Sr. Security Engineer

DocuSign DocuSign · Enterprise · Bangalore, India · Security

Senior Security Engineer role focused on vulnerability and configuration management within Docusign's cloud infrastructure. Responsibilities include operating discovery tools, analyzing findings, prioritizing remediation, and scripting automations to mitigate risks. The role involves partnering with infrastructure, platform, and security operations teams.

What you'd actually do

  1. Provide strategic and technical leadership for the infrastructure vulnerability management and external surface coverage program, partnering with stakeholders across the company
  2. Analyze public and private vulnerability disclosures and exploit code, deeply understanding and assessing the technical details and potential impact across Docusign’s infrastructure, services, and applications
  3. Engineer high-quality, scalable, and accurate vulnerability detection mechanisms, leveraging automation and advanced tooling
  4. Perform discovery scans with accurate scope, ensuring efficacy, freshness, and deduplication of data, and integrate results with existing reporting mechanisms
  5. Develop and maintain scripts and code (Python, Ruby, Go, Swift, Java, .Net, C++, SQL, etc.) for ETL, enrichment, evidence capture, and automation of external scanning processes

Skills

Required

  • Cybersecurity
  • Vulnerability Management
  • Cloud Security (Azure, AWS, GCP)
  • Scripting/Programming (Python, Go, TypeScript)
  • SQL
  • Infrastructure Deployment and Management
  • DNS, HTTP, TLS protocols
  • EASM tools
  • Asset Inventory and Vulnerability Management tools
  • Data aggregation and visualization

Nice to have

  • CISSP or CISM certifications
  • Technical mentor experience
  • Data pipelines and reporting tools
  • Problem-solving skills
  • Adaptability

What the JD emphasized

  • 10+ years of industry experience in cybersecurity, with a focus on coverage, vulnerability management, or related areas
  • Experience securing cloud platforms (Azure, AWS, GCP), especially public endpoints and security groups
  • Experience in scripting and programming (Python, Go, or TypeScript) and SQL
  • Background in infrastructure deployment and management (network, systems)
  • Experience with coverage or EASM tools (e.g., Microsoft Defender EASM, VirusTotal, Wiz EASM)
  • Experience with asset inventory and vulnerability management tools (e.g., ServiceNow, Qualys, Tenable)