Senior Security Risk Manager

DocuSign DocuSign · Enterprise · Dublin, Ireland · Security

This role focuses on security risk management within an enterprise environment, involving risk assessments, data analysis, and collaboration with engineering and business functions. It leverages risk frameworks and GRC platforms to identify, assess, and report on security risks, aiming to mature the Security Risk Management program. While it touches on AI security, the core function is risk management, not AI/ML development.

What you'd actually do

  1. Lead end-to-end security risk assessments of applications, systems, and cloud environments, across all security domains leveraging advanced risk scoring models such as risk quantification
  2. Identify, assess, monitor, and report on security risks across the enterprise
  3. Analyze risk data to uncover recurring issues, trends, and root causes, and recommend changes to strengthen controls
  4. Partner with Engineering, Security, and business functions to embed risk insights into planning, prioritization, and decision-making
  5. Develop and maintain risk dashboards and metrics that provide leadership with actionable insights into risk exposure and trends

Skills

Required

  • Security risk management
  • Risk assessment
  • Risk quantification
  • Risk data analysis
  • Security control frameworks
  • GRC platforms
  • Cyber threats and vulnerabilities
  • Risk management frameworks (RMF, ISO 27005, NIST 800-37, NIST 800-30)
  • Risk quantification models (e.g., FAIR)
  • Control frameworks (SSAE16, ISO27001, NIST CSF/800-53, PCI DSS, SIG, CSA, HIPAA, FedRAMP)
  • ServiceNow IRM
  • Cloud environments (AWS, Azure, GCP)
  • SaaS platforms
  • Data visualization tools (e.g., Tableau, Power BI)
  • CISSP
  • CRISC
  • CISM
  • CTPRP
  • CISA
  • CCSP
  • CIPT
  • CompTIA Security+
  • AWS/Azure Security

Nice to have

  • building custom risk scoring approaches
  • Knowledge of cloud environments (AWS, Azure, GCP) and SaaS platforms
  • Demonstrated ability to work independently with a strong sense of ownership, urgency, and drive
  • Strong business acumen with the ability to communicate risk to technical and non-technical stakeholders and recommend appropriate compensating controls
  • Experience working cross-functionally to evaluate security controls and business processes, translating findings into meaningful risk insights
  • Familiarity with data visualization tools (e.g., Tableau, Power BI) for building risk dashboards

What the JD emphasized

  • hands-on role
  • technical expertise
  • business acumen
  • strong analytical skills
  • confidence to represent the Security Risk Management program
  • hands-on expertise in one or more security domains
  • Experience with risk management frameworks
  • Experience with risk quantification models
  • Experience with control frameworks
  • Experience with GRC platforms and automation tools