Sr. Manager, Security Product Management - Governance & Controls
San Francisco, San Francisco County, California, 94199, USA
Listed on 2026-02-16
-
IT/Tech
Cybersecurity, Information Security
Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity.
Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).
We are hiring a Sr. Manager, Security Product Management - Governance & Controls to transform our security governance function into a scalable, productized capability. This role replaces document-centric compliance with security requirements and controls built directly into engineering and business workflows.
As the product owner for security control framework, this role owns the user experience of security - ensuring policies, standards and controls are designed for adoption, automated by default and measured through real-time data. This role is also accountable for periodic security maturity assessments, using control telemetry to continuously improve security posture.
You will partner closely with Product & Engineering, GRC Engineering, Security, Compliance, and business teams to ensure security requirements are designed into systems and delivery pipelines early, enabling teams to move fast while building securely by default.
This position is a people manager role reporting to the Senior Director of Security Governance, Risk Management, and Compliance (GRC).
Responsibility
- Build and lead a high-performing team that replaces document-centric security governance with scalable, productized control capabilities
- Define and drive a multi-year product vision and roadmap for security governance focused on adoption and measurable risk reduction
- Define and clearly communicate product goals and requirements, working cross-functionally with Security, GRC Product Management, and Engineering to deliver solutions
- Establish the architecture blueprint that transforms security governance into a scalable product platform
- Own the end-to-end lifecycle of security policies, standards, and controls as versioned, releasable product assets
- Translate security, compliance, and risk requirements into developer-friendly product features embedded in engineering workflows (CI/CD, infrastructure provisioning, service onboarding)
- Run continuous Voice of the Customer research to identify friction and drive feature improvements
- Analyze cost, risk, and engineering tradeoffs, facilitating discussions to reach alignment and clear decisions
- Define critical success metrics, implement tracking mechanisms, and measure feature impact post-launch using telemetry and data insights
- Drive iterative delivery and continuous improvement through data-informed prioritization
- Lead internal product marketing and advocacy of security governance capabilities
- Partner with GRC Engineering and Security Program Management to ensure features ship on time and align with security priorities
- Own risk-based prioritization and deprecation decisions, including when to simplify, delay, or retire security controls
- Provide executive-level visibility into governance maturity using real-time data, not point-in-time assessments
Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in‑office expectation)
Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law.
What you bringBasic
- 8+ years in technical product management, platform security, or security engineering, with a track record of shipping internal…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).