yoinka

Sr. Security Manager, Public Sector

DocuSign

Seattle, WashingtonFull TimeSenior$146.4k – $206.8k/yrH-1B sponsor companyClearance required
Sign in to applyVerified 2h ago
Location
Seattle, Washington
Employment
Full Time
Work model
On-Site
Level
Senior
Salary
$146.4k – $206.8k/yr
H-1B history
71 approvals (FY2023)
Posted
3h ago

Skills

CybersecuritySAPSplunk

About this role

Company Overview Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).

What you'll do

The Information System Security Officer (ISSO) or Security Manager is a technical individual contributor role. In this capacity, you will act as the primary subject matter expert for the Assessment and Authorization (A and A) process across Docusign's Public Sector Products and Environments. You will report to the Sr. Director of Public Sector and Insider Risk, managing projects, customer deliverables, and initiatives that help ensure the success of all 3rd Party assessments for the Public Sector. Your primary responsibility will be directing the comprehensive development of Authority to Operate (ATO) packages and System Security Plans (SSP) across GovRAMP, FedRAMP High, and DoD Impact Level (IL) environments. This position requires a leader capable of influencing technical infrastructure, product development, and security workstreams to develop and implement effective compliance solutions and rigorous risk assessments. You will serve as a strategic liaison, collaborating across marketing, sales, legal, and customer-facing teams to ensure all initiatives align with relevant compliance standards. Beyond oversight, you will proactively identify potential roadblocks in the FedRAMP Assessment and Authorization process, providing technical guidance to engineering teams to ensure security controls are integrated into the production environments and aligned with current policies and procedures. By fostering deep partnerships with cross-functional stakeholders, you will help translate high-level compliance requirements into actionable technical specifications, ensuring that Docusign's Public Sector offerings remain resilient, secure, and fully authorized to meet the evolving needs of government agencies. This position is an individual contributor role reporting to the Sr. Director, Public Sector and Insider Risk.

Responsibility

Drive the full lifecycle from system categorization to receiving formal ATO for Federal and DoD information systems Develop and maintain Assessment and Authorization artifacts including the System Security Plan (SSP), Security Assessment Plan (SAP), and all Appendix Plans Ensure all ATO package deliverables are audit-ready and align with NIST FedRAMP Special Publications, CNSSI 1253 and the DoD Cloud SRG Lead mature security reviews across core products, microservices, and native cloud environments with high-fidelity artifacts and evidence Maintain and help mature the risk management process using NIST 800-30 or 37 to ensure compliance and proactive risk reduction Improve risk visibility by integrating data from multiple manual or automated assessments and internal audits Develop playbooks and procedures to support technical teams in executing compliance initiatives Present risk in context-regulatory, business, or cybersecurity to ensure alignment with Executive Leadership guidance Maintain and deliver timely Continuous Monitoring (ConMon) and remediation strategies Collaborate with security teams to operationalize new capabilities that support risk reduction and remediation actions Work with Prod or Dev, Sec Architecture, and Infrastructure teams to mitigate systemic vulnerabilities and operationalize known security gaps Drive the remediation of vulnerabilities, ensuring the Plan of Action and Milestones (POA and M) is accurate

Listing verified 2h ago. Applications go through the company's official careers site.

← Back to Yoinka

Sr. Security Manager, Public Sector at DocuSign, Seattle, Washington | Yoinka