senior leadership role responsible for establishing, maturing, and governing the enterprise information security program across Tract Capital Managemen…
Skills: Information Security Governance, Risk Management, Compliance, ISO 27001, NIST 800-53
Position Overview The Manager, OSP Engineering leads the Outside Plant engineering discipline within Tract Capital's Site Communications & Network Infrastructure organization, owning the pre-construction design and const…
Position Overview The Manager, Inside Plant Engineering leads the Inside Plant engineering discipline within Tract Capital's Site Communications & Network Infrastructure organization, owning the pre-construction design a…
Skills: Inside Plant Engineering, Structured Cabling, Team Management, Vendor Management, Low Voltage Design
Position Overview The Manager, Carrier & Vendor Relations leads the carrier and telecom commercial discipline within Tract Capital's Site Communications & Network Infrastructure organization, owning the sourcing, procure…
The Role Havenly Brands is looking for a Senior Manager, Lifecycle Marketing to own CRM and lifecycle strategy across our portfolio of seven home brands: Havenly, Interior Define, Burrow, The Citizenry, The Inside, St. F…
Principal Technical Program Manager, New Product Development
Quinte West, Ontario, Canada · On-site
$150k–$200k/yr
Senior+
Position Overview The Principal Technical Program Manager, New Product Development leads the most complex and business-critical product development programs supporting data center infrastructure. This role partners close…
Skills: Manufacturing Strategy, New Product Introduction, Program Management, Automation, Robotics
Software Engineering Mgr. - Twilight - Elastic and LogScale
Quinte West, Ontario, Canada · On-site
$110k–$204k/yr
Senior
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to …
EVOCS OVERVIEW EVOCS’s journey began with a mission to empower businesses with advisory expertise, empowered with idealtechnologies to provide them with comprehensive solutions to grow and prosper. Founded by a team of p…
Skills: Solution Architecture, Azure, Microsoft 365, Dynamics, Power Platform
The Mogl team is looking for a Marketing Coordinator to help execute and grow our marketing initiatives across digital channels. This is an excellent opportunity for a marketing professional with 2–3 years of experience …
Skills: Content Creation, Graphic Design, Email Marketing, Social Media Management, B2B SaaS Marketing
About Us Maybell Quantum is redefining the future of computing. As a venture-backed quantum hardware innovator experiencing rapid growth, we're building technology that will transform industries for decades to come. Quan…
Position Overview: We are seeking a hands-on, experienced Internal IT Lead to build, guide, and support our internal IT function. This is a player/coach role where you'll not only lead and mentor the team but also direct…
Skills: Team Leadership, System Administration, Microsoft 365, Azure, Fortinet Firewalls
LauraMac is seeking a Documentation Specialist to support the creation, organization, and maintenance of internal and external documentation, training materials, and knowledge base content. This role focuses on translati…
Skills: Technical Writing, Documentation Management, Confluence, Knowledge Base Management, Training Material Development
TechInsights
Senior Analyst, Compute AI Semiconductor Market Modeling
Quinte West, Ontario, Canada · Remote OK
$118k–$125k/yr
Senior+
OUR STORY TechInsights is the information Platform for the semiconductor industry. Regarded as the most trusted source of actionable, in-depth intelligence related to semiconductor innovation and surrounding markets, Tec…
Senior Analyst, Compute AI Semiconductor Market Modeling
Quinte West, Ontario, Canada · Remote OK
$118k–$125k/yr
Senior+
OUR STORY TechInsights is the information Platform for the semiconductor industry. Regarded as the most trusted source of actionable, in-depth intelligence related to semiconductor innovation and surrounding markets, Tec…
About SugarAI SugarAI is redefining CRM for the age of AI. We’re delivering on the original promise of CRM—turning fragmented customer and revenue signals into clear, prioritized action. Instead of more dashboards or sur…
The Opportunity **This is a hybrid role and requires presence in our Denver Office twice a week (Local Candidates Only)** At OrthoFi, we are looking for a talented, full stack Senior Software Engineer to drive technical …
Skills: .NET Core, .NET Framework, React, Angular, SQL Server
Space is a warfighting domain. True Anomaly seeks those with the talent and ambition to build the technology that secures it. OUR MISSION True Anomaly delivers decisive capabilities for space superiority. We build autono…
About Us Maybell Quantum is redefining the future of computing. As a venture-backed quantum hardware innovator experiencing rapid growth, we're building technology that will transform industries for decades to come. Quan…
At E Tech Group, joining our team means joining a group of passionate and forward-thinking experts. We’re one of the largest engineering and system integration firms in the United States providing value for our clients t…
Chemelex is a global leader in electric thermal and sensing solutions, protecting the world’s critical processes, places and people. With over 50 years of innovation and a commitment to excellence, we develop solut…
Skills: Standard Operating Procedures, Process Optimization, Continuous Improvement, SAP, Enovia
Establish and govern the enterprise information security program across multiple investment entities, focusing on governance, compliance, and risk management. The role involves leading the ISMS, managing regulatory alignment, and representing the firm's security posture to institutional investors.
Requirements
Requires a bachelor's degree and 10+ years of security experience, including 5 years in a senior leadership role within financial services or private equity. Expertise in ISO 27001, NIST frameworks, and the Microsoft 365 security stack is essential.
Full job description
Position Overview
The Chief Information Security Officer (CISO) is a senior leadership role responsible for establishing, maturing, and governing the enterprise information security program across Tract Capital Management and each of its individual investment strategies (Tract and Fleet Data Centers). Reporting directly to the CITO, the CISO will own information security governance, compliance, risk management, and controls — ensuring that TCM's security posture satisfies the demands of institutional investors, hyperscale customers, regulatory bodies, and internal fiduciary obligations.
This is a hands-on leadership position that requires deep expertise in building information security programs within complex, multi-entity investment structures. The CISO will work across corporate IT, operational technology (OT) environments, and third-party ecosystems to deliver a unified governance model that scales with TCM's rapid growth.
Job Responsibilities
The candidate will have experience and practical expertise in the following:
Information Security Governance
Design and lead TCM's enterprise-wide Information Security Management System (ISMS) aligned to ISO/IEC 27001 and NIST 800-53, covering corporate IT and OT environments across all entities.
Establish and chair an Information Security Governance Committee with representation from TCM, Tract, and Fleet Data Centers — integrating into the existing risk committee structure chaired by the Chief Legal Officer (CLO).
Own the information security policy framework across all entities, including the Acceptable Use Policy, AI Policy, Access Control Policy, Data Classification & Handling, Incident Response, and supporting Fleet policies (0034–0039).
Drive the adoption and operationalization of ISO 27001 certification and ISO 42001 (AI Management System) across appropriate entities.
Present security posture, risk exposure, and program maturity to the ELT Steering Committee (SteerCo), Risk Committees, and the CITO on a regular cadence.
Serve as the authoritative voice on information security during investor operational due diligence (ODD) processes, responding to DDQs (e.g., Future Fund ORR, SIG questionnaires) and representing TCM's security posture to institutional investors.
Compliance & Regulatory
Build and operate the information security compliance program spanning TCM corporation, Tract (land/development), and Fleet Data Centers (critical infrastructure) — recognizing the distinct regulatory and contractual obligations of each strategy.
Maintain and continuously improve alignment with applicable frameworks: ISO 27001, NIST 800-53, SOC 2 Type II, GDPR, CCPA, and customer-specific security requirements (hyperscaler contracts, FedRAMP where applicable).
Own TCM's compliance posture scoring using Microsoft Purview Compliance Manager and equivalent tools, mapping internal controls to required frameworks.
Partner with the CLO and outside counsel (Kirkland & Ellis) to ensure information security practices align with securities regulations, fiduciary obligations, fund LPA requirements, and evolving data privacy legislation.
Manage the relationship with Trace3 Security Solutions and other third-party assessors for independent penetration testing, vulnerability assessments, and security audits conducted against NIST 800-115, OWASP, and MITRE ATT&CK methodologies.
Ensure compliance with EU data protection requirements (GDPR, Schrems II) as TCM expands its European investment footprint through Tract II.
Controls & Risk Management
Define, implement, and monitor information security controls at both the TCM enterprise level and within each investment strategy, ensuring appropriate segmentation and tailoring of controls to each entity's risk profile.
Own the enterprise third-party / vendor risk management program in coordination with the Technology Requirements Checklist, evaluating all vendors against 50+ controls spanning Authentication & Identity, Security & Compliance Certifications, Data Residency & Protection, Integration & API Security, and Operational Resilience.
Oversee data loss prevention (DLP), information classification, sensitivity labeling (Microsoft Purview), and data governance controls to protect investor data, financial information, deal pipeline data, proprietary design drawings, and other Confidential Information.
Manage the enterprise identity and access management (IAM) governance in partnership with the IT team — including Entra ID Conditional Access policies, RBAC enforcement, SCIM lifecycle automation, and Privileged Identity Management (PIM).
Lead the Insider Risk Management program using Microsoft 365 security stack capabilities, including behavioral analytics for data exfiltration, IP theft, and policy violations.
Maintain and exercise the Incident Response Plan and Disaster Recovery / Business Continuity Plans, coordinating with the CITO, CLO, and risk committee chairs for incident classification, escalation, and investor/customer notification per contractual timelines.
Govern the security awareness training program (KnowBe4), including phishing simulations, the Tract Capital Cyber Security Safety Guide, and new-hire security onboarding.
Collaboration & Stakeholder Management
Partner with Fleet's SVP of Physical, OT, & Cyber Security to align corporate IT security governance with converged physical/OT/cyber security operations at data center facilities.
Collaborate with the CFO and finance organization on controls relevant to fund accounting, capital call processes, wire transfer security, and investor portal security.
Support the CITO in AI governance, ensuring Enterprise-Approved AI Tools (e.g., Glean) operate within security and data governance guardrails and that the AI Policy is enforced.
Interface with hyperscaler customer security teams to satisfy contractual security requirements and support customer due diligence processes.
Work with Investor Relations to maintain DDQ-ready security documentation and ensure timely, accurate responses to ODD questionnaires.
Basic Qualifications
Bachelor's degree in Information Security, Computer Science, Engineering, or related field.
10+ years of progressive information security experience, with at least 5 years in a CISO, Deputy CISO, or equivalent senior security leadership role.
Demonstrated experience building and maturing information security programs in private equity, asset management, or financial services environments with multi-entity / multi-fund structures.
Deep working knowledge of ISO 27001, NIST 800-53, SOC 2 Type II, and demonstrated experience leading organizations through certification and audit processes.
Expert-level understanding of data protection regulations (GDPR, CCPA) and their application to investment management firms with cross-border operations.
Hands-on experience with Microsoft 365 security and compliance stack — Entra ID, Defender XDR, Purview (DLP, sensitivity labels, Insider Risk, Compliance Manager), Intune, and Conditional Access.
Strong background in third-party risk management and vendor security assessment programs.
Experience with incident response planning, execution, and post-incident reporting in environments with investor and regulatory notification obligations.
Proven ability to communicate security posture and risk to executive leadership, boards, and institutional investors — including experience with investor ODD/DDQ processes.
Preferred Qualifications
Experience with critical infrastructure security, including OT/ICS environments (data centers, utilities, industrial).
Familiarity with ISO 42001 (AI Management System) or demonstrated experience establishing AI governance frameworks.
Experience supporting SEC-registered or SEC-exempt investment advisers and understanding of related compliance obligations.
Knowledge of REIT structures, fund accounting controls, and the security considerations unique to real estate private equity.
Experience with FedRAMP requirements as they relate to customer contractual obligations.
Advanced degree (MBA, MS in Cybersecurity, or equivalent).
Active certifications: CISSP, CISM, CISA, CRISC, or equivalent.
Competency
Strategic Vision — Ability to translate business strategy and growth trajectory into a scalable security program that enables, rather than constrains, the business.
Multi-Entity Governance — Comfort operating across distinct legal entities with different risk profiles, regulatory postures, and operational models under a unified governance umbrella.
Investor-Grade Communication — Experience presenting security posture and controls to sophisticated institutional investors (sovereign wealth funds, pensions, endowments) during due diligence.
Hands-On Leadership — Willingness to operate at both the strategic and tactical level, particularly as the security function matures and scales.
Collaborative Influence — Ability to drive outcomes across business units (TCM, Tract, Fleet) through influence rather than direct authority, partnering effectively with Legal, Finance, Operations, and Engineering stakeholders.
Annual Compensation Range: $275,000-$300,00 Base Salary + Discretionary Bonus
Tract Capital Management offers a competitive total compensation package commensurate with experience, including base salary, annual performance bonus, and a comprehensive benefits program. Details will be discussed during the interview process.
Tract Capital Employment
Tract Capital employees enjoy competitive compensation and comprehensive benefits, including 100% employer-covered medical, dental, and vision insurance, a 401K program, standard paid holidays, and unlimited PTO.
NOTE: This job description is not intended to be all-inclusive. Employees may perform other related duties to meet the organization's ongoing needs.
Tract Capital is proud to be an Equal Opportunity Employer. Qualified applicants are considered for employment regardless of age, race, color, religion, sex, national origin, sexual orientation, gender identity, disability, or veteran status. If you need assistance applying for any of our open positions, please contact us at [email protected].
Related keywords
CISOISMSISO 27001NIST 800-53SOC 2 Type IIGDPRCCPAMicrosoft PurviewEntra IDDefender XDRIntuneISO 42001FedRAMPCISSPCISMCISA