×
Register Here to Apply for Jobs or Post Jobs. X

Senior Director Information Security

Job in Yonkers, Westchester County, New York, 10701, USA
Listing for: EverCommerce
Full Time position
Listed on 2026-09-27
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 225000 - 275000 USD Yearly USD 225000.00 275000.00 YEAR
Job Description & How to Apply Below
Position: EverCommerce: Senior Director Information Security

Ever Commerce (Nasdaq: EVCM) is a leading service commerce platform, providingvertically-tailored, integrated SaaS solutions that help more than
745,000 global service-based businesses accelerate growth, streamline operations, and increase retention. Its modern digital and mobile applications create predictable, informed, and convenient experiences between customers and their service professionals. With its Ever Pro, Ever Health, and Ever Well brands specializing in Home, Health, and Wellness service industries, Ever Commerce provides end-to-end business management software, embedded payment acceptance, marketing technology, and customer experience applications.

Learn more

We are building an extraordinary company and looking for talented, energetic, and motivated people to join our team.

You can learn more about our Company,Culture and Values here:

This role reports to the Chief Information Security Officer (CISO) and requires a hands-on cybersecurity leader who can balance strategic planning with operational execution, and is responsible for maturing a scalable, business-aligned security program supporting a diverse portfolio of dozens of SaaS products across multiple vertical business units. The Senior Director Information Security partners closely with the multiple groups including Vertical Business Product Development, Legal, Compliance, the People Team, and senior leadership to ensure security enables innovation while effectively managing cyber risk.

The ideal candidate is an experienced security leader capable of balancing strategic planning with operational execution in a fast-paced, acquisition-driven SaaS organization.

Core Responsibilities

1. Engineering-First Security Architecture & Dev Sec Ops  (Shift-Left)

  • Platform Security-as-Code: Partner with Platform Engineering to enforce mandatory security baselines, Terraform modules, and AWS Control Tower account isolation.
  • Shift-Left App Sec & Container Security: Embed automated security gates (SAST, DAST, SCA, dependency analysis, and Truffle Hog secret scanning) directly into Git Hub CI/CD pipelines.
  • Golden Container & AMI Approval: Establish signing, scanning, and approval pipelines for the Central Golden Container Registry to eliminate base-image vulnerability drift across production.
  • Central Secrets & Cryptographic Lifecycle: Mandate enterprise-wide AWS Secrets Manager and Vault architectures, enforcing automated 60/90-day rotation and eliminating plain-text secrets across staging and production

2. Incident Response & Cyber Resiliency

  • 24x7 Detection & Threat Hunting: Direct the modernization of the Security Operations Center (SOC), optimizing SIEM telemetry (Elastic Cloud / ECS log schemas) and SOAR automation (Torque).
  • Zero-Code Infrastructure Observability: Leverage Linux kernel-level telemetry (eBPF and Open Telemetry collectors) baked into base infrastructure to catch unauthorized API access, anomalous database queries, and lateral movement out-of-process
  • Crisis Management & Incident Response: Lead enterprise incident response, digital forensics, root cause analysis (RCA), and executive crisis communications.
  • Adversary Emulation & Offensive Security (Red/Purple Teaming):Direct internal and contingent red-team penetration testing across all HIPAA, PCI, and proprietary SaaS platforms, driving cross-team CTF exercises and threat modeling.

3. Continuous Trust & Automated Compliance (GRC Modernization)

  • Continuous Compliance Automation: Transition GRC from point-in-time manual evidence collection to API-driven, continuous control validation supporting
    SOX 404(b), HIPAA, PCI DSS, NIST CSF, EHNAC, and SEC disclosure requirements
    .
  • Centralized Risk Governance: Maintain an auditable, real-time enterprise Risk Register, eliminating fragmented…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary