Jobs and Careers
DO

Director, Offensive Security

Docusign
Remote, United States, United StatesRemotefull_timeVerifiedPosted 22 Jul 2025
💰 $327,625/yr($174,400/yr$327,625/yr)

About the role

Company Overview

Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).

What you'll do

The Director of Offensive Security owns end‑to‑end offensive security building, coordinating product security incident response (PSIRT), internal/external penetration testing, continuous adversary emulation (red teaming), and more broadly providing an adversarial mindset and TTPs to proactively identify, validate, prioritize, and drive remediation of vulnerabilities and other security risks across products, platforms, and corporate environments.

Through thought leadership and a strong partnership with Security, Product amp; Engineering, and other cross-functional teams, this key leadership role will impact the security posture of Docusign products and services working alongside multiple Security teams including Security Architecture, Bug Bounty, Vulnerability Management, Product Security, Incident Response, and Trust Services.

 

The right candidate has an established record of accomplishment, demonstrates subject area mastery, and experience leading a functional team in product, infra and application security. The ideal candidate will be able to drive clarity of mission and have a strong drive for coaching talent, a bias for action, prioritization and long term impact for this newly formed team.

 

This position is a people manager role reporting to the Group Vice President, Chief Information Security Officer.

 

Responsibility

  • Design and build a world class Offensive Security team and program, applying an adversarial mindset and establishing processes and TTPs to enhance the security of the company and our customers

  • Build and lead a newly defined PSIRT team to build a high performing team to coordinate response and improvements to validated product vulnerability incidents handed

  • Run structured post‑incident reviews focused on exploit mechanics and detection gaps; provide remediation recommendations

  • Set the annual/quarterly penetration testing strategy; oversee internal tests and third‑party engagements for high‑risk products/services

  • Plan and execute intelligence‑driven red team campaigns targeting crown‑jewel assets, lateral movement paths, and detection/control assumptions

  • Coordinate with partner security teams to drive security improvements to infrastructure, services and Docusign products

  • Maintain a unified offensive findings repository; ensure high signal quality, consistent taxonomy, and timely handoff to Vulnerability Management / Product Security

  • Curate external vulnerability and threat intel to prioritize test focus and enrich PSIRT assessments; feed emerging TTPs to Detection and Response

  • Provide pattern and root‑cause insights to Product Security/AppSec for secure design guidance, guardrail tooling, and developer education (advisory role)

  • Partner closely with Vulnerability Management, Product Security, SOC/Detection and Response, Legal, Communications, and Customer Success on coordinated Product response and disclosure

  • Own offensive tooling, lab environments, and automation that improve test fidelity, repeatability, and reporting

  • Recruit, mentor, and retain PSIRT analysts, penetration testers, and red team operators; enforce ethical rules of engagement and data handling

  • Deliver concise executive reporting on offensive coverage, PSIRT responsiveness, detection performance in exercises, and emerging exploit trends—distinct from remediation metrics (owned elsewhere)

  • Escalate urgent exploitability risks when required; drive alignment on priority without assuming downstream remediation control

Job Designation

Remote: Employee is not required to be in or near an office frequently and works from a designated remote work location for the majority of the time.

 

Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on busin

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Docusign

View company profile →