VP, Information Security and Compliance
Job in
Irvine, Orange County, California, 92713, USA
Listed on 2026-08-09
Listing for:
Veritone
Full Time
position Listed on 2026-08-09
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Job Description & How to Apply Below
The role requires a rare blend of strategic vision, commercial SaaS agility, public sector governance (e.g., FedRAMP, NIST, DoD), and public company risk management capabilities (e.g., SOX, SEC disclosure requirements).WHAT YOU'LL DO Strategic Leadership & Governance Security Vision &
Roadmap:
Architect and execute a multi-year, enterprise wide information security and compliance strategy aligned with commercial growth targets and public sector expansion goals.
Executive Presence:
Serve as the primary security advisor to the Board of Directors, Executive Leadership Team and entire organization. Clearly translate complex security risks into actionable business terms.
Team Leadership:
Build, mentor and lead a high performing global security team and compliance organization across security operations, engineering, risk management and regulatory compliance
Security Culture:
Foster a company-wide security first culture through continuous training, awareness programs and cross-functional advocacy
Compliance
FedRAMP & Defense Authorizations:
Lead the strategy, deployment and continuous monitoring required to achieve and maintain FedRAMP (moderate/high), StateRAMP, DoD/CMMC, and CJIS authorizations in cloud environments (AWS Gov Cloud/Azure Government)
Commercial Frameworks:
Oversee compliance and auditing for SOC 2 Type II, ISO 27001, PCI-DSS and global privacy standards (GDPR, CCPA/CPRA)
Public Company Compliance:
Partner with legal, finance and internal audit teams to maintain robust IT general controls (ITGCs) for SOX compliance and support SEC cybersecurity disclosure requirements
Security Operations, Architecture & Incident Response Cloud & Product Architecture:
Partner with Enterprise Architecture, Infrastructure, and Engineering teams to embed security controls into multi-tenant SaaS platforms, CI/CD pipelines, and cloud environments.
Threat & Vulnerability Management:
Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence operations to proactively address emerging vector threats.
Incident Management:
Oversee breach investigations, threat response protocols, and tabletop exercises, ensuring rapid containment, notification, and mitigation when incidents arise.
Enterprise Risk Management & Operations Third-Party & Vendor Risk:
Establish and enforce third-party risk management (TPRM) programs to audit and secure vendor ecosystems, software supply chains, and external partners.
M&A Due Diligence:
Lead security and compliance due diligence for mergers and acquisitions, driving post-acquisition security integration strategies.
Business Continuity & Resilience:
Construct policies and operational frameworks for Business Continuity Planning (BCP), Disaster Recovery (DR), loss prevention, and fraud prevention.
WHAT YOU'LL NEED
Education:
Bachelor of Science degree in Computer Science, Cybersecurity, Computer Engineering, Information Technology, or equivalent technical discipline.
Executive
Experience:
10+ years of progressive leadership experience in information security, cloud architecture, and compliance within a global, publicly traded cloud/SaaS technology company.
Proven FedRAMP Track Record:
Hands-on experience leading a cloud solution through the FedRAMP authorization lifecycle (PMO/JAB or Agency route) and continuous monitoring in AWS and/or Azure cloud environments.
Dual-Domain Capability:
Equal fluency in scaling commercial enterprise SaaS security and navigating rigid public sector regulatory landscapes (NIST 800-53, NIST 800-171, CMMC, CJIS, FISMA).Executive Presence & Communication:
Exceptional ability to communicate…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×