Chief Information Security Officer

XeroxApplyPublished 1 days agoFirst seen 2 days ago
Apply

The salary range above represents the low and high end in the local currency of Xerox’s salary range for this position and is reflected in an annualized amount. Actual salaries will vary based on factors including, but not limited to, geographic location, market competition, and/or the successful applicant’s education, experience, knowledge, skills, and abilities. The range listed is just one component of Xerox’s total compensation package for employees. Employees are also afforded a comprehensive suite of benefits, to view those details please visit Xerox Careers for your applicable country. If you are not reviewing this job posting on Xerox Careers, we cannot guarantee the validity of this posting. For a list of our current internal postings, please visit Xerox Careers.

Monthly: Monthly rates for this position can be shared with you per your location, this rate will fall within the posted range.

About Xerox Holdings Corporation
For more than 100 years, Xerox has continually redefined the workplace experience. Harnessing our leadership position in office and production print technology, we’ve expanded into software and services to sustainably power today’s workforce. From the office to industrial environments, our differentiated business solutions and financial services are designed to make every day work better for clients — no matter where that work is being done. Today, Xerox scientists and engineers are continuing our legacy of innovation with disruptive technologies in digital transformation, augmented reality, robotic process automation, additive manufacturing, Industrial Internet of Things and cleantech. Learn more at www.xerox.com and explore our commitment to diversity and inclusion.

Xerox Corporation  |  Reports to the Chief Technology Officer  |

Overview: The Chief Security Officer (CSO) owns the protection of Xerox worldwide across both cyber and physical domains. Reporting to the Chief Technology Officer, this leader sets and executes a single, converged security strategy covering enterprise information security, product and infrastructure security, physical and site security, and executive protection.

This is a technologist's seat, not a governance seat. Xerox is looking for a hands-on practitioner-leader who has personally run both infrastructure and cyber organizations, who has led offensive and defensive operations, and who has stood up incident response for cyber and physical events alike. The CSO operates as a peer to the enterprise technology team, and is expected to support decisions across the full technology estate — not only within the security perimeter.

Artificial intelligence is reshaping attacker capability, defender economics, and the physical threat surface simultaneously. Xerox is looking for a leader who has already formed a clear point of view on what that means and what a complete technology-organization response requires across cyber, physical, technology, AI, and data.

Why Join This Team

  • Full converged mandate. Single accountability for cyber and physical security across a global, multi-brand enterprise — an unusually broad remit for a security leader.
  • Executive and Board visibility. Direct engagement with the Executive Committee, the Board, and enterprise risk committees on security posture, investment, and risk appetite.
  • Build the AI-era security model. Define how a global technology organization defends against AI-enabled adversaries while safely enabling Xerox's own AI and data ambitions.
  • Shape enterprise technology, not just security. Partner across infrastructure, applications, AI, and data to influence architecture and operating decisions at enterprise scale.
  • Lead a global team. Build, develop, and lead a distributed security organization spanning in-house teams, global competency centers, and managed partners.

What You Will Do

Converged Security Strategy

  • Own a single enterprise security strategy spanning cyber and physical security, with unified policies, standards, control frameworks, and security architecture.
  • Set risk appetite in partnership with the CTO, CIO, executive leadership, and enterprise risk committees; establish key risk indicators and drive measurable risk reduction.
  • Align the security operating model to Xerox's business strategy, integration agenda, and technology roadmap.

Cyber Operations — Offensive and Defensive

  • Lead threat detection, threat hunting, security operations, vulnerability management, and red/purple team functions with an offensive-minded posture that anticipates and hunts rather than waits.
  • Own enterprise security architecture across network, cloud, endpoint, identity, application, and OT/device environments.
  • Own the secure software development lifecycle and product security for Xerox products, services, and connected devices.

Physical Security, Executive Protection, and Resilience

  • Lead global physical security across corporate sites, manufacturing and distribution facilities, and field operations — including access control, surveillance, insider threat, and workplace violence prevention.
  • Own the executive protection program, including travel risk, event security, and threat assessment for senior leadership.
  • Lead physical incident response and crisis management; integrate physical and cyber response into a single, exercised playbook covering converged threat scenarios.
  • Partner with Legal, HR, Real Estate, and Operations on investigations, business continuity, and site resilience planning.

AI — Threat, Defense, and Enablement

  • Define and execute Xerox's point of view on AI in security across three fronts: defending against AI-enabled adversaries, applying AI to accelerate detection and response, and securing Xerox's own AI and data estate.
  • Establish controls for AI-specific attack classes — prompt injection, model inversion and extraction, training-data poisoning, and agent privilege escalation — across internally built and vendor-supplied AI systems.
  • Extend the AI threat model to the physical domain, including synthetic media and voice cloning in social engineering, impersonation and identity fraud, and AI-enabled reconnaissance of people and facilities.
  • Partner with technology, AI, and data leadership so that security is embedded in AI enablement from design forward rather than retrofitted after deployment.

Third-Party and Supply Chain Risk

  • Own the third-party security risk program across suppliers, channel partners, resellers, managed service providers, and acquired entities. 
  • Establish security requirements, assessment standards, and contractual controls for vendors with access to Xerox systems, facilities, or customer data. 
  • Assess and mitigate risk introduced through the hardware and software supply chain supporting Xerox products and services. 

Governance, Compliance, and Communication

  • Report security program status, posture, and material risks to executive leadership, the Board, and enterprise risk committees.
  • Maintain compliance with applicable legal, regulatory, and customer security requirements across global jurisdictions.
  • Serve as the senior security voice with major customers, regulators, auditors, and partners.
  • Drive security awareness and culture across the global employee and contractor population.

What You Need to Succeed

Required

  • Dual infrastructure and cyber leadership. Has personally led both an infrastructure/technology operations organization and a cybersecurity organization. This is a screening requirement — candidates who have led security alone will not be a fit for the technical breadth this role demands. 
  • Hands-on technical depth. Practitioner-grade background in threat detection, incident response, and both offensive and defensive security operations. Candidates with primarily policy, audit, or compliance-oriented backgrounds are not a fit.
  • Cyber and physical incident response. Direct experience leading response to both cyber incidents and physical security events, including crisis management under executive and Board scrutiny.
  • Demonstrated AI point of view. A developed, defensible position on how AI changes the threat landscape and what a full technology-organization response requires across cyber, physical, technology, AI, and data — supported by real implementation experience, not conference-stage familiarity.
  • Enterprise scale and global remit. Security and technology leadership within organizations of 5,000+ employees with genuine global scope, including direct experience operating through global competency centers and offshore delivery models.
  • Complexity navigation. Proven ability to lead through multi-brand, multi-culture organizational complexity and a fragmented technology environment — including post-merger integration.
  • Depth of experience. 15+ years in security and technology leadership, including 3+ years at CISO or CSO level. Candidates who are "ready now" for a first enterprise seat will be considered where the technical and leadership profile is exceptional.
  • Executive communication. Credibility with the Board, the Executive Committee, and major customers; able to translate technical risk into business terms and security priorities into business value.

Preferred

  • Converged security ownership. Prior accountability for both cyber and physical security functions in a single role.
  • Public company experience and familiarity with associated disclosure, audit, and regulatory obligations.
  • Application portfolio leadership. Prior ownership of an enterprise application portfolio alongside infrastructure and security.
  • Manufacturing, device, or product security exposure — particularly connected devices and OT environments.

Baseline Knowledge

  • Working knowledge of NIST, ISO 27001, SANS, and OWASP frameworks, and of PCI DSS, SOC 2, FedRAMP, and CMMC requirements. Treated as a baseline expectation, not a differentiator.
  • Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related field. CISSP, CISM, CISA, CRISC, or similar certifications are welcome but are not a deciding factor — demonstrated practitioner experience matters more.

How Success Will Be Measured

Performance in this role will be assessed against measurable outcomes, established with the CTO within the first 90 days:

  • Detection and response. Coverage of the enterprise attack surface, mean time to detect and mean time to respond, and demonstrated improvement against both.
  • Risk reduction. Movement in key risk indicators across cyber, physical, and third-party domains against an agreed baseline.
  • Service reliability. Availability and performance of security services, and security's measured impact on technology delivery velocity.
  • Converged readiness. Frequency, realism, and outcome of joint cyber-physical incident exercises, and closure of resulting findings.
  • AI security posture. Coverage of AI systems under security review and controls, and demonstrated enablement of Xerox's AI roadmap without unmanaged risk.
  • Organizational health. Retention, capability build, and succession depth across the global security organization.

How We Set You Up for Success

  • Location. Virtual work model, with preference for locations where Xerox has an on-site presence. Open to candidates across the East Coast and Midwest. West Coast-based candidates will not be considered due to time zone overlap requirements.
  • Travel. Travel expected in support of site security, regional teams, and global competency centers.  
  • Scope. 70+ security professionals globally, with a significant operating and capital budget across cyber and physical security.
  • Compensation. Base range plus annual incentive and long-term incentive eligibility.