Career profile
Merlin Namuth
Chief Information Security Officer, City and County of Denver
- Current role, per sources checked 20 July 2025
- 16 October 2024
Merlin Namuth is the Chief Information Security Officer of the City and County of Denver, appointed in October 2024. The appointment followed Denver's decision to split its combined chief data and information security officer position into two separate roles, a chief data officer post and a distinct CISO post.
Career path
Before joining Denver, Namuth spent more than 25 years in cybersecurity, with roles at Tenable, Red Robin, Sports Authority, Wells Fargo, Lockheed Martin, and Beazley Security. Across his career he has led six different security programs, building programs from the ground up, advancing existing ones, and working on mergers and acquisitions, incident response, digital forensics, compliance, architecture, and security engineering. He has also served as an advisor to security startup companies. He came to the Denver role after working primarily in the private sector, which he has said gave him experience balancing security needs against an organization's specific requirements.
Remit at Denver
As CISO, Namuth is responsible for expanding and strengthening the city's information security program and aligning it with industry best practices and regulatory requirements, with duties spanning strategic planning, risk management, internal training, and vendor and budget management. He provides cybersecurity support across all 55 of Denver's agencies and has described building relationships with staff in those agencies as central to identifying security gaps and understanding each group's needs. He has said framing security risks in terms employees already understand, such as the operational impact on utilities like water distribution, helps build that understanding. One of his stated long-term goals has been to extend Denver's security awareness program beyond City Hall: "We're looking at somehow being able to expand this security awareness to the residents across the city and county of Denver." He has also described Denver's size as a factor that can increase its exposure to ransomware and phishing threats, and has discussed artificial intelligence as both a tool for threat detection and a resource bad actors can use to generate phishing content.
A Denver IT audit manager has described an open, communicative working relationship with Namuth, noting that Namuth's team and the Auditor's Office share the same underlying goal of reducing risk even when they differ on specific recommendations. Namuth's responsibilities also appear in the city's Audit Committee materials, where he is listed as Chief Information Security Officer on an information technology risk management follow-up report alongside Denver's Chief Information Officer.
Speaking and writing
Namuth has presented at the RSA Conference six times, both in the United States and internationally, has been interviewed on cybersecurity podcasts, and writes blogs and articles on security topics.
Sources
Related careers
Andy Ritter
Chief Information Security Officer
Commonwealth of Pennsylvania
Bertrum Carroll
State Chief Information Security Officer
State of Nevada, Governor's Technology Office
Gwen Gann
State Chief Information Security Officer
Washington Technology Solutions (WaTech)
Mike Marshall
State Chief Information Security Officer
California Department of Technology