Senior IT Security Engineer
SIMPRO Miami, Florida, United States
Software Development · 501-1,000 employees
Applying here? Try the free cover letter tool — paste this posting and your résumé, no account needed.
About the role
The Senior IT Security Engineer will own the end-to-end security and compliance posture, including managing SOC 2 and ISO 27001 certifications. They will also lead risk management, identity and access architecture, and incident response efforts while serving as a technical advisor to product engineering.
What they look for
Requirements
Candidates must have 6 or more years of experience in information security or a related IT discipline. A bachelor's degree in a relevant field is required, along with hands-on technical depth in identity architecture and security operations.
Full description
Job Context
Simpro Group is a pioneer of AI-powered field service software serving over 250,000 users worldwide. Headquartered in Miami, we've been transforming how trades and field service businesses operate since 2013, connecting jobs, people, and performance across plumbing, HVAC, fire & security, facilities management, electrical contracting, and more. As we grow, we need a Senior IT Security Engineer to sustain and strengthen our certification posture, covering frameworks such as SOC 2 and ISO 27001, while owning the day-to-day security of our internal IT environment.
What You’ll Do
This is a senior individual contributor role based onsite in downtown Miami, reporting to the IT Director. You'll own IT security and compliance end to end, with real autonomy in day-to-day execution while strategy is shaped jointly with IT leadership. On the product engineering side, this role is a technical sounding board, advisory rather than an owner of engineering's process.
Protecting customer data, meeting our compliance obligations, and safeguarding core systems are never up for negotiation. Beyond that, this role calls for sound judgment on where security effort delivers the most protection without slowing the business down.
What You'll Own
Security & Compliance: Sustain and strengthen our certification posture across frameworks such as SOC 2 and ISO 27001, lead new certification initiatives as needed, select and implement a Governance, Risk, and Compliance (GRC) platform, and manage prospect and customer security questionnaires
Risk Management: Build and maintain the risk register across physical, logical, and systems- level exposure, and prioritize remediation
Identity & Access Management (IAM): Audit and remediate shared credential and generic account exposure, improve identity architecture including SSO consolidation and network authentication
Security Operations & Endpoint Protection: Select and stand up our EDR/MDR capability, maintain group policy and endpoint standards, secure remote connectivity, own data protection practices, and address physical security risks tied to IT-managed systems like door access technology
Engineering Security Advisory: Serve as a sounding board to product engineering on secure configuration, secrets handling, and vulnerability management, in an advisory capacity
Vendor & Third-Party Risk: Assess new and existing SaaS vendors, review security posture and trust documentation on a recurring basis
Incident Response: Build playbooks, run tabletop exercises, and lead response when incidents occur
What You’ll Bring
- Hands-on technical depth in identity and access architecture, not just policy writing
- Experience selecting and standing up EDR/MDR, and maintaining endpoint and group policy standards
- Experience across both logical security (IAM, network segmentation, cloud config) and physical security practices
- Comfortable advising engineering teams you don't manage, credible enough that they value your input even without formal authority
- Strong communicator who can explain risk and tradeoffs to non-security stakeholders
- Solid working understanding of how SOC 2 and ISO 27001 programs run, close enough to the process to have done real work in it, not just relaying auditor requests.
- Owning a certification cycle start to finish is a plus, not a requirement, since you'll work alongside outside compliance consultants who guide the harder parts of the process
Experience & Education
- 6+ years in information security or a closely related IT discipline
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or an equivalent combination of professional experience and industry certifications
Nice to Have
- CISSP, CISA, or ISO 27001 Lead Implementer/Auditor certification
- Experience with GRC tooling such as Vanta, Drata, or Secureframe
- Background in vendor risk management or third-party due diligence
Our Technology Landscape What matters here is how you reason about risk, not which specific tool you've used before. You'll work across identity and access systems, cloud infrastructure, collaboration and AI tooling, and vulnerability management platforms, spanning both our internal IT environment and our product engineering pipeline.
Our Core Values
We Are One Team
We Are Customer Centric We Are Growth Minded We Are Accountable We Celebrate Success
Simpro, AroFlo, BigChange & ClockShark are equal opportunity employers with a best-of-class onboarding program and supportive team environments. This means that we want everyone to feel welcome with us and to provide equal opportunities for everyone, regardless of age, disability, gender reassignment, marriage and civil partnership, pregnancy and maternity, race, religion or belief, sex or sexual orientation, or any other non-performance factor.
If you'd like to join a fun and progressive organization, where there are opportunities to develop your career, please apply now with your CV/resume.
*Please note, no agencies will be accepted in the recruitment of this role.
Similar roles
-
Information Systems Security Engineer
MANTECH Crane, Indiana, United States
-
Business Developer:in Defence (Naval & Cybersecurity) (m/w/d) | Deutschland
CONCAPE Germany
-
Telematics Cybersecurity
Daimler Truck Sriperumbudur, Tamil Nadu, India
-
Network & Security Engineer (Fortinet) (REF5857V)
Deutsche Telekom IT Solutions Budapest, Central Hungary, Hungary
-
Cybersecurity Threat Researcher (Position located in Cheltenham, United Kingdom)
KnowBe4 Cheltenham, England, United Kingdom
-
Expert Application Security Specialist (IAM)
OPTIVEUM sp. z o.o. Łódź, Łódź Voivodeship, Poland · PLN 293K/yr