Jobs · Information Technology · California

VP, Information Security and Compliance

Veritone · Irvine, CA · 5 days ago
Information Technology$200k–$250k/yrFull-time

Reporting directly to the Chief Legal Officer, this executive role serves as the Chief Information Security Officer and global champion for enterprise security and compliance programs. The position requires a blend of strategic vision, commercial SaaS agility, public-sector governance, and public-company risk management to protect customer data, intellectual property, and infrastructure across all business units, including high-stringency public-sector environments.

Responsibilities

  • Strategic Leadership & Governance
    • Security Vision & Roadmap: Architect and execute a multi-year, enterprise-wide information security and compliance strategy aligned with commercial growth targets and public-sector expansion goals.
    • Executive Presence: Serve as the primary security advisor to the Board of Directors, Executive Leadership Team, and the organization, translating complex security risks into actionable business terms.
    • Team Leadership: Build, mentor, and lead a high-performing global security team across security operations, engineering, risk management, and regulatory compliance.
    • Security Culture: Foster a company-wide "security-first" culture through continuous training, awareness programs, and cross-functional advocacy.
  • Compliance
    • FedRAMP & Defense Authorizations: Lead strategy, deployment, and continuous monitoring to achieve and maintain FedRAMP (Moderate/High), StateRAMP, DoD/CMMC, and CJIS authorizations in cloud environments (AWS GovCloud/Azure Government).
    • Commercial Frameworks: Oversee compliance and auditing for SOC 2 Type II, ISO 27001, PCI-DSS, and global privacy standards (GDPR, CCPA/CPRA).
    • Public Company Compliance: Partner with legal, finance, and internal audit teams to maintain robust IT general controls (ITGCs) for SOX compliance and support SEC cybersecurity disclosure requirements.
  • Security Operations, Architecture & Incident Response
    • Cloud & Product Architecture: Partner with Enterprise Architecture, Infrastructure, and Engineering teams to embed security controls into multi-tenant SaaS platforms, CI/CD pipelines, and cloud environments.
    • Threat & Vulnerability Management: Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence operations to proactively address emerging threats.
    • Incident Management: Oversee breach investigations, threat response protocols, and tabletop exercises, ensuring rapid containment, notification, and mitigation.
  • Enterprise Risk Management & Operations
    • Third-Party & Vendor Risk: Establish and enforce third-party risk management (TPRM) programs to audit and secure vendor ecosystems, software supply chains, and external partners.
    • M&A Due Diligence: Lead security and compliance due diligence for mergers and acquisitions, driving post-acquisition security integration strategies.
    • Business Continuity & Resilience: Construct policies and operational frameworks for Business Continuity Planning (BCP), Disaster Recovery (DR), loss prevention, and fraud prevention.

Requirements

  • Education: Bachelor of Science degree in Computer Science, Cybersecurity, Computer Engineering, Information Technology, or equivalent technical discipline.
  • Executive Experience: 10+ years of progressive leadership experience in information security, cloud architecture, and compliance within a global, publicly traded cloud/SaaS technology company.
  • Proven FedRAMP Track Record: Hands-on experience leading a cloud solution through the FedRAMP authorization lifecycle (PMO/JAB or Agency route) and continuous monitoring in AWS and/or Azure cloud environments.
  • Dual-Domain Capability: Equal fluency in scaling commercial enterprise SaaS security and navigating rigid public-sector regulatory landscapes (NIST 800-53, NIST 800-171, CMMC, CJIS, FISMA).
  • Executive Presence & Communication: Exceptional ability to communicate security concepts to technical engineers, enterprise buyers, regulatory auditors, and Board members.
  • Risk & Contract Negotiation: Demonstrated success negotiating security exhibits, data processing agreements (DPAs), and risk terms with enterprise clients and vendors.

Preferred Qualifications

  • Advanced Degree: Master’s degree (M.S. in Cybersecurity/Computer Science or MBA).
  • Industry Certifications: Active professional certifications such as CISSP, CISM, CRISC, CISA, or CCSP.
  • Security Clearance: Active or clearable U.S. Government Security Clearance (DoD Secret or Top Secret preferred).
  • AI/ML Security: Knowledge of security, privacy, and governance frameworks surrounding Artificial Intelligence and Machine Learning workloads.

Pay

The annual salary range for this position is $200,000–$250,000. This base pay is for illustrative purposes and will be determined based on skills and experience comparable to the job requirements. Additional compensation and benefits may include incentive compensation, health benefits, retirement benefits, life insurance, paid time off, parental leave, and other employee perks.

Similar jobs

VP, Security & Compliance

DynataTexas, United States· 1 mo ago
RemoteInformation Technology$200k–$220k/yrapply on dynata.wd108.myworkdayjobs.com

VP, Information Security

LCSDes Moines, IA· 2 wk ago
Information Technology$171k–$214k/yrapply on eexs.fa.us2.oraclecloud.com