We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
New

Vice President, Information Security

SWCA Environmental Consultants
United States, Arizona, Phoenix
20 East Thomas Road (Show on map)
Sep 12, 2026
About the opportunity

SWCA Environmental Consultants is seeking a strategic, business-oriented, and highly experienced Vice President, Information Security to lead the organization's cybersecurity, governance, risk, compliance, business continuity, resilience, and information protection programs.

Reporting to the Chief Digital Information Officer (CDIO), the Vice President, Information Security serves as SWCA's senior cybersecurity executive and trusted advisor on cyber risk, regulatory compliance, client data protection, operational resilience, and emerging technology risk.

This executive will set enterprise security direction, strengthen cyber resilience, and enable responsible growth, innovation, AI adoption, and digital transformation across SWCA.

The role will lead security operations, governance, regulatory readiness, data protection, third-party risk, business continuity, and federal compliance initiatives including CUI and CMMC readiness. The Vice President will partner with executive leadership, operations, business development, legal, HR, finance, and technology teams to ensure security protects SWCA while enabling business objectives.

What You Will Bring to the Team:

  • Executive presence with the ability to advise senior leaders, clients, and the Board.
  • Business-minded, risk-based decision maker who balances protection, operational enablement, and growth.
  • Deep expertise in cybersecurity, compliance, resilience, data protection, and emerging technology governance.
  • Collaborative leader who builds trust across business, technology, legal, HR, finance, and operations teams.
  • Passion for developing people, strengthening culture, and building high-performing teams.

Please include a Cover Letter to be considered for this position.

Application Deadline: Sunday, September 27, 2026 at 5PM Pacific Time.


What you will accomplish

Information Security Strategy & Executive Leadership
  • Define and execute an enterprise cybersecurity strategy aligned with SWCA's business objectives, risk appetite, and growth plans.
  • Serve as the senior executive advisor on cyber risk, regulatory obligations, emerging threats, and security investments.
  • Establish executive-level reporting, KPIs, maturity roadmaps, and governance mechanisms that demonstrate program effectiveness.
  • Benchmark capabilities against leading frameworks and translate findings into practical, risk-based improvement plans.
Security Operations & Cyber Risk Management
  • Lead enterprise security operations across threat detection, incident response, vulnerability management, endpoint protection, identity and access management, and security monitoring.
  • Own cyber incident management, crisis response, ransomware preparedness, and recovery planning.
  • Oversee security investigations, event analysis, and continuous improvement of SWCA's security posture.
  • Ensure effective protection of cloud, SaaS, endpoint, collaboration, and core business platforms.
Governance, Risk & Compliance
  • Lead the enterprise Governance, Risk & Compliance program, including policies, standards, control frameworks, and risk acceptance processes.
  • Oversee cyber risk assessments, enterprise risk registers, executive risk reviews, and security governance forums.
  • Establish mature third-party and supply chain risk management capabilities.
  • Coordinate client security assessments, audits, due diligence reviews, questionnaires, and contractual security requirements.
CUI, Federal Compliance & Security Assurance
  • Lead CUI, NIST 800-171, DFARS, CMMC, and federal cybersecurity readiness initiatives.
  • Design and govern secure operating environments, enclave requirements, segmentation, data handling, and access controls for regulated data.
  • Maintain System Security Plans, Plans of Action & Milestones, audit evidence, and compliance governance processes.
  • Partner with federal clients, assessors, auditors, and regulatory stakeholders to demonstrate compliance and readiness.
Data Protection & Information Governance
  • Develop the enterprise data protection strategy, including information classification, handling standards, and Data Loss Prevention governance.
  • Protect sensitive client information, project data, environmental and geospatial data, and intellectual property.
  • Partner with legal, compliance, HR, and business leaders to embed information governance and insider risk controls into business processes.
Contractual Risk, Compliance & Data Governance
  • Lead the cybersecurity review of client, partner, subcontractor, and vendor agreements to identify security, privacy, compliance, data protection, incident response, and regulatory obligations.
  • Partner with Legal, Procurement, Contracts, and business leaders to assess and negotiate cybersecurity, information security, CUI, data management, privacy, AI, and compliance requirements.
  • Establish processes to evaluate contractual risks associated with data retention, data sovereignty, cybersecurity obligations, audit rights, breach notification requirements, and third-party security expectations.
  • Ensure contractual security and compliance requirements are translated into operational controls, policies, governance processes, and reporting obligations.
  • Advise executive leadership on contractual cyber risk exposure and emerging compliance obligations associated with client and government agreements.
Business Continuity & Operational Resilience
  • Own enterprise business continuity, crisis management, cyber recovery, and operational resilience programs.
  • Develop and maintain continuity plans, incident response plans, recovery objectives, and resilience frameworks.
  • Lead business impact analyses, tabletop exercises, preparedness activities, and cross-functional disruption response planning.
  • Partner with technology leaders to ensure disaster recovery capabilities meet business continuity requirements.
AI Security & Emerging Technology Governance
  • Establish security and governance standards for AI-enabled business solutions, enterprise AI platforms, automation, and emerging technologies.
  • Assess cybersecurity, privacy, regulatory, intellectual property, and client-obligation risks associated with generative AI and evolving digital platforms.
  • Partner with business and technology leaders to enable responsible, secure adoption of AI capabilities.
Security Architecture & Technology Governance
  • Establish enterprise security architecture standards, secure design principles, and security-by-design practices.
  • Provide security oversight for major technology initiatives, architecture decisions, and high-risk business changes.
  • Lead Zero Trust strategy development and partner with technology leaders to evaluate emerging technology risks.
Client Trust, Revenue Enablement & Strategic Partnerships
  • Partner with business development and operations teams to support opportunities requiring strong cybersecurity, compliance, and client-assurance capabilities.
  • Participate in client security reviews, due diligence activities, and security capability discussions.
  • Support federal, utility, critical infrastructure, and regulated client pursuits through credible security and compliance programs.
  • Enable secure collaboration with clients, partners, subcontractors, and project teams.
Leadership & Organizational Development
  • Build, lead, and develop a high-performing Information Security organization.
  • Mentor security leaders and cybersecurity professionals; establish talent development and succession planning strategies.
  • Promote security awareness, accountability, collaboration, and operational excellence across SWCA.
Applied = 0

(web-665cd84569-cc6jf)