Talent.com
Security GRC Engineer

Security GRC Engineer

DocuSign, Inc.San Francisco, CA, United States
4 days ago
Job type
  • Full-time
Job description

Company Overview

Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).

What you'll do

As part of the GRC Engineering team, you will play a key role in transforming how Security GRC operates by modernizing and automating traditional governance, risk, and compliance processes. As a Security GRC Engineer, you are a highly motivated, self-starting problem solver who approaches challenges with creativity and a security-first mindset. You will design, develop, and implement technologies that enhance the effectiveness of Security’s Governance, Risk, and Compliance (GRC) function—building AI-driven and automation-first solutions that improve efficiency, accuracy, and scalability. This is a hands-on, high-impact individual contributor role for those passionate about reimagining traditional GRC through data, automation, and innovation.

This position is an individual contributor role reporting to the Senior Manager of GRC Engineering.

Responsibilities

  • Build and enhance automation across GRC platforms (e.g., ServiceNow IRM, OneTrust, or custom tools)
  • Develop integrations between GRC, cloud and enterprise systems / applications for automated control evidence collection
  • Design and implement AI powered solutions to improve evidence analysis, risk assessments, and control testing
  • Build reporting and visualization capabilities that deliver actionable insights into control health, compliance readiness and risk posture
  • Develop scripts and automation logic to enforce security policies and streamline compliance workflows
  • Manage GRC processes and tools as a product, focusing on delivering continuous value and addressing business and security needs beyond traditional GRC use cases
  • Collaborate with stakeholders to design customer-centric solutions that reduce resource intensive audits, operational toil, and improve security outcomes
  • Support continuous control monitoring and risk metrics pipelines
  • Troubleshoot automation issues, optimize performance, and improve workflow resilience
  • Maintain documentation, runbooks and automation playbooks
  • Advocate for proactive security risk reduction across teams

Job Designation

Hybrid : Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency : Minimum 2 days per week; may vary by team but will be weekly in-office expectation)

Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role / job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law.

What you bring

Basic

  • 5+ years of relevant work experience in Information Security
  • University degree in Computer Science, Information Systems, or related field or equivalent work experience and relevant security certifications (CISSP, etc)
  • Experience with securely implementing AI / ML architecture and platforms in the enterprise
  • Proven ability to develop scalable automated processes via orchestration or automation tools to streamline GRC processes (control testing, evidence collection analysis)
  • Experience with programming languages like Python, C# or other object-oriented languages, SQL, Container
  • Orchestration services including Docker and Kubernetes, and a variety of Azure tools and services
  • Strong familiarity with Cloud Security Controls (Azure, GCP, AWS) and how to apply, measure, and validate the effectiveness of security controls
  • Preferred

  • One or more of these certifications : CISM, CISA, CISSP, CEH, CompTIA Security+, AWS / Azure Security
  • Experience and familiarity with new AI technologies (such as agents / agentic workflows, LLM APIs, etc)
  • Experience designing and delivering technology solutions in the enterprise
  • Familiarity with AI governance and risk management frameworks (NIST AI RMF, ISO 42001)
  • Knowledge of regulations and standards including PCI-DSS, ISO 27001, OWASP, and NIST Cybersecurity Frameworks
  • Proactive, demonstrated self-starter, open to learning new security topics, flexible and organized
  • Ability to review and interpret data and extract key insights
  • Strong communication, collaborative, and interpersonal skills
  • Strong documentation and reporting skills
  • Solid understanding of information security concepts, processes, controls and tools
  • Life at Docusign

    Working here

    Docusign is committed to building trust and making the world more agreeable for our employees, customers and the communities in which we live and work. You can count on us to listen, be honest, and try our best to do what’s right, every day. At Docusign, everything is equal.

    We each have a responsibility to ensure every team member has an equal opportunity to succeed, to be heard, to exchange ideas openly, to build lasting relationships, and to do the work of their life. Best of all, you will be able to feel deep pride in the work you do, because your contribution helps us make the world better than we found it. And for that, you’ll be loved by us, our customers, and the world in which we live.

    Accommodation

    Docusign is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need such an accommodation, or a religious accommodation, during the application process, please contact us at accommodations@docusign.com.

    If you experience any issues, concerns, or technical difficulties during the application process please get in touch with our Talent organization at taops@docusign.com for assistance.

    Applicant and Candidate Privacy Notice

    #LI-Hybrid #LI-SA4

    #J-18808-Ljbffr

    Create a job alert for this search

    Security Engineer • San Francisco, CA, United States