Job Closed
This listing is no longer active.
Bringing Agreements to Life
Lead Security Engineer
Location
United States
Posted
152 days ago
Salary
$157.5K - $254.4K / year
Seniority
Senior
Job Description
Lead Security Engineer
Docusign
• Play a critical role in protecting Docusign’s products and customers by spearheading offensive security testing initiatives • Drive penetration tests, conduct red team exercises, mentor team members, and perform security research • Provide clear technical guidance and direction to the team • Mentor team members, imparting advanced offensive security skills and knowledge • Oversee the planning and execution of offensive security projects • Identify and direct areas for security investigation in coordination with the director and other leads • Serve as a key subject matter expert and point of contact for stakeholders, assisting with vulnerability impact analysis and defining remediation strategies • Work closely with the Product Security Incident Response Team (PSIRT) and engineering teams to analyze and drive the resolution of product security issue • Maintain professional and responsive communication with all stakeholders throughout the security evaluation lifecycle • Message key threats to the business to relevant stakeholders • Collaborate effectively with cross-functional groups, including Threat Intelligence and PSIRT, to continuously strengthen the overall product security posture
Job Requirements
- 12+ years experience (8+ with a Master’s degree) in security research, red teaming or penetration testing experience including on web application security
- Experience in exploit development
- Experience with cybersecurity principles, incident response lifecycles, and security best practices
- Experience with CVSS (Common Vulnerability Scoring System) for rating vulnerabilities, MITRE ATT&CK for adversary tactics and techniques, and CWE (Common Weakness Enumeration) for identifying and categorizing software weaknesses
- Experience leading a team effectively and communicating offensive security findings to leadership
Benefits
- Paid Time Off: earned time off, as well as paid company holidays based on region
- Paid Parental Leave: take up to six months off with your child after birth, adoption or foster care placement
- Full Health Benefits Plans: options for 100% employer paid and minimum employee contribution health plans from day one of employment
- Retirement Plans: select retirement and pension programs with potential for employer contributions
- Learning and Development: options for coaching, online courses and education reimbursements
- Compassionate Care Leave: paid time off following the loss of a loved one and other life-changing events
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer II
LivePersonLivePerson is an online engagement solutions company, which means that it works with clients to provide their customers with real, live assistance and advice. The company was found
• Design, build, and maintain security measures to protect Liveperson's computer systems, networks, and information. • Identify and define security needs for our systems, following industry best practices and rules. • Collaborate with other teams to find, fix, and reduce security issues in our cloud systems, software, and processes. • Write clear instructions and procedures for our security practices. • Develop technical solutions to make our systems more secure and automate repetitive security tasks. • Document, monitor, and report on various security systems and processes to make sure our systems and data are secure and working correctly.
Senior Manager, Information Security Architecture – Engineering
OportunOportun is an A.I.-powered digital banking platform that seeks to make financial health effortless for anyone.
• Define and maintain secure application and infrastructure architecture frameworks, ensuring security is built-in from the outset • Partner with engineering, DevOps, and technology teams to integrate security into SDLC, CI/CD, and data pipelines • Own and oversee the vulnerability management program, ensuring risk-based remediation across all technology assets • Enhance and scale an existing security design review service, providing structured security assessments for new and evolving systems and data • Advocate for security as a service, building tools and processes that streamline secure development and system operations • Act as a security advisor to engineering and technology operations, ensuring security aligns with business goals • Collaborate with the Security Governance, Risk, and Compliance (GRC) team to align technical security requirements with regulatory and commercial requirements • Champion a security-first culture, ensuring technical execution teams understand security risks, standards, and best practices
Staff Security Engineer, Product Security
MozillaThe Mozilla Corporation was founded in 2005 as a taxable, wholly-owned subsidiary of the Mozilla Foundation, which launched in 2003. The corporation serves the
• Safeguard millions of users by embedding security into Firefox, Mozilla VPN, and other mission-critical products. • Ensure software products are secure by embedding security into the full Software Development Life Cycle (SDLC). • Anticipate, prioritize and mitigate risks through proactive threat modeling, security assessments, security testing, and automation. • Perform security code reviews • Lead penetration testing on web, mobile, and embedded applications, then guide remediation efforts. • Develop and maintain automated security tests within CI/CD pipelines to catch vulnerabilities early. • Partner with engineers to integrate security throughout the software development lifecycle—not as an afterthought, but as a core design principle. Provide security guidance, develop secure solutions, and facilitate secure releases. • Help define and enforce security policies and provide security guidance to development teams. • Help shape Mozilla's security culture through collaboration, guidance, and education.
• Conduct analysis and testing of generative AI systems • Conduct sophisticated and comprehensive simulated attacks on generative AI models and their operating environments to uncover vulnerabilities. • Evaluate the security posture of AI models and infrastructure, identifying weaknesses and potential threats. • Perform thorough risk analysis to determine the impact of identified vulnerabilities and prioritize mitigation efforts. • Collaborate with development and security teams to develop effective strategies to mitigate identified risks and enhance model resilience. • Stay abreast of the latest trends and developments in AI security, ethical hacking, and cyber threats. • Maintain detailed documentation of all red team activities, findings, and recommendations. • Prepare and present reports to senior management and relevant stakeholders.




