Director, Offensive Security
DocusignAbout the role
Company Overview
Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).
What you'll do
The Director of Offensive Security owns end‑to‑end offensive security building, coordinating product security incident response (PSIRT), internal/external penetration testing, continuous adversary emulation (red teaming), and more broadly providing an adversarial mindset and TTPs to proactively identify, validate, prioritize, and drive remediation of vulnerabilities and other security risks across products, platforms, and corporate environments.
Through thought leadership and a strong partnership with Security, Product amp; Engineering, and other cross-functional teams, this key leadership role will impact the security posture of Docusign products and services working alongside multiple Security teams including Security Architecture, Bug Bounty, Vulnerability Management, Product Security, Incident Response, and Trust Services.
The right candidate has an established record of accomplishment, demonstrates subject area mastery, and experience leading a functional team in product, infra and application security. The ideal candidate will be able to drive clarity of mission and have a strong drive for coaching talent, a bias for action, prioritization and long term impact for this newly formed team.
This position is a people manager role reporting to the Group Vice President, Chief Information Security Officer.
Responsibility
Design and build a world class Offensive Security team and program, applying an adversarial mindset and establishing processes and TTPs to enhance the security of the company and our customers
Build and lead a newly defined PSIRT team to build a high performing team to coordinate response and improvements to validated product vulnerability incidents handed
Run structured post‑incident reviews focused on exploit mechanics and detection gaps; provide remediation recommendations
Set the annual/quarterly penetration testing strategy; oversee internal tests and third‑party engagements for high‑risk products/services
Plan and execute intelligence‑driven red team campaigns targeting crown‑jewel assets, lateral movement paths, and detection/control assumptions
Coordinate with partner security teams to drive security improvements to infrastructure, services and Docusign products
Maintain a unified offensive findings repository; ensure high signal quality, consistent taxonomy, and timely handoff to Vulnerability Management / Product Security
Curate external vulnerability and threat intel to prioritize test focus and enrich PSIRT assessments; feed emerging TTPs to Detection and Response
Provide pattern and root‑cause insights to Product Security/AppSec for secure design guidance, guardrail tooling, and developer education (advisory role)
Partner closely with Vulnerability Management, Product Security, SOC/Detection and Response, Legal, Communications, and Customer Success on coordinated Product response and disclosure
Own offensive tooling, lab environments, and automation that improve test fidelity, repeatability, and reporting
Recruit, mentor, and retain PSIRT analysts, penetration testers, and red team operators; enforce ethical rules of engagement and data handling
Deliver concise executive reporting on offensive coverage, PSIRT responsiveness, detection performance in exercises, and emerging exploit trends—distinct from remediation metrics (owned elsewhere)
Escalate urgent exploitability risks when required; drive alignment on priority without assuming downstream remediation control
Job Designation
Remote: Employee is not required to be in or near an office frequently and works from a designated remote work location for the majority of the time.
Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on busin
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s