EverCommerce: Senior Director Information Security

EverCommerceDenver, CO
$225,000 - $275,000Remote

About The Position

EverCommerce is seeking a Senior Director of Information Security, a hands-on cybersecurity leader who can balance strategic planning with operational execution. This role is responsible for maturing a scalable, business-aligned security program supporting a diverse portfolio of dozens of SaaS products across multiple vertical business units. The Senior Director partners closely with various groups including Vertical Business Product Development, Legal, Compliance, the People Team, and senior leadership to ensure security enables innovation while effectively managing cyber risk. The ideal candidate is an experienced security leader capable of balancing strategic planning with operational execution in a fast-paced, acquisition-driven SaaS organization.

Requirements

  • Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Computer Engineering, or a related technical discipline (or equivalent practical experience).
  • 12+ years of progressive leadership with significant focus across multiple information security domains, including cloud security, and software platform security, security strategy, architecture, engineering, controls, testing, vulnerability management, incident response, and cyber resiliency.
  • 6+ years of direct people leadership experience leading multi-disciplinary teams (Architecture, SecOps, IR, GRC) in high-growth, public SaaS or enterprise technology companies
  • Demonstrated hands-on engineering background in AWS cloud infrastructure, Infrastructure-as-Code (Terraform/CloudFormation), and container orchestration (ECS, EKS, Docker).
  • Proven track record building or modernizing SIEM/SOAR pipelines, automated detection engineering, and incident response operations
  • Direct experience designing and executing continuous compliance programs under SOX 404(b), HIPAA, PCI DSS, or SEC reporting frameworks.
  • Exceptional ability to translate complex security risks into clear business metrics (MTTD, MTTR, exposure burn-down) for C-suite executives and Board Audit Committees
  • Strong collaborative acumen to lead through influence in a decentralized, multi-business unit operating model
  • Strong knowledge of or leading enterprise security architecture, building and maturing security GRC programs, and deep knowledge of cyber threat landscapes, attacker tactics, techniques, and procedures (TTPs).
  • Must be eligible to work without sponsorship.
  • May require travel of up to our Corporate Headquarters in Denver, Colorado, or to other office locations around North America.

Nice To Haves

  • Experience leading security due diligence and post-merger integration for high-volume M&A activity
  • Direct experience with modern security tools: Information Asset Inventory systems, SIEM tools, Elastic Cloud, Torq SOAR, CrowdStrike, EDR/MDR/XDR, Okta, Netskope, AWS Secrets Manager, PAM, TruffleHog, and Lumos AI.
  • Recognized security and architecture credentials (e.g., CISSP, CISM, CISA, GMON, CCSP, AWS Certified Security Specialty)
  • Experience working with SaaS software development and product teams.
  • Experience working with distributed and remote team environments.

Responsibilities

  • Engineering-First Security Architecture & DevSecOps (Shift-Left): Partner with Platform Engineering to enforce mandatory security baselines, Terraform modules, and AWS Control Tower account isolation. Embed automated security gates (SAST, DAST, SCA, dependency analysis, and TruffleHog secret scanning) directly into GitHub CI/CD pipelines. Establish signing, scanning, and approval pipelines for the Central Golden Container Registry to eliminate base-image vulnerability drift across production. Mandate enterprise-wide AWS Secrets Manager and Vault architectures, enforcing automated 60/90-day rotation and eliminating plain-text secrets across staging and production.
  • Incident Response & Cyber Resiliency: Direct the modernization of the Security Operations Center (SOC), optimizing SIEM telemetry (Elastic Cloud / ECS log schemas) and SOAR automation (Torque). Leverage Linux kernel-level telemetry (eBPF and OpenTelemetry collectors) baked into base infrastructure to catch unauthorized API access, anomalous database queries, and lateral movement out-of-process. Lead enterprise incident response, digital forensics, root cause analysis (RCA), and executive crisis communications. Direct internal and contingent red-team penetration testing across all HIPAA, PCI, and proprietary SaaS platforms, driving cross-team CTF exercises and threat modeling.
  • Continuous Trust & Automated Compliance (GRC Modernization): Transition GRC from point-in-time manual evidence collection to API-driven, continuous control validation supporting SOX 404(b), HIPAA, PCI DSS, NIST CSF, EHNAC, and SEC disclosure requirements. Maintain an auditable, real-time enterprise Risk Register, eliminating fragmented policy exceptions in email and chat tools. Standardize vendor risk management workflows (Coupa/security assessments) and provide automated security assurance documentation for enterprise customer deals.
  • Hub-and-Spoke VBU Partnership & Culture: Deploy and lead dedicated Security Engineering "Spokes" who sit directly in Vertical Business Units product sprint planning to eliminate delivery roadblocks upfront. Foster an engineering mindset across the broader technology team, establishing internal training guilds to upskill engineers in secure coding, automation, and modern cloud operations.
  • Develop multi-year cybersecurity strategic plans and roadmaps.
  • Align security investments with business priorities.
  • Support mergers, acquisitions, and divestitures from a cybersecurity perspective.
  • Drive AI and automation across security operations.

Benefits

  • Flexibility to work where/how you want within your country of employment – in-office, remote, or hybrid
  • Day 1 access to a robust health and wellness benefits, including an annual wellness stipend
  • 401k with up to a 4% match and immediate vesting
  • Flexible and generous (FTO) time-off
  • Employee Stock Purchase Program
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service