Security GRC Engineer (San Francisco) Job at DocuSign, Inc., San Francisco, CA

R3Z2ZjZXdE0vajZYVU0vcllYRnJwMVVUWUE9PQ==
  • DocuSign, Inc.
  • San Francisco, CA

Job Description

Company Overview

Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify peoples lives. With intelligent agreement management, Docusign unleashes businesscritical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusigns Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in esignature and contract lifecycle management (CLM).

What you'll do

As part of the GRC Engineering team, you will play a key role in transforming how Security GRC operates by modernizing and automating traditional governance, risk, and compliance processes. As a Security GRC Engineer, you are a highly motivated, selfstarting problem solver who approaches challenges with creativity and a securityfirst mindset. You will design, develop, and implement technologies that enhance the effectiveness of Securitys Governance, Risk, and Compliance (GRC) functionbuilding AIdriven and automationfirst solutions that improve efficiency, accuracy, and scalability. This is a handson, highimpact individual contributor role for those passionate about reimagining traditional GRC through data, automation, and innovation.

This position is an individual contributor role reporting to the Senior Manager of GRC Engineering.

Responsibility

  • Build and enhance automation across GRC platforms (e.g., ServiceNow IRM, OneTrust, or custom tools)
  • Develop integrations between GRC, cloud and enterprise systems / applications for automated control evidence collection
  • Design and implement AI powered solutions to improve evidence analysis, risk assessments, and control testing
  • Build reporting and visualization capabilities that deliver actionable insights into control health, compliance readiness and risk posture
  • Develop scripts and automation logic to enforce security policies and streamline compliance workflows
  • Manage GRC processes and tools as a product, focusing on delivering continuous value and addressing business and security needs beyond traditional GRC use cases
  • Collaborate with stakeholders to design customercentric solutions that reduce resource intensive audits, operational toil, and improve security outcomes
  • Support continuous control monitoring and risk metrics pipelines
  • Troubleshoot automation issues, optimize performance, and improve workflow resilience
  • Maintain documentation, runbooks and automation playbooks
  • Advocate for proactive security risk reduction across teams

Job Designation

Hybrid: Employee divides their time between inoffice and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly inoffice expectation)

Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a positions job designation depending on business needs and as permitted by local law.

What you bring

Basic

  • 5+ years of relevant work experience in Information Security
  • University degree in Computer Science, Information Systems, or related field or equivalent work experience and relevant security certifications (CISSP, etc)
  • Experience with securely implementing AI/ML architecture and platforms in the enterprise
  • Proven ability to develop scalable automated processes via orchestration or automation tools to streamline GRC processes (control testing, evidence collection analysis)
  • Experience with programming languages like Python, C#, or other objectoriented languages, SQL, Container
  • Orchestration services including Docker and Kubernetes, and a variety of Azure tools and services
  • Strong familiarity with Cloud Security Controls (Azure, GCP, AWS) and how to apply, measure, and validate the effectiveness of security controls

Preferred

  • One or more of these certifications: CISM, CISA, CISSP, CEH, CompTIA Security+, AWS/Azure Security
  • Experience and familiarity with new AI technologies (such as agents/agentic workflows, LLM APIs, etc)
  • Experience designing and delivering technology solutions in the enterprise
  • Familiarity with AI governance and risk management frameworks (NIST AI RMF, ISO 42001)
  • Knowledge of regulations and standards including PCIDSS, ISO 27001, OWASP, and NIST Cybersecurity Frameworks
  • Proactive, demonstrated selfstarter, open to learning new security topics, flexible and organized
  • Ability to review and interpret data and extract key insights
  • Strong communication, collaborative, and interpersonal skills
  • Strong documentation and reporting skills
  • Solid understanding of information security concepts, processes, controls and tools

Life at Docusign

Working here

Docusign is committed to building trust and making the world more agreeable for our employees, customers and the communities in which we live and work. You can count on us to listen, be honest, and try our best to do whats right, every day. At Docusign, everything is equal.

We each have a responsibility to ensure every team member has an equal opportunity to succeed, to be heard, to exchange ideas openly, to build lasting relationships, and to do the work of their life. Best of all, you will be able to feel deep pride in the work you do, because your contribution helps us make the world better than we found it. And for that, youll be loved by us, our customers, and the world in which we live.

Accommodation

Docusign is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need such an accommodation, or a religious accommodation, during the application process, please contact us at [email protected].

If you experience any issues, concerns, or technical difficulties during the application process please get in touch with our Talent organization at [email protected] for assistance.

Applicant and Candidate Privacy Notice

#LI-Hybrid #LI-SA4

#J-18808-Ljbffr

Job Tags

Full time, Contract work, Work experience placement, Work at office, Local area, Remote work, Flexible hours, 2 days per week,

Similar Jobs

Denova Collaborative Health

Billing Specialist - Patient Collections Job at Denova Collaborative Health

 ...Billing Specialist Patient Collections Job Purpose: The Billing Specialist Patient Collections is responsible for providing patient...  ...equivalent required; post-secondary coursework or certification in Medical Billing & Coding or Healthcare Administration preferred.... 

jobgether

Architectural Designer - REMOTE Job at jobgether

 ...This position is posted by Jobgether on behalf of a partner company. We are currently looking for an Architectural Designer. In this role, you will be responsible for assisting project teams from early design through construction, gaining valuable experience while contributing... 

Wegmans Food Markets

Store Security Specialist Job at Wegmans Food Markets

 ...Schedule: Part time Availability: Morning, Afternoon, Evening (Includes Weekends). Age Requirement: Must be 18 years or older...  ...) or First Responder Leadership experience, preferably in a retail setting At Wegmans, weve always believed we can achieve our... 

Peraton

Logistics Services Manager Job at Peraton

 ...USINDOPACOM AOR. They include but are not limited to Program Management and Services in Planning, Logistics, Training, Strategic Engagement, Analytics, Business...  .... This includes developing and implementing robust supply chain processes to ensure timely procurement,... 

World Nurses

Travel Sterile Processing Technologist Job at World Nurses

Job Description World Nurses is seeking a travel Sterile Processing Technician for a travel job in Arcata, California. Job Description & Requirements ~ Specialty: Sterile Processing Technician ~ Discipline: Allied Health Professional ~ Duration: 13 weeks ...