EverCommerce: Senior Director Information Security

🏢 EverCommerce · all EverCommerce jobs (43)
📍 United States
💰 USD 225,000 - 275,000 / annual
📅 Posted 2026-09-04 · via Himalayas
🏷 Information-Security-Leadership,Cybersecurity-Architecture,Cloud-Security,Security-Operations,GRC,Senior-Data-Security-Director,Enterprise-Security-Director,Director-of-Information-Security,Senior-Director-Enterprise-Technology-And-Security-Operations
Apply on original site ↗

EverCommerce (Nasdaq: EVCM) is a leading service commerce platform, providingvertically-tailored, integrated SaaS solutions that help more than745,000 global service-based businesses accelerate growth, streamline operations, and increase retention. Its modern digital and mobile applications create predictable, informed, and convenient experiences between customers and their service professionals. With its EverPro, EverHealth, and EverWell brands specializing in Home, Health, and Wellness service industries, EverCommerce provides end-to-end business management software, embedded payment acceptance, marketing technology, and customer experience applications. Learn more at  EverCommerce .com.

We are building an extraordinary company and looking for talented, energetic, and motivated people to join our team.You can learn more about ourCompany,Culture and Values here:

This role reports to the Chief Information Security Officer (CISO) and requires a hands-on cybersecurity leader who can balance strategic planning with operational execution, and is responsible for maturing a scalable, business-aligned security program supporting a diverse portfolio of dozens of SaaS products across multiple vertical business units. The Senior Director Information Security partners closely with the multiple groups including Vertical Business Product Development, Legal, Compliance, the People Team, and senior leadership to ensure security enables innovation while effectively managing cyber risk.

The ideal candidate is an experienced security leader capable of balancing strategic planning with operational execution in a fast-paced, acquisition-driven SaaS organization.
Core Responsibilities

1. Engineering-First Security Architecture & DevSecOps (Shift-Left)

-
Platform Security-as-Code: Partner with Platform Engineering to enforce mandatory security baselines, Terraform modules, and AWS Control Tower account isolation.

-
Shift-Left AppSec & Container Security: Embed automated security gates (SAST, DAST, SCA, dependency analysis, and TruffleHog secret scanning) directly into GitHub CI/CD pipelines.

-
Golden Container & AMI Approval: Establish signing, scanning, and approval pipelines for the Central Golden Container Registry to eliminate base-image vulnerability drift across production.

-
Central Secrets & Cryptographic Lifecycle: Mandate enterprise-wide AWS Secrets Manager and Vault architectures, enforcing automated 60/90-day rotation and eliminating plain-text secrets across staging and production

2. Incident Response & Cyber Resiliency

-
24x7 Detection & Threat Hunting: Direct the modernization of the Security Operations Center (SOC), optimizing SIEM telemetry (Elastic Cloud / ECS log schemas) and SOAR automation (Torque).

-
Zero-Code Infrastructure Observability: Leverage Linux kernel-level telemetry (eBPF and OpenTelemetry collectors) baked into base infrastructure to catch unauthorized API access, anomalous database queries, and lateral movement out-of-process

-
Crisis Management & Incident Response: Lead enterprise incident response, digital forensics, root cause analysis (RCA), and executive crisis communications.

-
Adversary Emulation & Offensive Security (Red/Purple Teaming): Direct internal and contingent red-team penetration testing across all HIPAA, PCI, and proprietary SaaS platforms, driving cross-team CTF exercises and threat modeling.

3. Continuous Trust & Automated Compliance (GRC Modernization)

-
Continuous Compliance Automation: Transition GRC from point-in-time manual evidence collection to API-driven, continuous control validation supporting SOX 404(b), HIPAA, PCI DSS, NIST CSF, EHNAC, and SEC disclosure requirements .

-
Centralized Risk Governance: Maintain an auditable, real-time enterprise Risk Register, eliminating fragmented policy exceptions in email and chat tools.

-
Third-Party Risk & Customer Trust: Standardize vendor risk management workflows (Coupa/security assessments) and pr

← All remote jobs

Get remote jobs like this by email

One weekly digest. No spam, unsubscribe anytime.

Similar for you