JobRaahGet matched free

Jobs

VP, Information Security and Compliance

veritone · Irvine, CA · United States · On-site

Pay: USD 200,000 – 250,000 a year

Posted Aug 24, 2026

Apply with JobRaah

Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.

POSITION SUMMARY The VP, Information Security & Compliance, will serve as the Company’s Chief Information Security Officer and executive champion for our global enterprise security and compliance programs. Reporting directly to the Chief Legal Officer, this role will design, execute and mature an overarching security strategy that protects customer data, intellectual property and infrastructure across all of Veritone’s business units, including, but not limited to commercial SaaS and high stringency public sector (federal, state and defense) environments. The role requires a rare blend of strategic vision, commercial SaaS agility, public sector governance (e.g., FedRAMP, NIST, DoD), and public company risk management capabilities (e.g., SOX, SEC disclosure requirements). ‎  WHAT YOU'LL DO Strategic Leadership & Governance Security Vision & Roadmap: Architect and execute a multi-year, enterprise wide information security and compliance strategy aligned with commercial growth targets and public sector expansion goals. Executive Presence: Serve as the primary security advisor to the Board of Directors, Executive Leadership Team and entire organization. Clearly translate complex security risks into actionable business terms. Team Leadership: Build, mentor and lead a high performing global security team and compliance organization across security operations, engineering, risk management and regulatory compliance Security Culture: Foster a company-wide security first culture through continuous training, awareness programs and cross-functional advocacy Compliance FedRAMP & Defense Authorizations: Lead the strategy, deployment and continuous monitoring required to achieve and maintain FedRAMP (moderate/high), StateRAMP, DoD/CMMC, and CJIS authorizations in cloud environments (AWS GovCloud/Azure Government) Commercial Frameworks: Oversee compliance and auditing for SOC 2 Type II, ISO 27001, PCI-DSS and global privacy standards (GDPR, CCPA/CPRA) Public Company Compliance: Partner with legal, finance and internal audit teams to maintain robust IT general controls (ITGCs) for SOX compliance and support SEC cybersecurity disclosure requirements Security Operations, Architecture & Incident Response Cloud & Product Architecture: Partner with Enterprise Architecture, Infrastructure, and Engineering teams to embed security controls into multi-tenant SaaS platforms, CI/CD pipelines, and cloud environments. Threat & Vulnerability Management: Direct vulnerability scanning, penetration testing, intrusion detection, and threat intelligence operations to proactively address emerging vector threats. Incident Management: Oversee breach investigations, threat response protocols, and tabletop exercises, ensuring rapid containment, notification, and mitigation when incidents arise. Enterprise Risk Management & Operations Third-Party & Vendor Risk: Establish and enforce third-party risk management (TPRM) programs to audit and…