Senior Security Risk Manager
San Francisco, San Francisco County, California, 94199, USA
Listed on 2026-07-18
-
IT/Tech
Cybersecurity, Information Security, Data Security, Security Management & Operations
About the Role
Docusign is seeking a Senior Security Risk Manager to lead and manage modern, data‑driven security risk assessments within the Security Governance, Risk & Compliance (GRC) team. The role is an individual contributor reporting to the Sr. Director, Security Governance, Risk and Compliance.
Responsibilities- Lead end‑to‑end security risk assessments of applications, systems, and cloud and software environments across all security domains.
- Identify, assess, monitor, and report on security risks across the enterprise and within specific domains such as Vulnerability Management, Third Party Risk, Product Security, Detection and Response, etc.
- Review risk, control, and issue data to recommend top security investments.
- Analyze risk data to identify trends, root causes, and control gaps, and recommend enhancements.
- Partner with engineering, security, and business teams to embed risk insights into planning, prioritization, and decision‑making.
- Develop and maintain risk dashboards and metrics that provide leadership with actionable insights into risk exposure and trends.
- Maintain and evolve the security control framework, ensuring risks are effectively mapped to controls.
- Provide recommendations on risk acceptance and mitigation that balance business objectives with security requirements.
- Leverage modern GRC platforms and automation (e.g., Service Now IRM, One Trust) to scale risk management processes.
- Serve as a trusted advisor to leadership on security risk posture and decisions.
- Stay ahead of emerging risks and industry trends to continuously improve risk practices.
- 8+ years of security risk management, GRC, or related experience.
- Bachelor’s degree in Computer Science, Information Security, or related field.
- Hands‑on expertise in one or more security domains (e.g., vulnerability management, insider risk, incident response, identity and access management, application infrastructure, cloud, product, platform, data and AI security).
- Experience with cloud environments (AWS, Azure, GCP) and SaaS platforms.
- Experience with risk management frameworks and risk quantification models (e.g., FAIR) or building custom risk scoring approaches.
- Experience with security risk assessments, controls, and threat analysis.
- Experience with GRC platforms and automation tools, preferably Service Now IRM.
- Certifications such as CISSP, CRISC, or CISM.
- Experience as a security risk SME or architect.
- Experience managing or mentoring junior GRC professionals.
- Experience building risk dashboards and metrics (e.g., Tableau, Power BI).
- Excellent communication and stakeholder management skills.
Base salary ranges vary by location:
- California: $ – $
The role is also eligible for a company bonus plan and Restricted Stock Units (RSUs).
Benefits- Paid Time Off and company holidays.
- Paid Parental Leave up to six months.
- Full Health Benefits Plans with options for 100% employer‑paid plans.
- Retirement Plans with potential employer contributions.
- Learning and Development opportunities.
- Compassionate Care Leave.
Hybrid – employee divides time between in‑office and remote work; office presence is required at least two days per week.
Equal Opportunity EmployerDocusign is an Equal Opportunity Employer and complies with all applicable laws. We prohibit discrimination based on protected characteristics and seek a diverse workforce.
AccommodationWe are committed to providing reasonable accommodations for qualified individuals with disabilities during the application process. Contact us at for assistance.
Applicant and Candidate Privacy NoticeThis position is not eligible for employment in the following states:
Alaska, Hawaii, Maine, Mississippi, North Dakota, South Dakota, Vermont, West Virginia, and Wyoming.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).