Senior Security Engineer

Job not on LinkedIn

October 1

Apply Now
Logo of EverCommerce

EverCommerce

SaaS • B2B • eCommerce

EverCommerce is the leading service commerce platform, providing vertically-tailored, integrated SaaS solutions to over 500,000 global service-based businesses. Established in 2016, EverCommerce offers software solutions that help businesses market their services, streamline day-to-day operations, and enhance customer engagement. The company specializes in powering the service economy with digital transformation across multiple industries, including Home & Field Services, Health Services, and Fitness & Wellness. EverCommerce's technology aims to accelerate growth, improve operations, and increase retention for small and medium-sized businesses, transforming the way they interact with customers through modern digital and mobile applications.

1001 - 5000 employees

Founded 2016

☁️ SaaS

🤝 B2B

🛍️ eCommerce

💰 Private Equity Round on 2019-07

📋 Description

• Create and maintain security architecture and engineering processes and procedures • Design system architectures which meet established cybersecurity requirements and align with customer needs, including security requirements definition, documentation, and communication • Develop security architecture requirements and implementation guidance based on analysis of NIST 800-53 and/or other security control frameworks • Architect, design, implement, maintain, and operate information system security controls and countermeasures • Provide techniques and patterns for securing integration with external security system vendors and/or cloud providers • Lead regular architecture and design reviews to ensure requirements implementation • Evaluate and play an active role in life-cycle management of multiple security technologies • Identify security risks and control gaps within systems, designs, products, data flows, and processes; recommend corrective architecture, integrations, controls, and operations • Participate in development of security requirements, architectures, and documentation to ensure security controls are integrated into new technology deployments • Perform secure architecture and design reviews of new technology and security systems deployments and collaborate with business teams to integrate secure-by-design principles into CI/CD pipelines and Agile development processes • Maintain a clear view of the overall security architecture roadmap and strategic plan • Leverage emerging technologies and advanced security practices to ensure EverCommerce is at the forefront of security for solution groups and customers • Build, maintain and mature security architecture metrics and reporting • Serve as a subject matter expert/contributor measurably improving the overall security framework and program • Mentor junior security engineers and analysts • Additional duties as required and assigned

🎯 Requirements

• At least 7 years of relevant work experience in a technical field (e.g. cybersecurity, software development, or systems administration) • Bachelor's Degree in a technical discipline such as Cyber Security, Information Technology, Computer Science, or Information Systems - or equivalent professional experience • Have at least one current Industry recognized security certifications; CISSP, CISM, CISA, GIAC or commensurate experience • Excellent communication and interpersonal skills, with the ability to communicate and collaborate effectively with cross-functional teams, matrixed organizations, and technical / and non-technical stakeholders • Demonstrated experience with the security, development and/or management of systems compliant to NIST 800-53, NIST CSF, or ISO 27001-2022 security control frameworks • Exceptional knowledge and understanding on the creation/implementation and securing of cloud technologies such AWS and Azure • Knowledge of Information Security risk assessment methodologies and standards • Highly flexible, self-motivated and eager to learn, with a strong passion for cyber security • Excellent verbal and written English communication skills • Must be eligible to work without sponsorship in the United States • May require travel to Corporate Headquarters in Denver, Colorado, or to other office locations around North America • Preferred: • Advanced knowledge regarding common attacks, attack methods, and defense architectures • Experience in securing multi-tenant compute services, microservices and modern APIs • Working knowledge of common web and container-based vulnerabilities • Experience with Information Security policies and procedure development and implementation • Experience developing technical documentation, including reports, proposals, statements of work, and whitepapers

🏖️ Benefits

• Continued investment in your professional development • Day 1 access to a robust health and wellness benefits package, including an annual wellness stipend • 401k with up to a 4% match and immediate vesting • Flexible and generous (FTO) time-off • Employee Stock Purchase Program • Annual bonus opportunity in most US locations

Apply Now

Similar Jobs

September 30

Provide security assessments and vCISO advisory services to higher education institutions at Strata Information Group. Guide security strategy, policies, and incident readiness for diverse clients.

Cloud

Cyber Security

September 30

Design and operate cloud security, detection, DevSecOps and incident response for Istari's engineering platform.

Ansible

AWS

Azure

Cloud

Cyber Security

DNS

Firewalls

Google Cloud Platform

Kubernetes

Linux

MacOS

Python

SDLC

TCP/IP

Terraform

September 30

Provide RMF support, risk assessments, eMASS operations, and COOP planning for DoD-focused clients at Concept Plus, an Oracle Gold Partner consulting firm.

Azure

Cloud

Cyber Security

September 29

Develop digital forensic collectors and CI/CD pipelines. Support ransomware incident response, research threats, and prototype tools at Coveware by Veeam.

AWS

Cyber Security

Linux

MacOS

Python

Rust

Built by Lior Neu-ner. I'd love to hear your feedback — Get in touch via DM or support@remoterocketship.com