Skip to content
CISO Spotlights

Career profile

Merlin Namuth

Chief Information Security Officer, City and County of Denver

Status
Current role, per sources checked 20 July 2025
Appointed
16 October 2024
Published

Compiled 8 October 2026 from public records. Each statement below is drawn from the sources listed at the end.

Merlin Namuth is the Chief Information Security Officer of the City and County of Denver, appointed in October 2024. The appointment followed Denver's decision to split its combined chief data and information security officer position into two separate roles, a chief data officer post and a distinct CISO post.

Career path

Before joining Denver, Namuth spent more than 25 years in cybersecurity, with roles at Tenable, Red Robin, Sports Authority, Wells Fargo, Lockheed Martin, and Beazley Security. Across his career he has led six different security programs, building programs from the ground up, advancing existing ones, and working on mergers and acquisitions, incident response, digital forensics, compliance, architecture, and security engineering. He has also served as an advisor to security startup companies. He came to the Denver role after working primarily in the private sector, which he has said gave him experience balancing security needs against an organization's specific requirements.

Remit at Denver

As CISO, Namuth is responsible for expanding and strengthening the city's information security program and aligning it with industry best practices and regulatory requirements, with duties spanning strategic planning, risk management, internal training, and vendor and budget management. He provides cybersecurity support across all 55 of Denver's agencies and has described building relationships with staff in those agencies as central to identifying security gaps and understanding each group's needs. He has said framing security risks in terms employees already understand, such as the operational impact on utilities like water distribution, helps build that understanding. One of his stated long-term goals has been to extend Denver's security awareness program beyond City Hall: "We're looking at somehow being able to expand this security awareness to the residents across the city and county of Denver." He has also described Denver's size as a factor that can increase its exposure to ransomware and phishing threats, and has discussed artificial intelligence as both a tool for threat detection and a resource bad actors can use to generate phishing content.

A Denver IT audit manager has described an open, communicative working relationship with Namuth, noting that Namuth's team and the Auditor's Office share the same underlying goal of reducing risk even when they differ on specific recommendations. Namuth's responsibilities also appear in the city's Audit Committee materials, where he is listed as Chief Information Security Officer on an information technology risk management follow-up report alongside Denver's Chief Information Officer.

Speaking and writing

Namuth has presented at the RSA Conference six times, both in the United States and internationally, has been interviewed on cybersecurity podcasts, and writes blogs and articles on security topics.

Sources

  1. 1.
    denvergov.orgdenvergov.org · undated page · checked 8 October 2026 · tier A
  2. 2.
    GovTechgovtech.com · published 26 November 2024 · checked 8 October 2026 · tier B
  3. 3.
    GovTechgovtech.com · published 20 July 2025 · checked 8 October 2026 · tier B
  4. 4.
    events.secureworld.ioevents.secureworld.io · undated page · checked 8 October 2026 · tier B
  5. 5.
    denvergov.orgdenvergov.org · undated page · checked 8 October 2026 · tier A

Tier A: the organization itself, a regulator or a government page. Tier B: established trade or business press.