Sr. Iam Security Engineer

DocuSign DocuSign · Enterprise · Bangalore, India · Security

The Senior Identity and Access Management Security Engineer will drive the implementation of the enterprise-wide identity and access management strategy at Docusign. This role involves setting company policy and security standards, collaborating with cross-functional teams to ensure best practices, and operationalizing governance and guardrails for IAM. The engineer will also drive automation efforts, embed IAM best practices into products, and ensure practices meet internal security standards, industry frameworks, and regulatory requirements. Experience with AI/ML and relevant frameworks like NIST AI RMF and ISO 42001 is mentioned.

What you'd actually do

  1. Execute the organization’s identity and access management strategy and standards, aligning with overall business objectives, digital transformation initiatives, and product and enterprise security requirements
  2. Contribute to a high-performing, product-driven team focused on measurable outcomes and continuous improvement
  3. Help to define, deliver, and continuously evolve identity and access management best practices
  4. Collaborate with cross-functional identity and access management teams to implement secure best practices, ensuring proper management of user accounts and permissions, appropriately tailored access policies and processes, effective management platform and solution evaluations, and validation of efficacy of the program and controls
  5. Operationalize governance and guardrails for identity and access management, ensuring safe and compliant use across the organization

Skills

Required

  • 8+ years in identity and access management or related security disciplines
  • Strong understanding of enterprise security, including risk mitigation and governance of identity and access management issues
  • Working knowledge of threats presented through the exploitation of identity and access management risks
  • Substantive experience in data governance and security, including implementation of data governance and security frameworks
  • Experience defining security KPIs, metrics pipelines, and executive reporting frameworks
  • Excellent stakeholder management and communication skills across technical and business audiences
  • Strong cross-functional collaboration and stakeholder management skills, especially with Product, Engineering, IT, Data, Privacy, and executive teams

Nice to have

  • CISM, CRISC, CISSP, CCSP, CAIP, or equivalent
  • Familiarity with attack surface monitoring, supply chain security, and continuous control validation
  • Experience driving automation strategies, predictive analytics, and data-driven insights
  • Knowledge of frameworks such as NIST CSF, NIST AI RMF, ISO 27001, ISO 42001, FAIR, SOC 2, and FedRAMP

What the JD emphasized

  • identity and access management strategy
  • identity and access management best practices
  • identity and access management teams
  • identity and access management issues
  • identity and access management risks
  • identity and access management
  • identity and access management, attack surface management, and data loss prevention
  • identity and access management