Security moves to the center of the AI cloud pitch
IREN, a vertically integrated AI cloud provider that builds large-scale data centers and compute for AI training and inference, named Eric Hammersley as its Chief Information Security Officer on July 15. His remit covers security across the full stack that IREN operates, from the physical data centers to the compute infrastructure to the software layers of its AI cloud platform. The company runs grid-connected land and power assets across renewable-rich regions in North America, Europe, and the Asia-Pacific region, so the surface Hammersley now defends spans hardware, facilities, and the tenant-facing services that sit on top.
Co-founder and co-CEO Daniel Roberts tied the hire directly to the customer base, saying that "security is core to how we design, build and operate our platform" and that "as we deliver AI cloud services to some of the most demanding customers in the world, Eric's experience securing cloud platforms at scale will be invaluable." That framing tells you where security now sits in the AI infrastructure market. It has moved from a back-office control function to a front-line sales requirement, because the enterprises and model developers buying large blocks of GPU capacity bring rigorous procurement and audit standards with them.
A builder with defense-grade credentials
Hammersley's resume is unusually deep on the engineering side of security. He served as Vice President of Engineering and Chief Product Security Officer at Nutanix, a role that put him at the intersection of shipping product and securing it at enterprise scale. Before that he worked as a software product security architect for NVIDIA's high-performance computing environments, which is directly relevant to the accelerated compute platforms IREN sells. That combination gives him firsthand knowledge of both the hypervisor and cloud layer and the GPU-heavy systems that define modern AI workloads.
His earlier career adds a national security dimension. Hammersley held senior engineering positions across the US federal government and the defense sector, including chief engineer work supporting the Joint Chiefs of Staff, and he is a US Navy veteran. That background carries weight with regulated buyers and with any customer running sensitive or export-controlled workloads on shared infrastructure. It also signals that IREN wants a security leader who can speak the language of the most demanding public sector and enterprise procurement teams, where certifications, supply chain assurance, and incident response maturity decide whether a deal closes.
The neocloud security problem is real
The wave of AI-focused cloud providers that stood up capacity over the past two years grew fast, and speed and security rarely scale at the same pace. Many of these operators started as infrastructure and power plays, then added cloud services and multi-tenant platforms as demand for GPU compute exploded. That evolution creates a hard security problem. Multi-tenant AI infrastructure has to isolate customer workloads, protect model weights and training data, secure the supply chain for accelerators, and defend management planes that control enormous amounts of compute. Any weakness there is a direct threat to the customers who trust the platform with their most valuable assets.
IREN's own history follows this arc. The company evolved into an AI cloud operator on top of grid-connected power and data center infrastructure, and it now targets customers who expect the same controls they would demand from a hyperscaler. Hiring a CISO with product security depth is how a provider closes the credibility gap with those buyers. It puts a named, accountable executive behind the security posture, which is what enterprise risk teams look for before they commit workloads. The appointment is a sign that IREN understands security maturity is now part of the product it sells.
What enterprise compute buyers should read into it
For CIOs and CISOs sourcing AI compute, this appointment is a useful benchmark for vendor evaluation. The market has expanded well beyond the three large hyperscalers, and enterprises are increasingly placing training and inference workloads with specialized providers to secure capacity and better pricing. Those decisions carry real risk, because a specialized provider without mature security can expose model weights, proprietary data, and pipelines. A named CISO with the right background is a signal that a provider takes that risk seriously and has someone accountable for it.
We would treat the presence of a credentialed security executive as a baseline procurement checkpoint for any AI infrastructure partner. The questions that follow are concrete. Who owns tenant isolation, how are accelerators and firmware secured across the supply chain, what certifications exist, and how is incident response tested. IREN putting Hammersley in the seat gives its sales team a credible answer to those questions. Buyers should expect the same from every neocloud vendor on their shortlist, and they should downgrade any provider that cannot point to a clear owner of platform security.
The talent signal for security leaders
The hire also says something about where senior security talent is flowing. Hammersley left an established enterprise software vendor to run security at an AI infrastructure company, which reflects the gravitational pull of the compute buildout. The most interesting security problems, and the biggest budgets, increasingly sit at the layer where AI actually runs. Leaders with both engineering depth and platform security experience are in short supply, and providers racing to win enterprise trust are competing hard for them.
For security executives weighing their next move, IREN's structure is instructive. The CISO reports into the top of a company that treats security as a commercial differentiator, with the co-CEO personally framing the mandate. That is a stronger position than sitting several layers down in an organization where security is a cost center. As AI infrastructure keeps scaling, we expect more of these elevated, business-facing CISO roles to open, and the operators who fill them with credible leaders will have an edge in the enterprise deals that matter most.



