Lead Security Risk Manager

DocuSign DocuSign · Enterprise · San Francisco, CA · Security

Lead Security Risk Manager to join Security Governance, Risk & Compliance (GRC) team. Role involves leading data-driven security risk assessments, advancing the Security Risk Management program, and translating risk findings into actionable insights for engineering, security, and business decisions. Responsibilities include leading security risk assessments of applications, systems, and cloud environments, analyzing risk data, partnering with cross-functional teams, developing risk dashboards, and staying ahead of emerging risks and industry trends, including AI risks.

What you'd actually do

  1. Lead end-to-end security risk assessments of applications, systems, and cloud environments, across security domains leveraging advanced risk scoring models such as risk quantification
  2. Identify, assess, monitor, and report on security risks across the enterprise
  3. Analyze risk data to uncover recurring issues, trends, and root causes, and recommend changes to strengthen controls
  4. Partner with Engineering, Security, and business functions to embed risk insights into planning, prioritization, and decision-making
  5. Develop and maintain risk dashboards and metrics that provide leadership with actionable insights into risk exposure and trends

Skills

Required

  • security risk management
  • cyber threats and vulnerabilities
  • risk management frameworks (RMF, ISO 27005, NIST 800-37, NIST 800-30)
  • risk quantification models (e.g., FAIR) or building custom risk scoring approaches
  • control frameworks (SSAE16, ISO27001, NIST CSF/800-53, PCI DSS, SIG, CSA, HIPAA, FedRAMP)
  • GRC platforms and automation tools, preferably ServiceNow IRM
  • data visualization tools (e.g., Tableau, Power BI)
  • CISSP, CRISC, CISM, CTPRP, CISA, CCSP, CIPT, CompTIA Security+, or AWS/Azure Security

Nice to have

  • cloud environments (AWS, Azure, GCP)
  • SaaS platforms
  • ServiceNow IRM

What the JD emphasized

  • advanced risk scoring models
  • risk quantification
  • risk management frameworks
  • risk quantification models
  • risk management frameworks
  • risk acceptance and mitigation
  • emerging risks
  • AI risk related discussions/assessments
  • emerging AI trends and risks
  • security risk management
  • risk management frameworks
  • risk quantification models
  • risk management frameworks
  • risk acceptance and mitigation
  • emerging risks
  • AI risk related discussions/assessments
  • emerging AI trends and risks