Senior Security Compliance Manager
DocusignAbout the role
Company Overview
Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).
What you'll do
The Senior Security Compliance Manager is responsible for managing and maintaining new and ongoing security certifications and self-assessments for Docusign. These include, but aren't limited to, ISO 27001, 27017, 27018, PCI-DSS 4.0, IRAP, APEC PRP, C5, ISMAP, FISC, SIG, and CSA STAR.
The person in this role must ensure that Docusign complies with all relevant security frameworks, regulations, standards, and policies. You will drive the cross-functional work needed to implement the management, operational, and technical security controls required for compliance. This involves close collaboration with all control owners and teams like Product and Engineering, IT, Security, US Public Sector Compliance, and Legal Product and Regulatory Compliance. This is a hands-on position where you'll build relationships with internal control owners and global stakeholders to represent Docusign's Security Compliance programs.
This is an individual contributor role that reports to the Director, Security Compliance.
Responsibility
Conduct security compliance audits and assessments including customer audits independently end-to-end while adhering to strict deadlines and maintaining executive level metrics and reporting
Be the subject matter expert to lead compliance discussions, awareness, internal and external audit interviews
Work with product and engineering, business, and technology teams to define and maintain an effective suite of controls adapting to changes in products, business processes and technology solutions
Manage audit deliverables, identify, and analyze process gaps, provide guidance and expertise to control owners, develop remediation recommendations, and track to completion
Review and manage customer facing security and compliance documents and white papers
Develop and maintain strong relationships based on trust and transparency with control owners, auditors, and customers
Establish governance across projects with structure on tracking and reporting. Develop metrics to measure and track compliance, risk and the effectiveness of the security compliance program
Document and socialize the security compliance programs to provide transparency to control owners and obtain actionable commitment from relevant stakeholders
Identify automation opportunities and implement scalable solutions including technical and monitoring controls
Job Designation
Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation)
Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law.
What you bring
Basic
Self-starter with excellent communication, collaborative, and presentation skills
University degree in Computer Science, Information Systems, or a related field or equivalent work experience
8+ years of relevant work experience in Security, Compliance, Auditing, Assessments or other GRC related experience
3-5 years of managing security compliance audits and/or customer audits
Experience with audit lifecycle including testing controls and writing test scripts in various environments and functions
Experience in working with cross functional departments and stakeholders to provide security compliance issues, risks, and recommendations
Industry certification such as CISSP, CISA, CISM, CRISC, ISO27001 Lead Auditor, CompTIA Security+, AWS/Azure Security, and/or equivalent GRC certification
Ability to review compliance evidences required for audit
Ability to coach and prepare technica
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s