About the opportunitySWCA Environmental Consultants is seeking a strategic, business-oriented, and highly experienced Vice President, Information Security to lead the organization's cybersecurity, governance, risk, compliance, business continuity, resilience, and information protection programs.
Reporting to the Chief Digital Information Officer (CDIO), the Vice President, Information Security serves as SWCA's senior cybersecurity executive and trusted advisor on cyber risk, regulatory compliance, client data protection, operational resilience, and emerging technology risk.
This executive will set enterprise security direction, strengthen cyber resilience, and enable responsible growth, innovation, AI adoption, and digital transformation across SWCA.
The role will lead security operations, governance, regulatory readiness, data protection, third-party risk, business continuity, and federal compliance initiatives including CUI and CMMC readiness. The Vice President will partner with executive leadership, operations, business development, legal, HR, finance, and technology teams to ensure security protects SWCA while enabling business objectives.
What You Will Bring to the Team:
- Executive presence with the ability to advise senior leaders, clients, and the Board.
- Business-minded, risk-based decision maker who balances protection, operational enablement, and growth.
- Deep expertise in cybersecurity, compliance, resilience, data protection, and emerging technology governance.
- Collaborative leader who builds trust across business, technology, legal, HR, finance, and operations teams.
- Passion for developing people, strengthening culture, and building high-performing teams.
Please include a Cover Letter to be considered for this position.
Application Deadline: Sunday, September 27, 2026 at 5PM Pacific Time.
What you will accomplish
Information Security Strategy & Executive Leadership
- Define and execute an enterprise cybersecurity strategy aligned with SWCA's business objectives, risk appetite, and growth plans.
- Serve as the senior executive advisor on cyber risk, regulatory obligations, emerging threats, and security investments.
- Establish executive-level reporting, KPIs, maturity roadmaps, and governance mechanisms that demonstrate program effectiveness.
- Benchmark capabilities against leading frameworks and translate findings into practical, risk-based improvement plans.
Security Operations & Cyber Risk Management
- Lead enterprise security operations across threat detection, incident response, vulnerability management, endpoint protection, identity and access management, and security monitoring.
- Own cyber incident management, crisis response, ransomware preparedness, and recovery planning.
- Oversee security investigations, event analysis, and continuous improvement of SWCA's security posture.
- Ensure effective protection of cloud, SaaS, endpoint, collaboration, and core business platforms.
Governance, Risk & Compliance
- Lead the enterprise Governance, Risk & Compliance program, including policies, standards, control frameworks, and risk acceptance processes.
- Oversee cyber risk assessments, enterprise risk registers, executive risk reviews, and security governance forums.
- Establish mature third-party and supply chain risk management capabilities.
- Coordinate client security assessments, audits, due diligence reviews, questionnaires, and contractual security requirements.
CUI, Federal Compliance & Security Assurance
- Lead CUI, NIST 800-171, DFARS, CMMC, and federal cybersecurity readiness initiatives.
- Design and govern secure operating environments, enclave requirements, segmentation, data handling, and access controls for regulated data.
- Maintain System Security Plans, Plans of Action & Milestones, audit evidence, and compliance governance processes.
- Partner with federal clients, assessors, auditors, and regulatory stakeholders to demonstrate compliance and readiness.
Data Protection & Information Governance
- Develop the enterprise data protection strategy, including information classification, handling standards, and Data Loss Prevention governance.
- Protect sensitive client information, project data, environmental and geospatial data, and intellectual property.
- Partner with legal, compliance, HR, and business leaders to embed information governance and insider risk controls into business processes.
Contractual Risk, Compliance & Data Governance
- Lead the cybersecurity review of client, partner, subcontractor, and vendor agreements to identify security, privacy, compliance, data protection, incident response, and regulatory obligations.
- Partner with Legal, Procurement, Contracts, and business leaders to assess and negotiate cybersecurity, information security, CUI, data management, privacy, AI, and compliance requirements.
- Establish processes to evaluate contractual risks associated with data retention, data sovereignty, cybersecurity obligations, audit rights, breach notification requirements, and third-party security expectations.
- Ensure contractual security and compliance requirements are translated into operational controls, policies, governance processes, and reporting obligations.
- Advise executive leadership on contractual cyber risk exposure and emerging compliance obligations associated with client and government agreements.
Business Continuity & Operational Resilience
- Own enterprise business continuity, crisis management, cyber recovery, and operational resilience programs.
- Develop and maintain continuity plans, incident response plans, recovery objectives, and resilience frameworks.
- Lead business impact analyses, tabletop exercises, preparedness activities, and cross-functional disruption response planning.
- Partner with technology leaders to ensure disaster recovery capabilities meet business continuity requirements.
AI Security & Emerging Technology Governance
- Establish security and governance standards for AI-enabled business solutions, enterprise AI platforms, automation, and emerging technologies.
- Assess cybersecurity, privacy, regulatory, intellectual property, and client-obligation risks associated with generative AI and evolving digital platforms.
- Partner with business and technology leaders to enable responsible, secure adoption of AI capabilities.
Security Architecture & Technology Governance
- Establish enterprise security architecture standards, secure design principles, and security-by-design practices.
- Provide security oversight for major technology initiatives, architecture decisions, and high-risk business changes.
- Lead Zero Trust strategy development and partner with technology leaders to evaluate emerging technology risks.
Client Trust, Revenue Enablement & Strategic Partnerships
- Partner with business development and operations teams to support opportunities requiring strong cybersecurity, compliance, and client-assurance capabilities.
- Participate in client security reviews, due diligence activities, and security capability discussions.
- Support federal, utility, critical infrastructure, and regulated client pursuits through credible security and compliance programs.
- Enable secure collaboration with clients, partners, subcontractors, and project teams.
Leadership & Organizational Development
- Build, lead, and develop a high-performing Information Security organization.
- Mentor security leaders and cybersecurity professionals; establish talent development and succession planning strategies.
- Promote security awareness, accountability, collaboration, and operational excellence across SWCA.
Minimum Qualifications
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or related discipline.
- 15+ years of progressive cybersecurity and technology leadership experience, including 7+ years leading enterprise security organizations or programs.
- Experience as a CISO, VP Information Security, Director of Information Security, or equivalent senior security leadership role.
- Demonstrated success leading cybersecurity programs in geographically distributed organizations.
- Deep expertise across cybersecurity strategy, GRC, security operations, incident response, security architecture, identity and access management, third-party risk, and business continuity.
- Hands-on leadership experience with CUI governance, NIST 800-171 controls, CMMC readiness, SSPs, POA&Ms, and compliance governance programs.
- Strong executive communication, stakeholder influence, and Board-level presentation skills.
Preferred Qualifications
- Experience supporting organizations that manage CUI, perform federal contract work, or support utility, critical infrastructure, or regulated clients.
- Experience in AEC, environmental consulting, engineering services, professional services, federal contracting, or regulated industries.
- Master's degree preferred.
- Experience with GCC, GCC High, secure enclave environments, or enterprise GRC transformations.
- Familiarity with Autodesk, GIS, BIM, geospatial platforms, and engineering collaboration ecosystems.
- CISSP, CISM, CRISC, CCSP, CGRC, or equivalent senior security certification.
- CMMC Registered Practitioner, CMMC Certified Professional, or comparable federal compliance credential.
- Microsoft, Azure, AWS Security, ITIL, or related technology certifications.
Pay Range
SWCA is committed to salary equity and salary transparency for all its employees. In alignment with this commitment, SWCA posts good faith pay ranges in all its advertised job postings to promote pay equity and transparency. An employee in this US-based position can expect an annual salary of $212,300.00 to $278,330. Actual pay within this range may depend on experience, qualifications, geographic location, client requirements where applicable, and other factors permitted by law. Bonus targets are up to 50% of salary depending upon both company and individual performance. Candidates are also encouraged to consider SWCA’s Total Rewards package, which includes a competitive benefits package (https://www.swca.com/careers/benefits-wellness/), forward-thinking workplace flexibility, outstanding corporate culture, award-winning career development, and more.
#LI-KB1