Senior Director, Information Security

Job not on LinkedIn

🔥 0 minutes ago

🇺🇸 United States – Remote

💵 $225k - $275k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🦅 H1B Visa Sponsor

infoinfo

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of EverCommerce

EverCommerce

1001 - 5000 employees

Founded 2016

🏥 Healthcare

💼 Consulting

📦 Logistics

💰 Private Equity Round on 2019-07

Healthcare • Consulting • Logistics

EverCommerce is the leading service commerce platform, providing vertically-tailored, integrated SaaS solutions to over 500,000 global service-based businesses. Established in 2016, EverCommerce offers software solutions that help businesses market their services, streamline day-to-day operations, and enhance customer engagement. The company specializes in powering the service economy with digital transformation across multiple industries, including Home & Field Services, Health Services, and Fitness & Wellness. EverCommerce's technology aims to accelerate growth, improve operations, and increase retention for small and medium-sized businesses, transforming the way they interact with customers through modern digital and mobile applications.

📋 Description

• Report to the Chief Information Security Officer and mature a scalable, business-aligned security program • Partner with Platform Engineering to enforce security baselines, Terraform modules, and AWS Control Tower account isolation • Embed SAST, DAST, SCA, dependency analysis, and TruffleHog scanning into GitHub CI/CD pipelines • Establish signing, scanning, and approval pipelines for the Central Golden Container Registry • Mandate AWS Secrets Manager and Vault architectures with automated secret rotation • Direct modernization of the 24x7 Security Operations Center, SIEM telemetry, and SOAR automation • Leverage eBPF and OpenTelemetry telemetry to detect unauthorized access, anomalous queries, and lateral movement • Lead enterprise incident response, digital forensics, root cause analysis, and executive crisis communications • Direct red-team penetration testing, CTF exercises, and threat modeling across HIPAA, PCI, and proprietary SaaS platforms • Transition GRC to API-driven continuous control validation for SOX 404(b), HIPAA, PCI DSS, NIST CSF, EHNAC, and SEC requirements • Maintain an auditable, real-time enterprise Risk Register • Standardize vendor risk management and provide automated security assurance documentation for customer deals • Deploy and lead embedded Security Engineering spokes within Vertical Business Units • Establish security and cloud training guilds • Develop multi-year cybersecurity strategies and roadmaps; align investments with business priorities • Support mergers, acquisitions, and divestitures from a cybersecurity perspective • Drive AI and automation across security operations • Inspire teams, develop security leaders, build stakeholder relationships, communicate risk, and foster cross-business collaboration • Travel to Denver headquarters or other North American offices as needed

🎯 Requirements

• Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical discipline (or equivalent practical experience) • 12+ years of progressive leadership experience across multiple information security domains • 6+ years of direct people leadership experience leading multi-disciplinary teams in high-growth, public SaaS or enterprise technology companies • Hands-on engineering background in AWS cloud infrastructure, Infrastructure-as-Code (Terraform/CloudFormation), and container orchestration (ECS, EKS, Docker) • Experience building or modernizing SIEM/SOAR pipelines, automated detection engineering, and incident response operations • Experience designing and executing continuous compliance programs under SOX 404(b), HIPAA, PCI DSS, or SEC reporting frameworks • Ability to translate complex security risks into business metrics for C-suite executives and Board Audit Committees • Strong collaborative acumen and ability to lead through influence in a decentralized, multi-business-unit operating model • Strong knowledge of enterprise security architecture, security GRC programs, and cyber threat landscapes, attacker TTPs • Must be eligible to work without sponsorship • Preferred: security due diligence and post-merger integration experience • Preferred: experience with Information Asset Inventory systems, Elastic Cloud, Torq SOAR, CrowdStrike, EDR/MDR/XDR, Okta, Netskope, AWS Secrets Manager, PAM, TruffleHog, and Lumos AI • Preferred: CISSP, CISM, CISA, GMON, CCSP, AWS Certified Security Specialty, or similar credentials • Preferred: SaaS software development/product-team experience • Preferred: distributed and remote team experience

🏖️ Benefits

• Flexibility to work where/how you want within your country of employment – in-office, remote, or hybrid • Day 1 access to a robust health and wellness benefits, including an annual wellness stipend • 401k with up to a 4% match and immediate vesting • Flexible and generous (FTO) time-off • Employee Stock Purchase Program • Variable component included in most US locations

Apply Now

Similar Jobs

🔥 44 minutes ago

Aledade, Inc.

501 - 1000

🏥 Healthcare

⚕️ Healthcare Insurance

🏢 Enterprise

Senior Security Engineer securing Aledade’s value-based primary care technology. Automating application security, cloud-native defenses, and incident response.

🔥 2 hours ago

VAILEXA

51 - 200

🎯 Recruiter

👥 HR Tech

Product security expert translating EU CRA, EU RED, and IEC 62443 into technical controls. Leading audits, compliance validation, global risk governance, and regulatory programs for Vailexa.

🔥 2 hours ago

US Anesthesia Partners

5001 - 10000

💼 Consulting

🏥 Healthcare

⚕️ Healthcare Insurance

Information Security Architect securing cloud applications and enterprise systems for U.S. Anesthesia Partners. Leading DevSecOps, threat modeling, compliance, and secure architecture governance.

🔥 2 hours ago

Jabil

10,000+ employees

🚘 Automotive

🎖️ Defense

🏥 Healthcare

Information Security Architect securing Jabil’s global manufacturing and technology systems. Leading risk reviews, threat modeling, cloud security, and enterprise architecture initiatives.

🔥 2 hours ago

Jabil

10,000+ employees

🚘 Automotive

🎖️ Defense

🏥 Healthcare

Information Security Architect leading endpoint and server security architecture at Jabil, a global engineering, supply chain, and manufacturing solutions provider. Defining controls, roadmaps, standards, and enterprise security solutions.