Senior IT Security Engineer

Simpro Software — United States · Posted ~20 hours ago

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Description

Job Context Simpro Group is a pioneer of AI-powered field service software serving over 250,000 users worldwide. Headquartered in Miami, we've been transforming how trades and field service businesses operate since 2013, connecting jobs, people, and performance across plumbing, HVAC, fire & security, facilities management, electrical contracting, and more. As we grow, we need a Senior IT Security Engineer to sustain and strengthen our certification posture, covering frameworks such as SOC 2 and ISO 27001, while owning the day-to-day security of our internal IT environment. What You’ll Do This is a senior individual contributor role based onsite in downtown Miami, reporting to the IT Director. You'll own IT security and compliance end to end, with real autonomy in day-to-day execution while strategy is shaped jointly with IT leadership. On the product engineering side, this role is a technical sounding board, advisory rather than an owner of engineering's process. Protecting customer data, meeting our compliance obligations, and safeguarding core systems are never up for negotiation. Beyond that, this role calls for sound judgment on where security effort delivers the most protection without slowing the business down. What You'll Own Security & Compliance: Sustain and strengthen our certification posture across frameworks such as SOC 2 and ISO 27001, lead new certification initiatives as needed, select and implement a Governance, Risk, and Compliance (GRC) platform, and manage prospect and customer security questionnaires Risk Management: Build and maintain the risk register across physical, logical, and systems- level exposure, and prioritize remediation Identity & Access Management (IAM): Audit and remediate shared credential and generic account exposure, improve identity architecture including SSO consolidation and network authentication Security Operations & Endpoint Protection: Select and stand up our EDR/MDR capability, maintain group policy and endpoint standards, secure remote connectivity, own data protection practices, and address physical security risks tied to IT-managed systems like door access technology Engineering Security Advisory: Serve as a sounding board to product engineering on secure configuration, secrets handling, and vulnerability management, in an advisory capacity Vendor & Third-Party Risk: Assess new and existing SaaS vendors, review security posture and trust documentation on a recurring basis Incident Response: Build playbooks, run tabletop exercises, and lead response when incidents occur What You’ll Bring Hands-on technical depth in identity and access architecture, not just policy writing Experience selecting and standing up EDR/MDR, and maintaining endpoint and group policy standards Experience across both logical security (IAM, network segmentation, cloud config) and physical security practices Comfortable advising engineering teams you don't manage, credible enough that they value your input even without formal authority Strong communicator who can explain risk and tradeoffs to non-security stakeholders Solid working understanding of how SOC 2 and ISO 27001 programs run, close enough to the process to have done real work in it, not just relaying auditor requests. Owning a certification cycle start to finish is a plus, not a requirement, since you'll work alongside outside compliance consultants who guide the harder parts of the process Experience & Education 6+ years in information security or a closely related IT discipline Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or an equivalent combination of professional experience and industry certifications Nice to Have CISSP, CISA, or ISO 27001 Lead Implementer/Auditor certification Experience with GRC tooling such as Vanta, Drata, or Secureframe Background in vendor risk management or third-party due diligence Our Technology Landscape What matters here is how you reason about risk, not which specific tool you've used before. You'll work across identity and access systems, cloud infrastructure, collaboration and AI tooling, and vulnerability management platforms, spanning both our internal IT environment and our product engineering pipeline. Our Core Values We Are One Team We Are Customer Centric We Are Growth Minded We Are Accountable We Celebrate Success Simpro, AroFlo, BigChange & ClockShark are equal opportunity employers with a best-of-class onboarding program and supportive team environments. This means that we want everyone to feel welcome with us and to provide equal opportunities for everyone, regardless of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex or sexual orientation, or any other non-performance factor. If you'd like to join a fun and progressive organization, where there are opportunities to develop your career, please apply now with your CV/resume. Please note, no agencies will be accepted in the recruitment of this role.