Chief Security Officer

Xerox
•$209,100 - $418,200•Remote

About The Position

The Chief Security Officer (CSO) owns the protection of Xerox worldwide — across both cyber and physical domains. Reporting to the Chief Technology Officer, this leader sets and executes a single, converged security strategy covering enterprise information security, product and infrastructure security, physical and site security, and executive protection. This is a technologist's seat, not a governance seat. Xerox is looking for a hands-on practitioner-leader who has personally run both infrastructure and cyber organizations, who has led offensive and defensive operations, and who has stood up incident response for cyber and physical events alike. The CSO operates as a peer to the enterprise technology team, and is expected to support decisions across the full technology estate — not only within the security perimeter. Artificial intelligence is reshaping attacker capability, defender economics, and the physical threat surface simultaneously. Xerox is looking for a leader who has already formed a clear point of view on what that means and what a complete technology-organization response requires across cyber, physical, technology, AI, and data.

Requirements

  • Dual infrastructure and cyber leadership. Has personally led both an infrastructure/technology operations organization and a cybersecurity organization. This is a screening requirement — candidates who have led security alone will not be a fit for the technical breadth this role demands.
  • Hands-on technical depth. Practitioner-grade background in threat detection, incident response, and both offensive and defensive security operations. Candidates with primarily policy, audit, or compliance-oriented backgrounds are not a fit.
  • Cyber and physical incident response. Direct experience leading response to both cyber incidents and physical security events, including crisis management under executive and Board scrutiny.
  • Demonstrated AI point of view. A developed, defensible position on how AI changes the threat landscape and what a full technology-organization response requires across cyber, physical, technology, AI, and data — supported by real implementation experience, not conference-stage familiarity.
  • Enterprise scale and global remit. Security and technology leadership within organizations of 5,000+ employees with genuine global scope, including direct experience operating through global competency centers and offshore delivery models.
  • Complexity navigation. Proven ability to lead through multi-brand, multi-culture organizational complexity and a fragmented technology environment — including post-merger integration.
  • Depth of experience. 15+ years in security and technology leadership, including 3+ years at CISO or CSO level. Candidates who are "ready now" for a first enterprise seat will be considered where the technical and leadership profile is exceptional.
  • Executive communication. Credibility with the Board, the Executive Committee, and major customers; able to translate technical risk into business terms and security priorities into business value.

Nice To Haves

  • Converged security ownership. Prior accountability for both cyber and physical security functions in a single role.
  • Public company experience and familiarity with associated disclosure, audit, and regulatory obligations.
  • Application portfolio leadership. Prior ownership of an enterprise application portfolio alongside infrastructure and security.
  • Manufacturing, device, or product security exposure — particularly connected devices and OT environments.
  • Working knowledge of NIST, ISO 27001, SANS, and OWASP frameworks, and of PCI DSS, SOC 2, FedRAMP, and CMMC requirements. Treated as a baseline expectation, not a differentiator.
  • Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related field. CISSP, CISM, CISA, CRISC, or similar certifications are welcome but are not a deciding factor — demonstrated practitioner experience matters more.

Responsibilities

  • Own a single enterprise security strategy spanning cyber and physical security, with unified policies, standards, control frameworks, and security architecture.
  • Set risk appetite in partnership with the CTO, CIO, executive leadership, and enterprise risk committees; establish key risk indicators and drive measurable risk reduction.
  • Align the security operating model to Xerox's business strategy, integration agenda, and technology roadmap.
  • Lead threat detection, threat hunting, security operations, vulnerability management, and red/purple team functions with an offensive-minded posture that anticipates and hunts rather than waits.
  • Own enterprise security architecture across network, cloud, endpoint, identity, application, and OT/device environments.
  • Own the secure software development lifecycle and product security for Xerox products, services, and connected devices.
  • Lead global physical security across corporate sites, manufacturing and distribution facilities, and field operations — including access control, surveillance, insider threat, and workplace violence prevention.
  • Own the executive protection program, including travel risk, event security, and threat assessment for senior leadership.
  • Lead physical incident response and crisis management; integrate physical and cyber response into a single, exercised playbook covering converged threat scenarios.
  • Partner with Legal, HR, Real Estate, and Operations on investigations, business continuity, and site resilience planning.
  • Define and execute Xerox's point of view on AI in security across three fronts: defending against AI-enabled adversaries, applying AI to accelerate detection and response, and securing Xerox's own AI and data estate.
  • Establish controls for AI-specific attack classes — prompt injection, model inversion and extraction, training-data poisoning, and agent privilege escalation — across internally built and vendor-supplied AI systems.
  • Extend the AI threat model to the physical domain, including synthetic media and voice cloning in social engineering, impersonation and identity fraud, and AI-enabled reconnaissance of people and facilities.
  • Partner with technology, AI, and data leadership so that security is embedded in AI enablement from design forward rather than retrofitted after deployment.
  • OWN THE THIRD-PARTY SECURITY RISK PROGRAM ACROSS SUPPLIERS, CHANNEL PARTNERS, RESELLERS, MANAGED SERVICE PROVIDERS, AND ACQUIRED ENTITIES.
  • ESTABLISH SECURITY REQUIREMENTS, ASSESSMENT STANDARDS, AND CONTRACTUAL CONTROLS FOR VENDORS WITH ACCESS TO XEROX SYSTEMS, FACILITIES, OR CUSTOMER DATA.
  • ASSESS AND MITIGATE RISK INTRODUCED THROUGH THE HARDWARE AND SOFTWARE SUPPLY CHAIN SUPPORTING XEROX PRODUCTS AND SERVICES.
  • Report security program status, posture, and material risks to executive leadership, the Board, and enterprise risk committees.
  • Maintain compliance with applicable legal, regulatory, and customer security requirements across global jurisdictions.
  • Serve as the senior security voice with major customers, regulators, auditors, and partners.
  • Drive security awareness and culture across the global employee and contractor population.

Benefits

  • Comprehensive suite of benefits
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service