EverCommerce - Security Engineer
EverCommerce5 days ago
Remote, United StatesSenior
Base Salary
$130k - $150k/yr
Responsibilities
- Create and maintain security architecture, engineering processes, procedures, requirements, documentation, and implementation guidance.
- Design, implement, maintain, and operate information system security controls and countermeasures.
- Secure integrations with external security vendors and cloud providers.
- Lead architecture and design reviews and ensure security requirements are implemented in new technology deployments.
- Evaluate and manage the lifecycle of security technologies.
- Identify security risks and control gaps and recommend corrective architecture, integrations, controls, and operational improvements.
- Integrate secure-by-design principles into technology deployments, CI/CD pipelines, and Agile development processes.
- Maintain the security architecture roadmap and strategic plan.
- Build and mature security architecture metrics and reporting.
- Serve as a security subject matter expert, contribute to the security program, and mentor junior security engineers and analysts.
Requirements
- At least 5 years of relevant technical work experience in cybersecurity, software development, systems administration, or a related field.
- Bachelor's degree in cybersecurity, information technology, computer science, information systems, or a related technical discipline, or equivalent professional experience.
- At least one current industry-recognized security certification such as CISSP, CISM, CISA, or GIAC, or commensurate experience.
- Experience with systems compliant with NIST 800-53, NIST CSF, or ISO 27001-2022 security control frameworks.
- Strong knowledge of securing cloud technologies such as AWS and Azure.
- Knowledge of information security risk assessment methodologies and standards.
- Advanced knowledge of common attacks, attack methods, and defense architectures.
- Experience securing multi-tenant compute services, microservices, and modern APIs.
- Working knowledge of common web and container-based vulnerabilities.
- Experience developing and implementing information security policies and procedures.
- Experience producing technical documentation including reports, proposals, statements of work, and whitepapers.
- Excellent communication, interpersonal, collaboration, problem-solving, and English verbal and written communication skills.
Benefits
- Remote work is available anywhere in the United States, with optional office work near company locations; Denver, Colorado is preferred.
- The role may require travel to the Denver corporate headquarters or other North American offices.
- Continued investment in professional development.
- Day-one access to health and wellness benefits, including an annual wellness stipend.
- 401(k) with up to a 4% match and immediate vesting.
- Flexible and generous FTO time off.
- Employee Stock Purchase Program.