Sr. Software Engineer
DocuSign
- Location
- Seattle, Washington
- Employment
- Full Time
- Work model
- On-Site
- Level
- Senior
- Salary
- $158.3k – $232.6k/yr
- H-1B history
- 71 approvals (FY2023)
- Posted
- 1h ago
Skills
About this role
Company Overview Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).
What you'll do
As a Senior Software Engineer on the Data Protection team, you'll be a key player in building the cryptographic foundation for Docusign's global infrastructure. You'll drive the engineering for our enterprise key management platform - owning the systems that enable customers to control their own encryption keys and extending cryptographic protection across our data stores and services. Looking ahead, you'll help define how key management and cryptographic controls evolve alongside Docusign's platform - ensuring our data protection posture stays ahead of industry standards and enterprise customer expectations. Our team is passionate about delivering high-quality, fully-tested code to ensure the level of security and reliability our customers depend on. This is a hands-on role where you'll help drive technical direction, secure our platform, and directly enable Docusign's Intelligent Agreement Management by delivering trusted data protection solutions to enterprise customers. This position is an individual contributor role reporting to the Sr. Engineering Manager, Data Protection.
Responsibility
Design and build cryptographic key management systems that support the full key lifecycle - generation, distribution, rotation, revocation, and expiry across cloud environments at enterprise scale Build and maintain operational tooling for the health, observability, and reliability of cryptographic services and key integrations Drive adoption of encryption best practices across Docusign's platform, establishing and evolving standards for data-at-rest and data-in-transit protection Collaborate with engineering teams across the company to ensure their systems correctly support data protection requirements - advising on encryption patterns, key management constraints, and data isolation boundaries Contribute to threat modeling and security design reviews for new platform initiatives, identifying cryptographic and data protection risks early in the development lifecycle Develop high-quality, ship-ready code covered by a full test suite Conduct design and code reviews with a focus on security and availability not just coding to a spec Job Designation Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation) Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law. What you bring Basic 8+ years of hands-on development experience in C# or other object-oriented languages 8+ years of software engineering experience in high-scale distributed systems Experience with cloud Key Management Services (KMS) AWS KMS, Azure Key Vault, GCP Cloud KMS, or equivalent - including key lifecycle management (rotation, revocation, expiry) and cross-tenant or cross-account key access patterns Experience with encryption fundamentals key wrapping (DEK/KEK model), asymmetric key operations, and cryptographic key lifecycle management B.S. or M.S. in Computer Science