Sr. Director, Security Governance, Risk and Compliance
$244k - $390.58kDocuSign Inc
Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign's Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).
What you'll doAs the most trusted brand in our industry, Docusign recognizes the profound importance of maintaining and enhancing customer trust in our products. Docusign's security program is vital to that trust, and this role is a critical leadership position driving our success. The Senior Director, Security Governance, Risk, and Compliance (GRC) will be a technically proficient, business savvy leader who manages all aspects of the GRC program and multiple facets of product and enterprise security. Security GRC will embed within Product, Technology, Digital Technology, and Sales teams to proactively identify and reduce security risks - transforming legacy GRC practices into a more contemporary, productized capability and replacing document-centric compliance with scalable security controls built directly into engineering and business workflows. The Senior Director, GRC will tailor and implement Docusign's security controls framework to protect the platform, company, and customers through a risk-based approach to security. They will enhance engineering and development capabilities within the GRC team; implement contemporary, cost-effective tools and practices to automate historically manual activities; and leverage AI and ML where appropriate to optimize efficiencies while delivering at scale and with speed while managing emerging risk and supporting product and business innovation. This position will leverage leading security frameworks like NIST, ISO, and BSIMM as foundations for the overall security program while driving continuous improvement. The role will ensure that security governance mechanisms and documentation are implemented and effective. The Senior Director will also be responsible for driving revenue growth through direct support to Sales teams, managing customer security assurance, ensuring audit readiness in preparation for certification and global regulatory and customer requirements. Ultimately, the Senior Director will be responsible for managing GRC product innovation, development, engineering, and delivery. The role will deepen security within the platform and across the enterprise, while enhancing customer trust. They will be charged with optimizing the GRC user experience - serving as the product owner for the security controls framework and security risk mitigation; ensuring policies, standards, procedures, and controls are designed for adoption, automated by default, and measured through real-time data; and driving revenue growth through GRC support to the business.
This position is a people manager role reporting to the Group Vice President, Chief Information Security Officer.
Responsibility
Lead and manage the global GRC team and program, including core components: GRC engineering, governance, risk, compliance, and customer security assurance
Manage a high-performing, product-driven team focused on measurable outcomes and continuous improvement. Implement tailored program goals, objectives, milestones, key results, and key performance indicators to drive consistent progress and outcomes
Define and drive a multi-year product vision and roadmap for security governance, risk, and compliance (including GRC engineering and development) focused on adoption and measurable risk reduction
Establish the architectural blueprint that transforms GRC into a scalable product platform and service
Set vision, strategy, and leadership for how governance, risk, and compliance are engineered and automated across the company, translating requirements into a technology-driven automation strategy
Manage architecting of scalable platforms for GRC automation and evidence production, while growing the team's technical skills sets and ensuring engineering and development best practices
Manage delivery and prioritization while ensuring timely delivery of GRC product, engineering, and risk reduction capabilities
Maintain expertise in components and capabilities of the product ecosystem as well as company infrastructure, environments, data, and security controls
Maintain expertise in security threats, trends, technologies, and industry best practices (existing and emerging)
Serve as a trusted leader/advisor to the CISO, other executives, and teams - translating technical risk into business impact, providing clear updates, trade-offs, and advice
Manage collaboration and effective relationships with cross-functional teams to ensure frictionless security and paved path approaches with leadership across the business
Manage the GRC budget and resourcing
Ensure security practices and controls meet internal security policy and standards, industry frameworks, and regulatory and customer requirements
Implement contemporary tooling and automation to optimize insights, efficiency, and efficacy while enhancing technical security rigor
Contribute to technical requirements, architectural design and modification documents, and educational resources
Serve as a senior escalation point for complex or high risk security issues; drive architectural, process, and implementation improvements from lessons learned
Implement the GRC strategy for using AI across GRC teams and responsibilities; maintain a high level of individual proficiency in using AI to perform daily and longer term tasks
Manage and continuously improve the company-wide Docusign security controls framework, ensuring controls are appropriately tailored and effective across all domains
Manage compliance requirements relevant to modern software development, enterprise security, and trust and safety protections against platform abuse
Serve as Security's primary liaison between technical teams and regulatory/audit bodies
Work closely with third-parties on assessments, audits, attestations, and in shaping security programs, roadmaps, and deliverables
Job Designation
Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation)
Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law.
What you bringBasic
15+ years' working experience in Security GRC, Product Security, Application Security, Engineering, Trust and Safety or closely related security and engineering disciplines, with 8+ years in technical leadership roles
Bachelor's degree in computer science, data science, artificial intelligence, machine learning, cybersecurity, risk management, or a related technical field
Experience designing and leading security programs, including but not limited to security risk management, governance (especially under NIST, ISO, and FedRAMP frameworks), compliance, engineering/secure development, customer security assurance, product security, enterprise security, and trust and safety
Experience with NIST CSF, NIST SDF, NIST AI RMF, ISO 27001, SOC, BSIMM, IL5, FedRAMP High, and other, more narrowly tailored or geographically focused security frameworks
Experience driving automation strategies, predictive analytics, and data-driven insights
Experience in implementing or improving security tools where they previously did not exist, did not perform to expectations, and/or better options emerged (e.g., workflow tools, case management systems, agents developed and trained to meet mission)
Experience designing and embedding security controls across the business, plus validating efficacy
Experience defining security KPIs, metrics pipelines, and executive reporting frameworks
Experience with cross-functional collaboration and stakeholder engagement across technical and business relationships, especially with Product, Technology, Digital Technology, Sales, Security, and executive teams
Preferred
Master's degree or higher
Deeply technical with strong strategic vision, tactical acumen, excellence in execution
Forward looking and acting with the ability to understand and address current and future threats and business requirements exceedingly well and manage products and their team to suit
Growth and product mindset; oriented to action and delivery; professional teammate
Excellent leadership, communications, and presentation skills
Certifications: CISSP, CCISO, CISM, CRISC, CGRC, CCSP, CSSLP, GSLC, GSEC, or equivalent
Substantial experience in implementing best practices and compliance obligations for AI product security and AI enterprise security
Demonstrated experience with modern security frameworks applied to cloud-native environments and SaaS products
Experience embedding GRC requirements into CI/CD pipelines (shift-left security)
Extensive technical knowledge, including network infrastructure, automated workflows, secure coding practices, cryptography basics, threat modeling, and data systems architecture
Strong experience with project management that includes a track record of success
Wage Transparency
Pay for this position is based on a number of factors including geographic location and may vary depending on job-related knowledge, skills, and experience.
Based on applicable legislation, the below details pay ranges in the following locations:
California: $244,000.00 - $390,575.00 base salary
Washington, Maryland, New Jersey and New York (including NYC metro area): $228,400.00 - $344,575.00 base salary
This role is also eligible for the following:
- Bonus: Sales personnel are eligible for variable incentive pay dependent on their achievement of pre-established sales goals. Non-Sales roles are eligible for a company bonus plan, which is calculated as a percentage of eligible wages and dependent on company performance.
- Stock: This role is eligible to receive Restricted Stock Units (RSUs).
Global benefits provide options for the following:
- Paid Time Off: earned time off, as well as paid company holidays based on region
- Paid Parental Leave: take up to six months off with your child after birth, adoption or foster care placement
- Full Health Benefits Plans: options for 100% employer paid and minimum employee contribution health plans from day one of employment
- Retirement Plans: select retirement and pension programs with potential for employer contributions
- Learning and Development: options for coaching, online courses and education reimbursements
- Compassionate Care Leave: paid time off following the loss of a loved one and other life-changing events
Life at Docusign
Working here
Docusign is committed to building trust and making the world more agreeable for our employees, customers and the communities in which we live and work. You can count on us to listen, be honest, and try our best to do what's right, every day. At Docusign, everything is equal.
We each have a responsibility to ensure every team member has an equal opportunity to succeed, to be heard, to exchange ideas openly, to build lasting relationships, and to do the work of their life. Best of all, you will be able to feel deep pride in the work you do, because your contribution helps us make the world better than we found it. And for that, you'll be loved by us, our customers, and the world in which we live.
Accommodation
Docusign is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need such an accommodation, or a religious accommodation, during the application process, please contact us at View email address on click.appcast.io.
If you experience any issues, concerns, or technical difficulties during the application process please get in touch with our Talent organization at View email address on click.appcast.io for assistance.
Applicant and Candidate Privacy Notice
States Not Eligible for EmploymentThis position is not eligible for employment in the following states: Alaska, Hawaii, Maine, Mississippi, North Dakota, South Dakota, Vermont, West Virginia and Wyoming.
Equal Opportunity EmployerIt's important to us that we build a talented team that is as diverse as our customers and where all employees feel a deep sense of belonging and thrive. We encourage great talent who bring a range of perspectives to apply for our open positions. Docusign is an Equal Opportunity Employer and makes hiring decisions based on experience, skill, aptitude and a can-do approach. We will not discriminate based on race, ethnicity, color, age, sex, religion, national origin, ancestry, pregnancy, sexual orientation, gender identity, gender expression, genetic information, physical or mental disability, registered domestic partner status, caregiver status, marital status, veteran or military status, or any other legally protected category.
EEO Know Your Rights poster
#LI-Hybrid
- DocuSign, Inc. is seeking a Senior Director, Security Governance, Risk, and Compliance (GRC) to lead their global GRC team. This role requires over 15 years of experience in security leadership, focusing on innovative risk management strategies. The ideal candidate will...Senior
$275k - $300k
...understand the bigger picture and our vision at Postman. About the Team The Information Security organization at Postman operates across three pillars: Governance Risk & Compliance (GRC), Product Security, and Security Operations. We are a team of builders, not...SeniorWork at officeFlexible hours3 days per week$260k - $346k
...Your Impact at LILA Cloud Security & Compliance Lead is responsible for the end-to-end security, governance, risk management, and regulatory compliance of Lila Sciences' cloud environments and research workflows. You'll own cloud security architecture, policy frameworks...SeniorFull timeContract workWork at officeLocal areaFlexible hours- Sr Manager, InfoSec Governance Risk and Compliance (GRC) Founded in 2000, Ivalua is a leading global provider of cloud‑based procurement solutions. Company... ...efforts, and serve as subject‑matter expert on security frameworks and standards. What You Will Do Lead and...SeniorWork at officeWorldwide3 days per week
$112k
...Sr Manager, InfoSec Governance Risk and Compliance (GRC) (San Francisco Bay Area, California, United States) Founded in 2000, Ivalua is a leading global... ...maintaining, and continuously improving Ivalua’s Information Security program globally. We provide peace of mind and...SeniorWork at officeWorldwide- ...Senior Vice President, Legal and Chief Compliance Officer (CCO) About the Company Nationally recognized healthcare services... ...-level role that directly impacts organizational strategy, governance, and risk posture. The successful candidate will be a trusted advisor...Senior
$300k - $360k
Ripple is seeking a Senior Director of Governance, Risk and Compliance in San Francisco. This leadership role involves defining the GRC strategy, leading... ...have over 15 years of experience in information security GRC, including senior roles in high-growth environments...Senior$198k - $368k
...future as we are, join our team. KPMG is currently seeking a Director, Security Compliance to join our Digital Security team. Responsibilities: Apply a comprehensive specialist-level knowledge of risk, compliance, and information security controls to develop and...Temporary workH1bLocal area$250k - $300k
...Director, Security & Compliance San Francisco, CA At Instabase, we're passionate about democratizing access to cutting-edge AI innovation... ...for building and managing out our Security and GRC (Governance, Risk, IT and Compliance) program, driving strategy and execution...Work at officeFlexible hours$130k - $175k
...sensitive technologies, and risks associated with potential exploitation... ...data, demand for national security-focused risk analysis and... ...data analytics, automated compliance monitoring, and advanced security... ...serves as fiduciary to U.S. government agencies as either third-...Full timePart timeFlexible hours$146.4k - $235.38k
...you'll do Docusign is looking for a Senior Security Risk Manager to join our Security Governance, Risk & Compliance (GRC) team. In this hands-on role, you will lead... ...individual contributor role reporting to the Director of Security Product Risk Management. Responsibility...SeniorContract workWork at officeLocal areaRemote work2 days per week- ...Credit Risk Senior Associate In Healthcare Leveraged Finance Bring your expertise... ...JPMorganChase. As part of Risk Management and Compliance, you are at the center of keeping... ...analysis, stress testing, and disciplined risk governance. You will also collaborate with business...Senior
$133.3k - $185k
...policy operations, improving efficiency while maintaining quality, compliance, and trust. • Partner with stakeholder teams to deep dive and... ...experience with expertise in customer experience solutions, risk mitigation, and brand integrity. We seek innovative, customer-...SeniorWork at officeFlexible hours$105k
...Requisition ID # 172697 Job Category: Compliance / Risk / Quality Assurance; Business Operations / Strategy Job Level: Individual Contributor... ...: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction on risk and compliance...SeniorWork experience placementWork at officeWork from homeFlexible hours2 days per week3 days per week- ...Senior Compliance Engineer, AI Governance Space is a warfighting domain. True Anomaly... ...build the technology that secures it. True Anomaly delivers... ...disciplines: an experienced Sr. Compliance Engineer with deep... ...to join our Governance, Risk, and Compliance (GRC) team....SeniorPermanent employment
$159k
...Yuba City Department Overview: The Electric Risk & Compliance organization provides governance, oversight, and strategic direction on risk and compliance... ...minimal information or supervision of a manager or director Ability to analyze complex problems and make...SeniorContract workWork experience placementWork at officeFlexible hours2 days per week3 days per week$161.6k - $202k
...patients - and that responsibility demands a security and compliance program that scales with the business.... ..., SOC 2, PCI-DSS, HIPAA), third-party risk management, security awareness... ...This role reports to Blake Atkinson, Director of Security, and partners closely with...SeniorWork from homeFlexible hours$159k
...Category: Business Operations / Strategy; Compliance / Risk / Quality Assurance Job Level:... ...Risk & Compliance organization provides governance, oversight, and strategic direction on... ...management. Position Summary: As the Sr. Manager, Electric Compliance Controls...SeniorWork experience placementWork at officeFlexible hours$168.3k - $296.7k
...personal information, such as your social security number. What to know: Commvault... ...have relied on Commvault to reduce risks, improve governance, and do more with data. The... ...with a unified lens for visibility, compliance, and resilience, ensuring that as data...Remote workShift work$226k - $270k
...Application Security Senior Manager Prosper is seeking an experienced Application Security Senior Manager to lead our Application Security... ..., prioritization, and remediation based on business risk, exploitability, and threat intelligence) Incident Response:...SeniorWork experience placementRemote workFlexible hours$193k - $220k
...of your success! The Role Andersen is scaling its information security function, and this is a critical hire for the program's next phase of maturity. The Senior Manager, Governance Risk & Compliance (GRC) will report directly to the Chief Information Security Officer...SeniorFull timeH1bLocal areaImmediate startWork visa$300k - $360k
Senior Director of Governance, Risk and Compliance As the Senior Director of GRC, you will define and lead Ripple's Governance, Risk & Compliance strategy... ...This is a high-impact leadership role at the nexus of security, regulatory compliance, and business strategy in one...SeniorFull timeLocal areaWorldwideShift work$122.19k - $221.82k
...as Principal, Cybersecurity Engineering with a focus on Governance, Risk, and Compliance. This is a high-impact role responsible for shaping and sustaining... ...candidate will lead the development and enforcement of security policies, manage third-party vendor risk, drive security...Contract workLocal areaRemote work- Find Your Next Career AEG is dedicated to both the letter and the spirit of the equal employment opportunity laws. It is AEG's policy to prohibit unlawful discrimination against any employee or applicant for employment based on race, color, religion, religious dress...SeniorTemporary work
$148.7k - $240.53k
...seeking a Senior Product Manager to define and advance our Device Security solution - an AI-first solution that discovers, assesses, and... ...capabilities - ML-based discovery, LLM enrichment, multi-factor risk scoring - to partners, customers, and internal stakeholders....SeniorFull timeWork at officeRemote workVisa sponsorshipWork visa$164k - $261.5k
...innovation, and keeping Salesforce’s core values at the heart of it all. Overview of the Role This role is part of the Salesforce Security organization, where we protect one of the world’s most trusted platforms and the customers who rely on it. As the voice of Salesforce...Senior$120k - $150k
...Lifecycle Management (CLM) Data Management & Governance Digital Realty is seeking a driven... ...governance to ensure data consistency, compliance, and accuracy across systems Monitor... ...center platform, provides customers with a secure data meeting place and a proven...SeniorContract workWork at office$161.9k - $218.6k
...solutions into compelling customer value? At AWS, we're seeking a Sr. Product Marketing Manager (PMM) who can shape the future of... ...strategy across multiple domains - from threat detection and network security to identity and access management. We're looking for a unique...SeniorLocal areaFlexible hours$195k - $263k
...The Role Pilot is looking for a Director of Security to establish a world-class security program that protects our customers... ...security roadmap that aligns with Pilot's priorities, risk profile, and compliance needs AI-specific security strategy and considerations...Full timeTemporary workPart timeFlexible hours- ...BSC technology and information security adherence to regulatory standards... ...data. The Technology Risk and External Assurance program runs technology governance forums including the Artificial... ...coordinated SOC 2 and PCI-DSS audit and compliance support, information security...SeniorWork at office2 days per week
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Director, Security Governance, Risk and Compliance. Be the first to apply!
- security engineering manager San Francisco, CA
- director global security San Francisco, CA
- security manager San Francisco, CA
- security project manager San Francisco, CA
- corporate security manager San Francisco, CA
- surveillance manager San Francisco, CA
- program manager with security clearance San Francisco, CA
- physical security manager San Francisco, CA
- security operations manager San Francisco, CA
- senior director information security San Francisco, CA

