HomeSearch › Job

Vice President, Information Security

SWCA Environmental Consultants

Remote - Any · executive

Job at a glance

Remote - Any
Location
Remote
Work arrangement
Executive
Seniority
SWCA Environmental Consultants
Employer

About the opportunity SWCA Environmental Consultants is seeking a strategic, business-oriented, and highly experienced Vice President, Information Security to lead the organization's cybersecurity, governance, risk, compliance, business continuity, resilience, and information protection programs. Reporting to the Chief Digital Information Officer (CDIO), the Vice President, Information Security serves as SWCA's senior cybersecurity executive and trusted advisor on cyber risk, regulatory compliance, client data protection, operational resilience, and emerging technology risk.

This executive will set enterprise security direction, strengthen cyber resilience, and enable responsible growth, innovation, AI adoption, and digital transformation across SWCA. The role will lead security operations, governance, regulatory readiness, data protection, third-party risk, business continuity, and federal compliance initiatives including CUI and CMMC readiness. The Vice President will partner with executive leadership, operations, business development, legal, HR, finance, and technology teams to ensure security protects SWCA while enabling business objectives.

What You Will Bring to the Team: Executive presence with the ability to advise senior leaders, clients, and the Board. Business-minded, risk-based decision maker who balances protection, operational enablement, and growth. Deep expertise in cybersecurity, compliance, resilience, data protection, and emerging technology governance. Collaborative leader who builds trust across business, technology, legal, HR, finance, and operations teams.

Passion for developing people, strengthening culture, and building high-performing teams. Please include a Cover Letter to be considered for this position. Application Deadline:  Sunday, September 27, 2026 at 5PM Pacific Time. What you will accomplish Information Security Strategy & Executive Leadership Define and execute an enterprise cybersecurity strategy aligned with SWCA's business objectives, risk appetite, and growth plans.

Serve as the senior executive advisor on cyber risk, regulatory obligations, emerging threats, and security investments. Establish executive-level reporting, KPIs, maturity roadmaps, and governance mechanisms that demonstrate program effectiveness. Benchmark capabilities against leading frameworks and translate findings into practical, risk-based improvement plans. Security Operations & Cyber Risk Management Lead enterprise security operations across threat detection, incident response, vulnerability management, endpoint protection, identity and access management, and security monitoring.

Own cyber incident management, crisis response, ransomware preparedness, and recovery planning. Oversee security investigations, event analysis, and continuous improvement of SWCA's security posture. Ensure effective protection of cloud, SaaS, endpoint, collaboration, and core business platforms. Governance, Risk & Compliance Lead the enterprise Governance, Risk & Compliance program, including policies, standards, control frameworks, and risk acceptance processes.

Oversee cyber risk assessments, enterprise risk registers, executive risk reviews, and security governance forums. Establish mature third-party and supply chain risk management capabilities. Coordinate client security assessments, audits, due diligence reviews, questionnaires, and contractual security requirements. CUI, Federal Compliance & Security Assurance Lead CUI, NIST 800-171, DFARS, CMMC, and federal cybersecurity readiness initiatives.

Design and govern secure operating environments, enclave requirements, segmentation, data handling, and access controls for regulated data. Maintain System Security Plans, Plans of Action & Milestones, audit evidence, and compliance governance processes. Partner with federal clients, assessors, auditors, and regulatory stakeholders to demonstrate compliance and readiness. Data Protection & Information Governance Develop the enterprise data

Search all live jobs — free, no account →