×
Register Here to Apply for Jobs or Post Jobs. X

Lead Security Risk Manager

Remote / Online - Candidates ideally in
San Francisco, San Francisco County, California, 94199, USA
Listing for: DocuSign, Inc.
Part Time, Remote/Work from Home position
Listed on 2026-05-28
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security
Salary/Wage Range or Industry Benchmark: 100000 - 125000 USD Yearly USD 100000.00 125000.00 YEAR
Job Description & How to Apply Below

What you'll do

Docusign is looking for a Lead Security Risk Manager to join our Security Governance, Risk & Compliance (GRC) team. In this hands‑on role, you will lead modern, data‑driven security risk assessments and play a pivotal role in advancing the maturity of our Security Risk Management program. The ideal candidate combines technical expertise with business acumen, translating risk findings into actionable insights that influence engineering, security and business decisions.

Success in this role requires strong analytical skills, the ability to influence cross‑functional stakeholders, and the confidence to represent the Security Risk Management program with clarity, empathy and resolution‑driven mindset.

This position is an individual contributor role reporting to the Director, Security Product Risk Management.

Responsibility
  • Lead end‑to‑end security risk assessments of applications, systems, and cloud environments, across security domains leveraging advanced risk scoring models such as risk quantification
  • Identify, assess, monitor, and report on security risks across the enterprise
  • Analyze risk data to uncover recurring issues, trends, and root causes, and recommend changes to strengthen controls
  • Partner with Engineering, Security, and business functions to embed risk insights into planning, prioritization, and decision‑making
  • Develop and maintain risk dashboards and metrics that provide leadership with actionable insights into risk exposure and trends
  • Support and enhance the security control framework, ensuring risks are effectively mapped to controls, and are relevant to the business
  • Provide recommendations and guidance on risk acceptance and mitigation that balances business objectives with security requirements
  • Leverage modern GRC platforms and automation (e.g., Service Now, Process Unity) to scale risk management processes
  • Stay ahead of emerging risks and industry trends to continuously improve risk practices
  • Lead AI risk related discussions/assessments to report on emerging AI trends and risks
Job Designation

Hybrid: Employee divides their time between in‑office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in‑office expectation).

What you bring Basic
  • 12+ years of experience in security risk management or related areas
  • Bachelor’s degree in Computer Science, Information Systems, Information Security, or a related field
  • Experience with cyber threats and vulnerabilities, with hands‑on expertise in one or more security domains (e.g., vulnerability management, insider risk, incident response, identity and access management, application, infrastructure, cloud, product, platform, data and AI security)
  • Experience with risk management frameworks (RMF, ISO 27005, NIST 800‑37, NIST 800‑30)
  • Experience with risk quantification models (e.g., FAIR) or building custom risk scoring approaches
  • Experience with control frameworks (SSAE
    16, ISO
    27001, NIST CSF/800‑53, PCI DSS, SIG, CSA, HIPAA, FedRAMP)
  • Experience with GRC platforms and automation tools, preferably Service Now IRM
Preferred
  • Knowledge of cloud environments (AWS, Azure, GCP) and SaaS platforms
  • Demonstrated ability to work independently with a strong sense of ownership, urgency, and drive
  • Strong business acumen with the ability to communicate risk to technical and non‑technical stakeholders and recommend appropriate compensating controls
  • Experience working cross‑functionally to evaluate security controls and business processes, translating findings into meaningful risk insights
  • Familiarity with data visualization tools (e.g., Tableau, Power BI) for building risk dashboards
  • One or more certifications: CISSP, CRISC, CISM, CTPRP, CISA, CCSP, CIPT, CompTIA Security+, or AWS/Azure Security
  • Strong analytical, problem solving, and communication skills
Wage Transparency

Pay for this position is based on a number of factors including geographic location and may vary depending on job‑related knowledge, skills, and experience.

Based on applicable legislation, the below details pay ranges in the following locations.

California: $ - $ base salary

This role is also eligible for the following:

  • Bonus:
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary