Left arrow iconBack to search

Senior IT Security Engineer

SIMPRO
Posted 9 days ago, valid for 22 days
Location

Miami, FL, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Job Context

Simpro Group is a pioneer of AI-powered field service software serving over 250,000 users worldwide. Headquartered in Miami, we've been transforming how trades and field service businesses operate since 2013, connecting jobs, people, and performance across plumbing, HVAC, fire & security, facilities management, electrical contracting, and more.
As we grow, we need a Senior IT Security Engineer to sustain and strengthen our certification posture, covering frameworks such as SOC 2 and ISO 27001, while owning the day-to-day security of our internal IT environment.

What You’ll Do

This is a senior individual contributor role based onsite in downtown Miami, reporting to the IT Director. You'll own IT security and compliance end to end, with real autonomy in day-to-day execution while strategy is shaped jointly with IT leadership. On the product engineering side, this role is a technical sounding board, advisory rather than an owner of engineering's process. 

Protecting customer data, meeting our compliance obligations, and safeguarding core systems are never up for negotiation. Beyond that, this role calls for sound judgment on where security effort delivers the most protection without slowing the business down. 


What You'll Own 

Security & Compliance: Sustain and strengthen our certification posture across frameworks such as SOC 2 and ISO 27001, lead new certification initiatives as needed, select and implement a Governance, Risk, and Compliance (GRC) platform, and manage prospect and customer security questionnaires 

Risk Management: Build and maintain the risk register across physical, logical, and systems- level exposure, and prioritize remediation 

Identity & Access Management (IAM): Audit and remediate shared credential and generic account exposure, improve identity architecture including SSO consolidation and network  authentication 

Security Operations & Endpoint Protection: Select and stand up our EDR/MDR capability, maintain group policy and endpoint standards, secure remote connectivity, own data protection practices, and address physical security risks tied to IT-managed systems like door access technology 

Engineering Security Advisory: Serve as a sounding board to product engineering on secure configuration, secrets handling, and vulnerability management, in an advisory capacity 

Vendor & Third-Party Risk: Assess new and existing SaaS vendors, review security posture and trust documentation on a recurring basis 

Incident Response: Build playbooks, run tabletop exercises, and lead response when incidents occur 

What You’ll Bring

  • Hands-on technical depth in identity and access architecture, not just policy writing 
  • Experience selecting and standing up EDR/MDR, and maintaining endpoint and group policy standards 
  • Experience across both logical security (IAM, network segmentation, cloud config) and physical security practices 
  • Comfortable advising engineering teams you don't manage, credible enough that they value your input even without formal authority 
  • Strong communicator who can explain risk and tradeoffs to non-security stakeholders 
  • Solid working understanding of how SOC 2 and ISO 27001 programs run, close enough to the process to have done real work in it, not just relaying auditor requests.
  • Owning a certification cycle start to finish is a plus, not a requirement, since you'll work alongside outside compliance consultants who guide the harder parts of the process

Experience & Education 

  • 6+ years in information security or a closely related IT discipline 
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or an equivalent combination of professional experience and industry certifications 

Nice to Have 

  • CISSP, CISA, or ISO 27001 Lead Implementer/Auditor certification 
  • Experience with GRC tooling such as Vanta, Drata, or Secureframe 
  • Background in vendor risk management or third-party due diligence 

Our Technology Landscape What matters here is how you reason about risk, not which specific tool you've used before. You'll work across identity and access systems, cloud infrastructure, collaboration and AI tooling, and vulnerability management platforms, spanning both our internal IT environment and our product engineering pipeline. 

Our Core Values


We Are One Team

We Are Customer Centric
We Are Growth Minded
We Are Accountable
We Celebrate Success

Simpro, AroFlo, BigChange & ClockShark are equal opportunity employers with a best-of-class onboarding program and supportive team environments. This means that we want everyone to feel welcome with us and to provide equal opportunities for everyone, regardless of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex or sexual orientation, or any other non-performance factor.

If you'd like to join a fun and progressive organization, where there are opportunities to develop your career, please apply now with your CV/resume.

*Please note, no agencies will be accepted in the recruitment of this role.




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.