Chief Security Officer

Xerox

United States

On-site

USD 300,000 - 420,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Xerox seeks a hands-on Chief Security Officer to own and execute a converged security strategy across cyber and physical domains worldwide. You will build and lead a global security organization, shaping risk posture while enabling AI-enabled capabilities.

The role requires deep technical breadth, incident response leadership, and executive-level communication with Board and senior leaders. Location is virtual with preferences on East Coast and Midwest, offering travel across global sites.

Qualifications

  • Has personally led both infrastructure/technology operations and a cybersecurity organization.
  • Hands-on practitioner with depth in threat detection, incident response, and security operations.
  • Experience leading cyber and physical incident response, including crisis management at executive level.
  • Formed a clear, real AI security perspective aligned with full technology-organization response.

Responsibilities

  • Own a single converged security strategy across cyber and physical domains.
  • Lead cyber operations, threat detection, vulnerability management, and secure SDLC for Xerox products.
  • Oversee global physical security, executive protection, and resilience across sites.
  • Define AI security posture and controls, enabling AI while mitigating risks.
  • Manage third-party and supply chain security across suppliers and partners.
  • Report security posture to Board/executives and ensure regulatory compliance.

Skills

Infrastructure leadership
Cyber security leadership
Threat detection
Incident response
Offensive security
Defensive security
Executive communication
Global scope

Education

Bachelor's/Master's in CS/IT/Cybersecurity

Job description

The Chief Security Officer (CSO) owns the protection of Xerox worldwide — across both cyber and physical domains. Reporting to the Chief Technology Officer, this leader sets and executes a single, converged security strategy covering enterprise information security, product and infrastructure security, physical and site security, and executive protection.

This is a technologist's seat, not a governance seat. Xerox is looking for a hands-on practitioner-leader who has personally run both infrastructure and cyber organizations, who has led offensive and defensive operations, and who has stood up incident response for cyber and physical events alike. The CSO operates as a peer to the enterprise technology team, and is expected to support decisions across the full technology estate — not only within the security perimeter.

Artificial intelligence is reshaping attacker capability, defender economics, and the physical threat surface simultaneously. Xerox is looking for a leader who has already formed a clear point of view on what that means and what a complete technology-organization response requires across cyber, physical, technology, AI, and data.

Why Join This Team?
  • Full converged mandate. Single accountability for cyber and physical security across a global, multi-brand enterprise — an unusually broad remit for a security leader.
  • Executive and Board visibility. Direct engagement with the Executive Committee, the Board, and enterprise risk committees on security posture, investment, and risk appetite.
  • Build the AI-era security model. Define how a global technology organization defends against AI-enabled adversaries while safely enabling Xerox's own AI and dat ambitions.
  • Shape enterprise technology, not just security. Partner across infrastructure, applications, AI, and data to influence architecture and operating decisions at enterprise scale.
  • Lead a global team. Build, develop, and lead a distributed security organization spanning in-house teams, global competency centers, and managed partners.
Converged Security Strategy
  • Own a single enterprise security strategy spanning cyber and physical security, with unified policies, standards, control frameworks, and security architecture.
  • Set risk appetite in partnership with the CTO, CIO, executive leadership, and enterprise risk committees; establish key risk indicators and drive measurable risk reduction.
  • Align the security operating model to Xerox's business strategy, integration agenda, and technology roadmap.
Cyber Operations — Offensive and Defensive
  • Lead threat detection, threat hunting, security operations, vulnerability management, and red/purple team functions with an offensive-minded posture that anticipates and hunts rather than waits.
  • Own enterprise security architecture across network, cloud, endpoint, identity, application, and OT/device environments.
  • Own the secure software development lifecycle and product security for Xerox products, services, and connected devices.
Physical Security, Executive Protection, and Resilience
  • Lead global physical security across corporate sites, manufacturing and distribution facilities, and field operations — including access control, surveillance, insider threat, and workplace violence prevention.
  • Own the executive protection program, including travel risk, event security, and threat assessment for senior leadership.
  • Lead physical incident response and crisis management; integrate physical and cyber response into a single, exercised playbook covering converged threat scenarios.
  • Partner with Legal, HR, Real Estate, and Operations on investigations, business continuity, and site resilience planning.
AI — Threat, Defense, and Enablement
  • Define and execute Xerox's point of view on AI in security across three fronts: defending against AI-enabled adversaries, applying AI to accelerate detection and response, and securing Xerox's own AI and data estate.
  • Establish controls for AI-specific attack classes — prompt injection, model inversion and extraction, training-data poisoning, and agent privilege escalation — across internally built and vendor-supplied AI systems.
  • Extend the AI threat model to the physical domain, including synthetic media and voice cloning in social engineering, impersonation and identity fraud, and AI-enabled reconnaissance of people and facilities.
  • Partner with technology, AI, and data leadership so that security is embedded in AI enablement from design forward rather than retrofitted after deployment.
Third-Party and Supply Chain Risk
  • Own the third-party security risk program across suppliers, channel partners, resellers, managed service providers, and acquired entities.
  • Establish security requirements, assessment standards, and contractual controls for vendors with access to Xerox systems, facilities, or customer data.
  • Assess and mitigate risk introduced through the hardware and software supply chain supporting Xerox products and services.
Governance, Compliance, and Communication
  • Report security program status, posture, and material risks to executive leadership, the Board, and enterprise risk committees.
  • Maintain compliance with applicable legal, regulatory, and customer security requirements across global jurisdictions.
  • Serve as the senior security voice with major customers, regulators, auditors, and partners.
  • Drive security awareness and culture across the global employee and contractor population.
Required
  • Dual infrastructure and cyber leadership. Has personally led both an infrastructure/technology operations organization and a cybersecurity organization. This is a screening requirement — candidates who have led security alone will not be a fit for the technical breadth this role demands.
  • Hands-on technical depth. Practitioner-grade background in threat detection, incident response, and both offensive and defensive security operations. Candidates with primarily policy, audit, or compliance-oriented backgrounds are not a fit.
  • Cyber and physical incident response. Direct experience leading response to both cyber incidents and physical security events, including crisis management under executive and Board scrutiny.
  • Demonstrated AI point of view. A developed, defensible position on how AI changes the threat landscape and what a full technology-organization response requires across cyber, physical, technology, AI, and data — supported by real implementation experience, not conference-stage familiarity.
  • Enterprise scale and global remit. Security and technology leadership within organizations of 5,000+ employees with genuine global scope, including direct experience operating through global competency centers and offshore delivery models.
  • Complexity navigation. Proven ability to lead through multi-brand, multi-culture organizational complexity and a fragmented technology environment — including post-merger integration.
  • Depth of experience. 15+ years in security and technology leadership, including 3+ years at CISO or CSO level. Candidates who are "ready now" for a first enterprise seat will be considered where the technical and leadership profile is exceptional.
  • Executive communication. Credibility with the Board, the Executive Committee, and major customers; able to translate technical risk into business terms and security priorities into business value.
Preferred
  • Converged security ownership. Prior accountability for both cyber and physical security functions in a single role.
  • Public company experience and familiarity with associated disclosure, audit, and regulatory obligations.
  • Application portfolio leadership. Prior ownership of an enterprise application portfolio alongside infrastructure and security.
  • Manufacturing, device, or product security exposure — particularly connected devices and OT environments.
Baseline Knowledge
  • Working knowledge of NIST, ISO 27001, SANS, and OWASP frameworks, and of PCI DSS, SOC 2, FedRAMP, and CMMC requirements. Treated as a baseline expectation, not a differentiator.
  • Bachelor's or Master's degree in Computer Science, Information Technology, Cybersecurity, or a related field. CISSP, CISM, CISA, CRISC, or similar certifications are welcome but are not a deciding factor — demonstrated practitioner experience matters more.

Performance in this role will be assessed against measurable outcomes, established with the CTO within the first 90 days:

  • Detection and response. Coverage of the enterprise attack surface, mean time to detect and mean time to respond, and demonstrated improvement against both.
  • Risk reduction. Movement in key risk indicators across cyber, physical, and third-party domains against an agreed baseline.
  • Service reliability. Availability and performance of security services, and security's measured impact on technology delivery velocity.
  • Converged readiness. Frequency, realism, and outcome of joint cyber-physical incident exercises, and closure of resulting findings.
  • AI security posture. Coverage of AI systems under security review and controls, and demonstrated enablement of Xerox's AI roadmap without unmanaged risk.
  • Organizational health. Retention, capability build, and succession depth across the global security organization.
How We Set You Up For Success:
  • Location. Virtual work model, with preference for locations where Xerox has an on-site presence. Open to candidates across the East Coast and Midwest. West Coast-based candidates will not be considered due to time zone overlap requirements.
  • Travel. Travel expected in support of site security, regional teams, and global competency centers.
  • Scope. 70+ security professionals globally, with a significant operating and capital budget across cyber and physical security.
  • Compensation. Base plus annual incentive and long-term incentive eligibility
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Global CSO: Converged Cyber & Physical Security
Global CSO: Converged Cyber & Physical Security

Xerox • United States

On-site
USD 300,000 - 420,000
Global Chief Security Officer (Cyber & Physical)
Global Chief Security Officer (Cyber & Physical)

Xerox Corporation • United States

On-site
USD 250,000 - 420,000
Senior Risk Analyst
Senior Risk Analyst

Xerox Corporation • Northern (KY)

Hybrid
USD 146,000 - 195,000
Senior Enterprise Security Architect
Senior Enterprise Security Architect

Xerox • Oak Brook (IL)

On-site
USD 150,000 - 190,000
Security Penetration Tester
Security Penetration Tester

Xerox Corporation • United States

On-site
USD 90,000 - 140,000
Deputy CISO (SVP Security)
Deputy CISO (SVP Security)

CyberApt Recruitment • Wilmington (DE)

On-site
USD 180,000 - 260,000
Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Sr. Security Program Manager
Sr. Security Program Manager

DigitalXForce Corporation • United States

On-site
USD 140,000 - 210,000
Director of Cyber Security
Director of Cyber Security

KAYAK • United States

Hybrid
USD 180,000 - 240,000
Flexible work policy
Generous time off
Volunteer time off
+3
SVP, Head of Security Technology
SVP, Head of Security Technology

Berkley Technology Services • Wilmington (DE)

On-site
USD 350,000 - 450,000