About the Role
Docusign is seeking a Senior Security Risk Manager to join the Security Governance, Risk & Compliance (GRC) team. This individual contributor role will lead and manage data-driven security risk assessments and enhance the Security Risk Management program.
Responsibilities
- Lead end-to-end security risk assessments of applications, systems, and cloud/software environments using advanced risk scoring models.
- Identify, assess, monitor, and report on enterprise-wide security risks across various domains.
- Review Risk, Control, and Issue data to provide recommendations on top security investments.
- Analyze risk data to identify trends, root causes, control gaps, and recommend improvements.
- Partner with Engineering, Security, and business teams to integrate risk insights into decision-making.
- Develop and maintain risk dashboards and metrics for leadership.
- Maintain and evolve the security control framework, mapping risks to controls.
- Provide recommendations on risk acceptance and mitigation.
- Leverage GRC platforms and automation tools to scale risk management processes.
- Serve as a trusted advisor to leadership on security risk posture.
- Stay informed about emerging risks and industry trends.
Requirements
- 8+ years of experience in security risk management, GRC, or related fields.
- Bachelor's degree in Computer Science, Information Security, or related field.
- Experience with cyber threats and vulnerabilities, with hands-on expertise in at least one security domain.
- Experience with cloud environments (AWS, Azure, GCP) and SaaS platforms.
- Experience with risk management frameworks, risk quantification models (e.g., FAIR), or custom risk scoring approaches.
- Experience with security risk assessments, controls, and threat analysis.
- Experience with GRC platforms and automation tools, preferably ServiceNow IRM.
- One or more certifications: CISSP, CRISC, CISM.
- Experience as a security risk SME or security architect (Preferred).
- Familiarity with cloud and SaaS environments (AWS, Azure, GCP) (Preferred).
- Experience managing or mentoring junior GRC professionals (Preferred).
- Experience building risk dashboards and metrics (e.g., Tableau, Power BI) (Preferred).
- Excellent communication and stakeholder management skills.
Skills
- Security Risk Management
- GRC
- Risk Quantification
- Vulnerability Management
- Third Party Risk
- Product Security
- Detection and Response
- Risk Analysis
- Control Frameworks
- GRC Platforms
- ServiceNow IRM
- Cloud Security (AWS, Azure, GCP)
- SaaS Security
- Risk Dashboards
- Metrics Development
- Tableau
- Power BI
- Communication
- Stakeholder Management
Location
- Hybrid
Work Type
- Hybrid
Experience Level
- Senior
Education Level
- Bachelor's degree in Computer Science, Information Security, or related field
Salary/Compensations
- California: $146,400.00 - $235,375.00 base salary
- Bonus: Company bonus plan
- Stock: Eligible to receive Restricted Stock Units (RSUs)
Benefits
- Paid Time Off
- Paid company holidays
- Paid Parental Leave
- Full Health Benefits Plans
- Retirement Plans
- Learning and Development options
- Coaching
- Online courses
- Education reimbursements
- Compassionate Care Leave
About the Company
- Docusign brings agreements to life with over 1.5 million customers and more than a billion people in over 180 countries.
- The company's Intelligent Agreement Management platform accelerates business processes and simplifies lives by unlocking critical data trapped in documents.
- Docusign is the #1 company in e-signature and contract lifecycle management (CLM).
Equal Opportunity
- Docusign is committed to building a talented, diverse team where all employees feel a deep sense of belonging and thrive.
- We encourage candidates with a range of perspectives to apply.
- Docusign is an Equal Opportunity Employer and makes hiring decisions based on experience, skill, aptitude, and a can-do approach.
- We do not discriminate based on race, ethnicity, color, age, sex, religion, national origin, ancestry, pregnancy, sexual orientation, gender identity, gender expression, genetic information, physical or mental disability, registered domestic partner status, caregiver status, marital status, veteran or military status, or any other legally protected category.
