EverCommerce: Senior Director Information Security

EverCommerce

Denver (CO)

On-site

USD 225,000 - 275,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible work location (remote/on-site
Wellness stipend
401k with match
Generous PTO
Employee Stock Purchase Program

Job summary

EverCommerce is seeking a Senior Director Information Security to lead a scalable security program for a diverse SaaS portfolio. The role blends strategic planning with hands-on execution, collaborating with Legal, Compliance, People, and Product teams to enable growth while managing cyber risk.

The position focuses on DevSecOps, platform security, incident response, and continuous compliance across SOX, HIPAA, PCI DSS, and NIST. Excellent executive communication and mentorship are essential.

Qualifications

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Computer Engineering, or related field.
  • 12+ years of progressive leadership across information security domains including cloud and software platform security.
  • 6+ years of direct people leadership in multi-disciplinary teams within SaaS or enterprise tech.
  • Hands-on engineering in AWS, IaC (Terraform/CloudFormation), and container orchestration (ECS/EKS/Docker).
  • Proven experience building/modernizing SIEM/SOAR pipelines, automated detection, and IR operations.
  • Experience designing continuous compliance programs under SOX 404(b), HIPAA, PCI DSS, or SEC.
  • Excellent executive communication translating risk into business metrics.

Responsibilities

  • Engineering-First Security Architecture & DevSecOps (Shift‑Left).
  • Platform Security-as-Code with Terraform modules and account isolation.
  • Shift-Left AppSec & Container Security with automated gates in CI/CD.
  • Golden Container & AMI approval pipelines to prevent drift.
  • Central Secrets & Cryptographic lifecycle with rotation policies.
  • Incident Response & Cyber Resiliency leadership.
  • 24x7 Detection & Threat Hunting with SOC modernization.
  • Zero-Code Infrastructure Observability using eBPF/OpenTelemetry.
  • Crisis Management & Incident Response with RCA & exec comms.
  • Adversary Emulation & Red/Purple Teaming across HIPAA/PCI/SEC platforms.

Skills

Security leadership
Cloud security
Security architecture
Executive communication
Cross-functional collaboration
Threat modeling

Education

Bachelor’s or Master’s in CS/Cybersecurity/Engineering

Tools

AWS
Terraform/CloudFormation
ECS/EKS/Docker
Elastic SIEM
Torq SOAR
Okta
Netskope
TruffleHog
PAM
Lumos AI

Job description

EverCommerce (Nasdaq: EVCM) is a leading service commerce platform, providing vertically-tailored, integrated SaaS solutions that help more than 745,000 global service-based businesses accelerate growth, streamline operations, and increase retention. Its modern digital and mobile applications create predictable, informed, and convenient experiences between customers and their service professionals. With its EverPro, EverHealth, and EverWell brands specializing in Home, Health, and Wellness service industries, EverCommerce provides end-to-end business management software, embedded payment acceptance, marketing technology, and customer experience applications. Learn more atEverCommerce.com.

We are building an extraordinary company and looking for talented, energetic, and motivated people to join our team. You can learn more about our Company, Culture and Values here: https://www.evercommerce.com/about-us/careers/.

This role reports to the Chief Information Security Officer (CISO) and requires a hands‑on cybersecurity leader who can balance strategic planning with operational execution, and is responsible for maturing a scalable, business‑aligned security program supporting a diverse portfolio of dozens of SaaS products across multiple vertical business units. The Senior Director Information Security partners closely with the multiple groups including Vertical Business Product Development, Legal, Compliance, the People Team, and senior leadership to ensure security enables innovation while effectively managing cyber risk.

The ideal candidate is an experienced security leader capable of balancing strategic planning with operational execution in a fast‑paced, acquisition‑driven SaaS organization.

Core Responsibilities
  • Engineering-First Security Architecture & DevSecOps (Shift‑Left)
  • Platform Security-as-Code: Partner with Platform Engineering to enforce mandatory security baselines, Terraform modules, and AWS Control Tower account isolation.
  • Shift-Left AppSec & Container Security: Embed automated security gates (SAST, DAST, SCA, dependency analysis, and TruffleHog secret scanning) directly into GitHub CI/CD pipelines.
  • Golden Container & AMI Approval: Establish signing, scanning, and approval pipelines for the Central Golden Container Registry to eliminate base‑image vulnerability drift across production.
  • Central Secrets & Cryptographic Lifecycle: Mandate enterprise-wide AWS Secrets Manager and Vault architectures, enforcing automated 60/90-day rotation and eliminating plain‑text secrets across staging and production
  • Incident Response & Cyber Resiliency
  • 24x7 Detection & Threat Hunting: Direct the modernization of the Security Operations Center (SOC), optimizing SIEM telemetry (Elastic Cloud / ECS log schemas) and SOAR automation (Torque).
  • Zero-Code Infrastructure Observability: Leverage Linux kernel-level telemetry (eBPF and OpenTelemetry collectors) baked into base infrastructure to catch unauthorized API access, anomalous database queries, and lateral movement out-of-process
  • Crisis Management & Incident Response: Lead enterprise incident response, digital forensics, root cause analysis (RCA), and executive crisis communications.
  • Adversary Emulation & Offensive Security (Red/Purple Teaming): Direct internal and contingent red-team penetration testing across all HIPAA, PCI, and proprietary SaaS platforms, driving cross-team CTF exercises and threat modeling.
  • Continuous Trust & Automated Compliance (GRC Modernization)
  • Continuous Compliance Automation: Transition GRC from point-in-time manual evidence collection to API-driven, continuous control validation supporting SOX 404(b), HIPAA, PCI DSS, NIST CSF, EHNAC, and SEC disclosure requirements.
  • Centralized Risk Governance: Maintain an auditable, real-time enterprise Risk Register, eliminating fragmented policy exceptions in email and chat tools.
  • Third-Party Risk & Customer Trust: Standardize vendor risk management workflows (Coupa/security assessments) and provide automated security assurance documentation for enterprise customer deals.
  • Hub-and-Spoke VBU Partnership & Culture
  • Embedded Security Spokes: Deploy and lead dedicated Security Engineering "Spokes" who sit directly in Vertical Business Units product sprint planning to eliminate delivery roadblocks upfront.
  • Security & Cloud Guilds: Foster an engineering mindset across the broader technology team, establishing internal training guilds to upskill engineers in secure coding, automation, and modern cloud operations
  • Additional core responsibilities
  • Develop multi-year cybersecurity strategic plans and roadmaps.
  • Align security investments with business priorities.
  • Support mergers, acquisitions, and divestitures from a cybersecurity perspective.
  • Drive AI and automation across security operations.
Required Qualifications & Leadership Profile
  • Education: Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical discipline (or equivalent practical experience).
  • Experience Level:
  • 12+ years of progressive leadership with significant focus across multiple information security domains, including cloud security, and software platform security, security strategy, architecture, engineering, controls, testing, vulnerability management, incident response, and cyber resiliency.
  • 6+ years of direct people leadership experience leading multi‑disciplinary teams (Architecture, SecOps, IR, GRC) in high-growth, public SaaS or enterprise technology companies
  • Technical Depth:
    • Demonstrated hands‑on engineering background in AWS cloud infrastructure, Infrastructure-as-Code (Terraform/CloudFormation), and container orchestration (ECS, EKS, Docker).
    • Proven track record building or modernizing SIEM/SOAR pipelines, automated detection engineering, and incident response operations
    • Direct experience designing and executing continuous compliance programs under SOX 404(b), HIPAA, PCI DSS, or SEC reporting frameworks.
  • Executive & Communication Skills:
    • Exceptional ability to translate complex security risks into clear business metrics (MTTD, MTTR, exposure burn-down) for C-suite executives and Board Audit Committees
  • Strong collaborative acumen to lead through influence in a decentralized, multi-business unit operating model
  • Strong knowledge of or leading enterprise security architecture, building and maturing security GRC programs, and deep knowledge of cyber threat landscapes, attacker tactics, techniques, and procedures (TTPs).
Preferred Qualifications
  • Experience leading security due diligence and post-merger integration for high-volume M&A activity
  • Direct experience with modern security tools: Information Asset Inventory systems, SIEM tools, Elastic Cloud, Torq SOAR, CrowdStrike, EDR/MDR/XDR, Okta, Netskope, AWS Secrets Manager, PAM, TruffleHog, and Lumos AI.
  • Recognized security and architecture credentials (e.g., CISSP, CISM, CISA, GMON, CCSP, AWS Certified Security Specialty)
  • Experience working with SaaS software development and product teams.
  • Experience working with distributed and remote team environments.
Leadership Expectations

The Senior Director Information Security is expected to:

  • Inspire high-performing security teams.
  • Develop future security leaders.
  • Build trusted relationships with multiple levels of leadership and business stakeholders.
  • Communicate complex cybersecurity risks in business terms.
  • Foster collaboration across decentralized business units.
  • Promote a culture of accountability, innovation, and operational excellence.
  • Lead through influence in a matrixed organizational environment.
Where

This role can be remote or hybrid if within close proximity to an EverCommerce location. The EverCommerce team is distributed globally, with teams in the U.S., Canada, the U.K., Jordan, New Zealand, and Australia. With a widely distributed team, we are used to working remotely across different time zones. This role can be based anywhere in the United States. – if you’re close to one of our offices, we can set you up in‑office or you can work 100% remotely. Please note that you must be eligible to work without sponsorship to qualify for this position, and this role may require travel of up to our Corporate Headquarters in Denver, Colorado, or to other office locations around North America.

Benefits and Perks
  • Flexibility to work where/how you want within your country of employment – in‑office, remote, or hybrid
  • Day 1 access to a robust health and wellness benefits, including an annual wellness stipend
  • 401k with up to a 4% match and immediate vesting
  • Flexible and generous (FTO) time‑off
  • Employee Stock Purchase Program
Compensation

The target base compensation for this position is between $225,000 – $275,000 USD per year with a variable component included in most US locations. Final offer amounts are determined by multiple factors including location, local market variances, and candidate experience and expertise, and may vary from the amounts listed above.

EverCommerce is an equal opportunity employer and we value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender identity, sexual orientation, age, marital status, veteran status, or disability status. We look forward to reviewing your credentials and getting to know more about your experience!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

EverCommerce - Security Engineer
EverCommerce - Security Engineer

Talanto • Denver (CO), Northern (KY)

Hybrid
USD 130,000 - 150,000
Continued professional development
Health and wellness benefits (Day 1)
401k with up to 4% match
+2
EverCommerce - Senior Site Reliability Engineer
EverCommerce - Senior Site Reliability Engineer

EverCommerce • Denver (CO)

Hybrid
USD 110,000 - 130,000
Flexible work environment
Health and wellness benefits
401(k) with company match
+2
VP, Chief Information Security Officer
VP, Chief Information Security Officer

BigCommerce Pty. • Austin (TX), Northern (KY)

On-site
USD 240,000 - 305,000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

Cacheflow • Austin (TX)

Hybrid
USD 240,000 - 305,000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

Commerce • Austin (TX), Northern (KY)

On-site
USD 240,000 - 305,000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

BigCommerce Pty • Austin (TX), Northern (KY)

On-site
USD 240,000 - 305,000
VP, Chief Information Security Officer
VP, Chief Information Security Officer

Commerce.com • Austin (TX)

Hybrid
USD 240,000 - 305,000
Hybrid work model
Senior Director, Information Security and Platform Security
Senior Director, Information Security and Platform Security

EverCommerce • Denver (CO)

On-site
USD 225,000 - 275,000
Flexible work location (remote/on-site
Wellness stipend
401k with match
+2
Senior Security & Compliance Engineer
Senior Security & Compliance Engineer

LHH • Smyrna (GA)

On-site
USD 120,000 - 190,000
Medical, Dental, Vision
Life Insurance
Short-term Disability
+4
Cyber Solution Area Lead
Cyber Solution Area Lead

ECS • Fairfax (VA)

On-site
USD 275,000 - 350,000
Executive leadership exposure