ForgeApply
Try it free

ForgeApply · Job listing

EverCommerce: Senior Director Information Security

EverCommerce

Remote · Denver, Colorado | Remote (Colorado), US$225k – $275k

See all 23 open roles at EverCommerce

Tailor your resume for this EverCommerce job in about a minute.

ForgeApply tailors your resume and cover letter to this exact posting, then hands you a ready-to-submit application for EverCommerce's site. Free trial, no card required.

About this role

EverCommerce (Nasdaq: EVCM) is a leading service commerce platform, providing   vertically-tailored , integrated SaaS solutions that help more than   745 ,000 global service-based businesses accelerate growth, streamline operations, and increase retention. Its modern digital and mobile applications create predictable, informed, and convenient experiences between customers and their service professionals. With its EverPro, EverHealth, and EverWell brands specializing in Home, Health, and Wellness service industries, EverCommerce provides end-to-end business management software, embedded payment acceptance, marketing technology, and customer experience applications. Learn more at EverCommerce.com.  

We are building an extraordinary company and looking for talented, energetic, and motivated people to join our team.   You can learn more about our   Company,   Culture and Values here:   https://www.evercommerce.com/about-us/careers/    

This role reports to the Chief Information Security Officer (CISO) and requires a hands-on cybersecurity leader who can balance strategic planning with operational execution, and is responsible for maturing a scalable, business-aligned security program supporting a diverse portfolio of dozens of SaaS products across multiple vertical business units. The Senior Director Information Security partners closely with the multiple groups including Vertical Business Product Development, Legal, Compliance, the People Team, and senior leadership to ensure security enables innovation while effectively managing cyber risk. The ideal candidate is an experienced security leader capable of balancing strategic planning with operational execution in a fast-paced, acquisition-driven SaaS organization.

Core Responsibilities 1. Engineering-First Security Architecture & DevSecOps (Shift-Left) • Platform Security-as-Code:  Partner with Platform Engineering to enforce mandatory security baselines, Terraform modules, and AWS Control Tower account isolation. • Shift-Left AppSec & Container Security:  Embed automated security gates (SAST, DAST, SCA, dependency analysis, and TruffleHog secret scanning) directly into GitHub CI/CD pipelines. • Golden Container & AMI Approval:  Establish signing, scanning, and approval pipelines for the Central Golden Container Registry to eliminate base-image vulnerability drift across production. • Central Secrets & Cryptographic Lifecycle:  Mandate enterprise-wide AWS Secrets Manager and Vault architectures, enforcing automated 60/90-day rotation and eliminating plain-text secrets across staging and production

2. Incident Response & Cyber Resiliency • 24x7 Detection & Threat Hunting:  Direct the modernization of the Security Operations Center (SOC), optimizing SIEM telemetry (Elastic Cloud / ECS log schemas) and SOAR automation (Torque). • Zero-Code Infrastructure Observability:  Leverage Linux kernel-level telemetry (eBPF and OpenTelemetry collectors) baked into base infrastructure to catch unauthorized API access, anomalous database queries, and lateral movement out-of-process • Crisis Management & Incident Response:  Lead enterprise incident response, digital forensics, root cause analysis (RCA), and executive crisis communications. • Adversary Emulation & Offensive Security (Red/Purple Teaming):  Direct internal and contingent red-team penetration testing across all HIPAA, PCI, and proprietary SaaS platforms, driving cross-team CTF exercises and threat modeling.

3. Continuous Trust & Automated Compliance (GRC Modernization) • Continuous Compliance Automation:  Transition GRC from point-in-time manual evidence collection to API-driven, continuous control validation supporting  SOX 404(b), HIPAA, PCI DSS, NIST CSF, EHNAC, and SEC disclosure requirements . • Centralized Risk Governance:  Maintain an auditable, real-time enterprise Risk Register, eliminating fragmented policy exceptions in email and chat tools. • Third-Party Risk & Customer Trust:  Standardize vendor risk management workflows (Coupa/security assessments) and provide automated security assurance documentation for enterprise customer deals.

4. Hub-and-Spoke VBU Partnership & Culture • Embedded Security Spokes:  Deploy and lead dedicated Security Engineering "Spokes" who sit directly in Vertical Business Units product sprint planning to eliminate delivery roadblocks upfront. • Security & Cloud Guilds:  Foster an engineering mindset across the broader technology team, establishing internal training guilds to upskill engineers in secure coding, automation, and modern cloud operations

5. Additional core responsibilities • Develop multi-year cybersecurity strategic plans and roadmaps. • Align security investments with business priorities. • Support mergers, acquisitions, and divestitures from a cybersecurity perspective. • Drive AI and automation across security operations.

Required Qualifications & Leadership Profile • Education:  Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical discipline (or equivalent practical experience). • Experience Level: • 12+ years  of progressive leadership with significant focus across multiple information security domains, including cloud security, and software platform security, security strategy, architecture, engineering, controls, testing, vulnerability management, incident response, and cyber resiliency. • 6+ years  of direct people leadership experience leading multi-disciplinary teams (Architecture, SecOps, IR, GRC) in high-growth, public SaaS or enterprise technology companies • Technical Depth: • Demonstrated hands-on engineering background in  AWS cloud infrastructure , Infrastructure-as-Code (Terraform/CloudFormation), and container orchestration (ECS, EKS, Docker). • Proven track record building or modernizing  SIEM/SOAR pipelines , automated detection engineering, and incident response operations • Direct experience designing and executing continuous compliance programs under  S

Salary insight

The midpoint of this range ($250k) is about 96% above the median disclosed salary for Denver roles listed on ForgeApply ($127k across 1,239 jobs).

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this EverCommerce role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Tailor Your Resume to a Job Description (Step by Step)