Jobs and Careers
DO

Senior Security GRC Engineer

Docusign
San Francisco, United Statesfull_timeVerifiedPosted 6 Oct 2025
💰 $254,350/yr($151,200/yr$254,350/yr)

About the role

Company Overview

Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).

What you'll do

Docusign is hiring a Senior Security GRC Engineer to design, build, and scale the next generation of automation-first GRC solutions. This is a high impact, hands-on technical role for independent thinkers who are passionate about solving technical problems with a GRC and Security lens.

As a Senior Security GRC Engineer, you are a highly motivated self-starter, responsible for transforming traditional governance, risk, and compliance processes into intelligent, data-driven, and automated systems. You will architect solutions that integrate across enterprise GRC platforms, cloud services, and data pipelines, applying advanced automation and AI/ML techniques to improve security outcomes, reduce audit fatigue, and enable continuous control monitoring.

The ideal candidate brings deep technical expertise in security engineering, automation, and cloud platforms, along with the ability to translate compliance and risk requirements into scalable engineering solutions. This position offers the opportunity to shape how GRC is delivered across the enterprise, working at the intersection of engineering, security, and business needs.

This position is an individual contributor role reporting to the Senior Manager of GRC Engineering.

Responsibility

  • Architect and implement automation frameworks that connect GRC platforms, cloud services, and enterprise data systems to enable continuous control monitoring

  • Design and implement AI/ML-enabled solutions for risk scoring, control validation, evidence collection, and anomaly detection in compliance data

  • Build advanced dashboards and data pipelines that integrate metrics across multiple systems to provide actionable insights

  • Engineer scalable, automated and orchestration workflows to enforce policies, detect configuration drift, and remediate non-compliant systems at scale

  • Extend and enhance enterprise GRC platforms (e.g., ServiceNow, OneTrust) through custom workflows, connectors, and APIs

  • Perform advanced scripting, orchestration, and data engineering (Python, C#, SQL, Docker, Kubernetes) to deliver scalable solutions

  • Evaluate and implement emerging technologies (e.g., generative AI, NLP, graph analytics) to improve GRC outcomes

  • Act as a technical leader and mentor, guiding GRC engineers on automation, cloud security controls, and secure system design

  • Operate GRC processes and tools as a product, ensuring continuous value delivery and extending capabilities beyond traditional GRC use cases

  • Partner with engineering, security, compliance, and audit teams to shape requirements and deliver solutions that scale

  • Champion automation-first GRC practices that reduce audit fatigue and operational overhead

Job Designation

Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation)

 

Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law.

What you bring

Basic

  • 8+ years of experience in Information Security, with significant focus on GRC engineering and automation

  • University degree in Computer Science, Information Systems, or related field

  • One or more of these certifications: CISM, CISA, CISSP, CEH, CompTIA Security+, AWS/Azure Security

  • Experience desiging and deploying scalable automated processes via orchestration or automation tools to streamline GRC processes (control testing, evidence collection and analysis)

  • Experience with programming and orchestration (Python, C#, SQL, Container Orchestration Services including Docker and Kubernetes)

  • Exper

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Docusign

View company profile →