VP, Security
CivicPlus
Description
Your Impact
We are seeking a Vice President of Security to lead our security, risk, and compliance strategy across a diverse portfolio of SaaS products supporting state and local government customers. As our company continues to grow, a service-oriented security team will be paramount to continue to build secure-by-design applications and make risk informed prioritization. This will help balance innovation, scale, and compliance while ensuring trust with government agencies and residents.
This leader will be responsible for setting the security vision, building resilient security programs, and ensuring compliance with GovRAMP, FedRAMP, CJIS, Commercial Compliance (SOC 2, PCI, etc.) and other public-sector standards. The ideal candidate is a hands-on, modern leader who can partner with engineering, product, operations, and IT stakeholders to embed security into every layer of our platforms and culture.
The Vice President of Security will report to the Chief Product & Technology Officer.
About CivicPlus
At CivicPlus, we strive to bring our company vision to life through innovation and collaboration. Supported by approachable leadership and transparent communication, we're empowered to make an impact on local government and the residents they serve. Grow your career alongside great people, where authenticity is welcome, successes are celebrated, and potential is nurtured.
What You’ll Do
As a VP of Security you will:
Strategic Leadership
- Establish measurable KPIs for security maturity (e.g., time-to-remediate, incident severity, audit readiness) and report quarterly progress to executives and the board.
- Define and execute a comprehensive security strategy aligned with company vision, government compliance requirements, and customer trust.
- Serve as the authority on cybersecurity, risk management, and compliance matters.
- Provide regular updates to cross-functional leaders on risk posture and mitigation.
- Oversee security budget allocation, vendor selection, and ROI optimization for tools and services.
Compliance & Risk Management
- Build and manage security policies, risk assessments, and audit readiness across the enterprise.
- Lead efforts to achieve and maintain GovRAMP and FedRAMP authorizations across multiple product lines.
- Oversee adherence to regulatory frameworks including CJIS, NIST, SOC 2, and other applicable standards.
- Partner with legal for risk management, including TPRM and oversee compliance teams.
Operational Security
- Establish governance processes for security reviews, and penetration testing.
- Develop and run proactive monitoring, detection, and response capabilities.
- Ensure secure multi-cloud and hybrid hosting environments across the product portfolio.
People & Team Building
- Recruit, lead, and mentor security professionals across multiple specialties.
- Drive a “security by design” culture throughout engineering, product, and operations teams.
- Champion security awareness, secure by design across the entire company. Own Security Awareness Training design.
What We’re Looking For
We know that excellent candidates come from diverse backgrounds. Even if you don’t meet 100% of the listed requirements, we encourage you to apply!
Preferred Qualifications:
- 10+ years of experience in cybersecurity, with 5+ years in leadership roles.
- Proven success leading security in SaaS or enterprise software organizations serving the public sector.
- Strong knowledge of GovRAMP, FedRAMP, NIST, and government compliance frameworks.
- Experience with secure cloud architectures, hybrid hosting models, and modern security technologies.
- Strong track record in incident response, risk management, and executive communication.
- Ability to engage with government agencies and communicate security posture with clarity and confidence.
Why CivicPlus?
This role offers:
- Shape the Future of Public-Sector Technology: Drive security strategy for SaaS solutions that directly impact state and local governments, influencing how communities stay safe and connected.
- Executive-Level Influence: Report to the Chief Product & Technology Officer and present to the board, setting the vision for security maturity and risk posture across the organization.
- Lead Mission-Critical Compliance Initiatives: Own high-profile programs like GovRAMP and FedRAMP, ensuring trust and compliance for government agencies and millions of residents.
Our Hiring Process
- Introductory call with Talent Acquisition
- Interview with the Hiring Manager
- Panel Interview with CivicPlus team members, including an interview project activity
- Offer
Note: The process may vary slightly depending on the role.
Additional Information
- CivicPlus is currently unable to provide visa sponsorship for this position now or in the future. Applicants must be authorized to work in the US.
- This position will remain open until January 16, 2026. We encourage you to apply as soon as possible, as applications will be reviewed on a rolling basis, and the posting may close earlier at the discretion of the Talent Acquisition team
Equal Opportunity Commitment
CivicPlus is proud to be an Equal Employment Opportunity employer. We celebrate and support diversity for the benefit of our employees, products, clients, and communities. Reasonable accommodations are available during the interview process.