Chief Information Security Officer, Global

Yellowwood Properties Sdn. Bhd.Denver, ColoradoOn-siteFull-timePrincipal, 12–15+ yearsListed 2 hours ago

Apply now

About this role

About Vantage

Vantage powers, cools, protects and connects the technology of the world’s well-known hyperscalers, cloud providers and large enterprises. Developing and operating across North America, EMEA and Asia Pacific, Vantage has evolved data center design in innovative ways to deliver dramatic gains in reliability, efficiency and sustainability in flexible environments that can scale as quickly as the market demands.

Cybersecurity Department

The Information Security function safeguards Vantage’s global digital infrastructure, customer trust, and operational resilience as the company scales across 19+ markets. The team partners closely with Technology, Risk, Legal, Compliance, Data Center Operations, and business leadership to ensure security is embedded into every stage of the customer, construction, and operations lifecycle — protecting the critical infrastructure that powers the world’s hyperscale and enterprise cloud customers.

Position Overview

The Chief Information Security Officer (CISO) provides strategic leadership for the organization’s information security program. This role is responsible for defining and executing the enterprise-wide security strategy, protecting critical assets, ensuring regulatory compliance, and managing cyber risk across all business operations. The CISO collaborates with executive leadership, IT, risk, compliance, and business units globally to align security initiatives with organizational objectives while fostering a culture of security awareness and operational excellence. The CISO champions innovation in security technologies and maintains a proactive posture against emerging cyber threats, ensuring the company’s resilience and reputation.

You will build a capability, not run a report. The benchmark you create will sit behind pricing, product decisions, and executive reporting across a growing global portfolio — and you will decide what it covers, how it is governed, and when it is strong enough to stand behind. Few roles offer this combination of commercial substance, methodological ownership, and visibility at one of the industry’s fastest-scaling companies.

As Vantage's CISO, you will own enterprise security as a board-level, business-critical mandate — not a back-office IT function. You will be the executive voice translating cyber risk into business risk for the CEO and Board, carrying direct accountability for regulatory disclosure and personal liability exposure under frameworks like the SEC Cybersecurity Disclosure Rule. Your remit spans the full convergence of Vantage's environment: traditional IT alongside the operational technology, building management, and physical control systems that run our data centers, plus the cloud-native and multi-tenant security architecture that underpins compliance attestations and due diligence for hyperscale customers.

You will own security posture through the lens of growth — leading due diligence and integration for greenfield markets and acquisitions across 19+ markets — while positioning security as a driver of innovation and competitive differentiation through AI-enabled threat foresight rather than purely reactive defense. Finally, you will own security as a commercial enabler, partnering with Sales and Legal so that Vantage's security posture becomes a trust differentiator that helps win and retain the world's largest hyperscale and enterprise cloud customers.

What Success Looks Like

- Develop and execute the enterprise information security strategy, ensuring alignment with business objectives and regulatory requirements.

- Lead and manage the global information security team, including security architects, analysts, engineers, and specialists, providing guidance, mentorship, and performance oversight.

- Oversee the design, implementation, and monitoring of security programs, policies, procedures, and controls to safeguard corporate assets, data, and infrastructure.

- Identify, assess, and mitigate cyber risks, vulnerabilities, and threats, maintaining enterprise-wide risk visibility and reporting to the executive team and board.

- Partner with IT, legal, compliance, risk management, and business units to ensure security considerations are embedded in all operational and strategic initiatives.

- Lead incident response planning and execution, including threat detection, containment, investigation, and post-incident analysis.

- Evaluate emerging security technologies, trends, and regulatory changes, recommending adoption or adjustments to the security strategy.

- Drive security awareness and training programs across the organization to strengthen the security culture.

- Establish metrics, reporting, and continuous improvement processes to measure the effectiveness of security programs.

- Represent the organization externally to regulators, auditors, partners, and industry groups on security matters.

- Promote a culture of continuous improvement, innovation, and adherence to company values.

- Perform additional duties as assigned by management.

Job Requirements

- Advanced degree in Information Security, Computer Science, Cybersecurity, or related field; relevant experience may substitute for education.

- 15+ years of progressive experience in information security, IT risk management, or related fields, with at least 5–7 years in a senior leadership role.

- Demonstrated experience developing and executing enterprise-wide security strategies, including regulatory compliance (e.g., GDPR, ISO 27001, NIST, SOC 2).

- Expertise in security technologies, threat intelligence, risk management, cloud security, network security, application security, and incident response.

- Proven ability to lead, mentor, and develop high-performing global security teams.

- Strong collaboration, communication, and executive stakeholder management skills in complex or matrixed organizations.

- Experience in security governance, vendor management, budget oversight, and large-scale program implementation.
- Communication: Ability to explain assumptions, movement, confidence levels, limits, and recommended decisions clearly to technical, commercial, and executive audiences.
- Strategic Mindset: Sees ahead clearly and translates evolving cyber threats and regulatory landscapes into a forward-looking security strategy.

- Business Insight: Applies knowledge of the data center and digital infrastructure business to security decision-making.

- Manages Complexity: Makes sense of complex, high-volume, and ambiguous threats and risk information to make effective decisions.

- Balances Stakeholders: Anticipates and balances the needs of the Board, executive leadership, customers, and regulators.

- Commitment to upholding company values, fostering a culture of security, and enabling business growth.

- Travel required is expected to be up to 20% but may increase overtime as the business evolves.
- AI governance fluency — Familiarity with AI/ML security risk (model exfiltration, data poisoning, prompt injection) and emerging frameworks in global markets.
- Global multi-region leadership — Demonstrated experience operating across NA, EMEA, and APAC, including navigating GDPR and regional data protection regimes.

- Customer-facing security assurance — Experience representing the organization directly to hyperscale/enterprise cloud customers during security due diligence, RFPs, or contractual reviews.
- OT/ICS and physical-cyber convergence — Hands-on experience securing building management systems (BMS), SCADA, and physical access control systems specific to data center operations, not just traditional enterprise IT

Physical Demands and Special Requirements

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

While performing the duties of this job, the employee is occasionally required to stand; walk; sit; use hands to handle or feel objects; reach with hands and arms; climb stairs; balance; stoop or kneel; talk and hear. The employee must occasionally lift and/or move up to 25 pounds.

Additional Details

- Salary Range: $330,000 – $360,000 Base + Bonus (this range is based on Colorado market data and may vary in other locations)
- This position is eligible for company benefits including but not limited to medical, dental, and vision coverage, life and AD&D, short and long-term disability coverage, paid time off, employee assistance, participation in a 401k program that includes company match, and many other additional voluntary benefits.
- Compensation for the role will depend on several factors, including your qualifications, skills, competencies, and experience and may fall outside of the range shown.

We operate with No Ego and No Arrogance. We work to build each other up and support one another, appreciating each other’s strengths and respecting each other’s weaknesses. We find joy in our work and each other, actively seeking opportunities to inject fun into what we do. Our hard and efficient work is rewarded with an above market total compensation package. We offer a comprehensive suite of health and welfare, retirement, and paid leave benefits exceeding local expectations.

Throughout the year, the advantage of being part of the Vantage team is evident with an array of benefits, recognition, training and development, and the knowledge that your contribution adds value to the company and our community.

Don't meet all the requirements? Please still apply if you think you are the right person for the position. We are always keen to speak to people who connect with our mission and values.

Vantage is an Equal Opportunity Employer.

Vantage does not accept unsolicited resumes from search firm agencies. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of Vantage.

We’ll be accepting applications for at least one week from the date this role is posted. If you're interested, we encourage you to apply soon—we’re excited to find the right person and will keep the role open until we do!