Company Overview
Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in 180+ countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. Intelligent agreement management unleashes business‑critical data trapped inside documents, enabling companies to create, commit, and manage agreements with the #1 e‑signature and contract lifecycle management (CLM) platform.
What you’ll do
Senior Security GRC Product Manager owns the strategy, roadmap, and delivery of governance, risk, and compliance (GRC) platforms and capabilities. Partner with engineering, security, compliance, and business stakeholders to design and scale automation‑first solutions that simplify and modernize risk and compliance processes enterprise‑wide.
Responsibilities
- Define and execute the product strategy and roadmap for GRC platforms (ServiceNow IRM, OneTrust, Archer, LogicGate, or custom tools)
- Partner with Security, Engineering, Compliance, and business teams to translate regulatory, audit, and business requirements into scalable workflows and automation
- Collaborate with GRC Engineering to deliver integrations, dashboards, and reporting that provide real‑time visibility into risk, compliance, and control posture
- Act as product owner in agile ceremonies : prioritize backlogs, define user stories, and ensure delivery against roadmap commitments
- Drive the design and continuous improvement of workflows for risk assessments, control testing, policy exceptions, issues management, and evidence collection
- Drive adoption and continuous improvement of GRC tools by engaging with users across engineering, business, and compliance teams
- Ensure GRC platforms are integrated with cloud, SaaS, and enterprise systems to support automated evidence and monitoring
- Deliver dashboards, KPIs, and reporting logic that provide executives with actionable insights
Qualifications
8+ years of experience in product management, security GRC, or related domainsBachelor’s degree in Information Security, Risk Management, Computer Science, or related fieldExperience with security, risk, compliance, and control frameworks (ISO 27001, SOC 2, NIST CSF, FedRAMP, GDPR, DORA, HIPAA)Experience with GRC platforms such as ServiceNow IRM, Archer, OneTrust, or LogicGateProven ability to translate regulatory and security requirements into business and technical specificationsExperience delivering automation‑enabled workflows for GRC use casesPreferred
Excellent stakeholder management skills, ability to influence across engineering, compliance, and executive teamsCertifications such as CISM, CRISC, CISSP, CTPRP, or PMPExperience building dashboards and reporting with tools like Tableau, Power BI, or LookerTrack record of scaling enterprise‑wide GRC programs with automation and integrationsStrong communication and executive presence, experience briefing senior leadershipBenefits
Paid Time Off, Paid Parental Leave, Full Health Benefits Plans, Retirement Plans, Learning and Development, Compassionate Care LeaveLocation
Hybrid : Employee divides time between in‑office and remote work. In‑office expectation : minimum 2 days per week.
Equal Opportunity Employer
Docusign is an Equal Opportunity Employer and makes hiring decisions based on experience, skill, aptitude and a can‑do approach. We will not discriminate based on race, ethnicity, color, age, sex, religion, national origin, ancestry, pregnancy, sexual orientation, gender identity, gender expression, genetic information, physical or mental disability, registered domestic partner status, caregiver status, marital status, veteran or military status, or any other legally protected category.
#J-18808-Ljbffr