Docusign

Founded in 2003, Docusign is an electronic signature and transaction management firm with over 1 million customers and billions of users across the globe. Docusign has won the pres

Senior Incident Commander

Location

Worldwide

Posted

2 days ago

Salary

$137.8K - $266K / year

Seniority

Senior

Job Description

Senior Incident Commander

Docusign

Title: Senior Incident Commander Location: United States Job Description: Company Overview Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people's lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign's Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM). What you'll do The Senior Incident Commander is part of the SRE Incident Response team at Docusign. The role is around leading and facilitating incidents and incident management processes around our products and security. The role involves strategic project management, effective communication with stakeholders including executive leadership, and handling challenging incidents independently. They play a pivotal role in developing Docusign's overall service excellence practice by creating standard operating procedures, training material, operationalizing action items and provide valuable metrics for improvement. The role also requires daily incident management support across various Docusign infrastructures globally, ensuring the maintenance of service levels. The role will facilitate resolution for all major incidents, and handling communications via bridge calls and emails. The role includes on-call responsibilities outside business hours and weekends, daily reporting, ticket administration, and general production assurance duties. The ideal candidate is self-motivated and responsible, with the ability to prioritize under heavy workloads and operate under time constraints. Adherence to established procedures and detailed documentation of incidents and resolution steps is essential. This position is an individual contributor role reporting to the Sr. Manager, SRE Incident Command. Responsibility - Serve as a subject matter expert for Docusign's incident management - Partner with the SRE team to manage complex and sensitive critical incidents to conclusion, identifying and resolving challenges to ensure timely resolution - Partner with Service Owners and SRE to craft quality RCA and drive improvements across the domain to minimize number of incidents and their severity - Monitor, evaluate and report on incident management programs, processes and statistics to assure continuous improvement, implementing automated procedures to capture such data consistently - Lead post-incident reviews (RCA) by working with Service Owners and SREs to identify root causes, propose actionable improvements, and implement processes that minimize the number and severity of future incidents - Leverage organizational data to analyze incident trends, operational success metrics, and key areas for improvement, enabling data-driven decision-making and proactive prevention strategies - Utilize advanced reporting tools to proactively identify issues, systemic trends, and data anomalies - Utilize advanced monitoring and automation tools to identify opportunities to reduce response times, and ensure swift mitigation of risks, enabling more efficient management of major incidents and preventing incident recurrence - Interact regularly with senior leaders to facilitate effective incident handling or project delivery, producing suitable communications - Generate communications for multiple audience types, both customer-facing and internal - Prioritize incidents based on impact and urgency and classify them based on customer and operational impact, ensuring efficient resource allocation and effective resolution - Engage resources to resolve major incidents and minimize customer/business impact, managing escalation pathos as necessary - Serve as an escalation point within the Incident Management process, contributing to and initiating Crisis Incident response processes and applying the escalation process when required - Analyze incident data for anomalies, correlations, and trends against operational success criteria to improve incident response and prevention strategies - Participate in a rotational shift 24 x 7 x 365 Job Designation Remote: Employee is not required to be in or near an office frequently and works from a designated remote work location for the majority of the time. Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law. What you bring Basic - 8+ years experience in Incident Management, including leadership of major incidents and high-severity situations - Experience in operating and implementing Incident Management tools - Experience monitoring platforms and applications like Prometheus, Grafana, Azure Data Explorer, Incident.io - Experience with cloud and on-premise system architecture and design - Experience with troubleshooting techniques and problem-solving in a 24x7x365 environment Preferred - Completion of recognized incident command training (e.g., ICS certifications) and the ability to apply structured command and communication during major incidents - Experience analyzing incidents from customers perspective and drive through all phases to mitigation - Experience leading during incident calls, confidently driving towards resolution while communicating progress effectively to all stakeholders - Strong cross-functional collaboration, coordinating with multiple internal teams to establish containment and remediation strategies are implemented and carried out - Ability to lead incident calls confidently and independently to a successful resolution - Ability to understand and work within complex, large enterprise business environments - Process improvement experience, including conducting process analysis, identifying inefficiencies, and implementing recommended solutions - Experience managing complex security and privacy investigations - Excellent oral and written communication skills, with the ability to tailor messages for technical and non-technical audiences - Ability to work well interpersonally across various levels and disciplines, as well as influence and manage without direct authority - Skilled in understanding infrastructure dependencies and system integrations to perform troubleshooting in public/private cloud environments - Applied mitigation experience with microservices architecture, CI/CD pipelines, network architecture, data storage solutions, and virtualization across hybrid environments, ensuring rapid incident resolution, effective rollback practices, and minimized downtime in highly distributed systems - Strong understanding of TCP/IP networking, DNS, Load Balancing, and SSL/TLS protocols to assist in diagnosing connectivity and performance issues Wage Transparency Pay for this position is based on a number of factors including geographic location and may vary depending on job-related knowledge, skills, and experience. Based on applicable legislation, the below details pay ranges in the following locations: California: $164,700.00 - $266,000.00 base salary Illinois, Colorado, Massachusetts and Minnesota: $158,300.00 - $223,625.00 base salary Washington, Maryland, New Jersey and New York (including NYC metro area): $158,300.00 - $232,575.00 base salary Washington DC: $164,700.00 - $232,575.00 base salary Ohio: $137,800.00 - $194,650.00 base salary This role is also eligible for the following: - Bonus: Sales personnel are eligible for variable incentive pay dependent on their achievement of pre-established sales goals. Non-Sales roles are eligible for a company bonus plan, which is calculated as a percentage of eligible wages and dependent on company performance. - Stock: This role is eligible to receive Restricted Stock Units (RSUs). Global benefits provide options for the following: - Paid Time Off: earned time off, as well as paid company holidays based on region - Paid Parental Leave: take up to six months off with your child after birth, adoption or foster care placement - Full Health Benefits Plans: options for 100% employer paid and minimum employee contribution health plans from day one of employment - Retirement Plans: select retirement and pension programs with potential for employer contributions - Learning and Development: options for coaching, online courses and education reimbursements - Compassionate Care Leave: paid time off following the loss of a loved one and other life-changing events Life at Docusign Working here Docusign is committed to building trust and making the world more agreeable for our employees, customers and the communities in which we live and work. You can count on us to listen, be honest, and try our best to do what's right, every day. At Docusign, everything is equal. We each have a responsibility to ensure every team member has an equal opportunity to succeed, to be heard, to exchange ideas openly, to build lasting relationships, and to do the work of their life. Best of all, you will be able to feel deep pride in the work you do, because your contribution helps us make the world better than we found it. And for that, you'll be loved by us, our customers, and the world in which we live. Accommodation Docusign is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need such an accommodation, or a religious accommodation, during the application process, please contact us at accommodations@docusign.com. If you experience any issues, concerns, or technical difficulties during the application process please get in touch with our Talent organization at taops@docusign.com for assistance. Applicant and Candidate Privacy Notice States Not Eligible for Employment This position is not eligible for employment in the following states: Alaska, Hawaii, Maine, Mississippi, North Dakota, South Dakota, Vermont, West Virginia and Wyoming. Equal Opportunity Employer It's important to us that we build a talented team that is as diverse as our customers and where all employees feel a deep sense of belonging and thrive. We encourage great talent who bring a range of perspectives to apply for our open positions. Docusign is an Equal Opportunity Employer and makes hiring decisions based on experience, skill, aptitude and a can-do approach. We will not discriminate based on race, ethnicity, color, age, sex, religion, national origin, ancestry, pregnancy, sexual orientation, gender identity, gender expression, genetic information, physical or mental disability, registered domestic partner status, caregiver status, marital status, veteran or military status, or any other legally protected category. EEO Know Your Rights poster #LI-Remote

Related Job Pages

More Incident Response Analyst Jobs

AppGate Cybersecurity, Inc. logo

L1 Analyst

AppGate Cybersecurity, Inc.

AppGate is a leading cybersecurity company and pioneer in the Zero Trust Network Access (ZTNA) market focused on providing cutting-edge solutions that protect organizations from evolving threats. Our mission is to support the warfighter, the national security community, and critical infrastructure by providing trusted access that ensures mission success.

Role Description We are looking for a highly curious and proactive L1 Analyst to join our GFC operations team. In this role, you will take on the first line of defense with an analytical approach, handling the investigation and mitigation of cybersecurity events for our clients. We value curiosity above all. We are looking for someone who doesn’t just see an alert and pass it on, but who asks "why?", digs deeper into data, investigates anomalies, and actively proposes new ideas and tools to improve our processes. Qualifications - Education: Student or Graduate in Systems Engineering, Telecommunications, Electronics, Mechatronics, or similar. - Experience: At least 1 year of experience in operations environments (SOC, Help Desk, or similar roles). - Technical Knowledge: - Solid understanding of Windows and Linux Operating Systems. - Basic knowledge of HTML and web fundamentals. - Language: Intermediate English level (B1+ or B2, spoken and written). - Soft Skills (The Core of our Team): - Natural Curiosity: A passion for investigative work, asking the right questions, and going beyond the surface of an alert. - Innovation & Proactivity: Innovation is part of our organizational values; we want someone who brings ideas. - Effective communication, problem-solving skills, and adaptability to change. Requirements - First Responder: Act as the initial point of contact for security events received via tickets, email, and telephone, ensuring elite communication with clients. - Proactive Threat analysis & Monitoring: Perform continuous monitoring, proactive searches, threat analysis, and vulnerability assessments using both documented procedures and your own investigative instinct. - Incident Response & Escalation: Solve technical problems independently. When necessary, accurately escalate complex issues to Level 2 analysts and Team Leaders. - Continuous Improvement: Actively participate and propose ideas in investigations focused on key information gathering. Explore and test new monitoring and remediation tools. - Documentation & Best Practices: Meticulously document all actions taken within incident management. Recommend improvements to GFC processes, procedures, and security policies of the area. - Team Collaboration: Collaborate with local team members, external staff, and participate in the training of junior analysts and interns. Benefits - Extensive Health Insurance Coverage for the Employee and Their Family - Fitness Allowance - Remote Work Stipend - Access to an E-Learning Platform

Colombia
Concurrent Technologies Corporation logo

Incident Response Analyst

Concurrent Technologies Corporation

Going above and beyond to create innovative, full lifecycle solutions. We make the world safer and more productive.

Full TimeRemoteTeam 201-500Since 1987H1B No Sponsor

Role Description Atuação no desenvolvimento e evolução de automações de resposta a incidentes, com foco na construção de playbooks e integrações entre ferramentas de segurança e TI. O profissional será responsável por otimizar processos de resposta, aumentar a eficiência operacional do SOC e contribuir para a maturidade das operações de segurança por meio de automação. - Desenvolver e manter playbooks de resposta automatizada a incidentes - Integrar soluções de segurança como EDR, SIEM, ferramentas de ITSM e e-mail - Analisar falhas em automações e ajustar a lógica dos fluxos de resposta - Criar e manter documentação técnica dos processos automatizados - Apoiar a geração de relatórios e métricas relacionadas às automações Qualifications - Experiência com plataformas SOAR, preferencialmente D3 Security - Experiência com integração via APIs - Conhecimento em scripting (Python e/ou JavaScript) - Domínio de fluxos de resposta a incidentes (Incident Response) - Experiência com integração de ferramentas de ITSM (ex.: ServiceNow, GLPI) Requirements - Treinamentos ou certificações em plataformas SOAR - Certificação SANS SEC450 ou equivalente - Experiência prévia em ambientes de SOC com automação de processos

Brazil
Rapid7 logo

Incident Handler

Rapid7

At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what’s possible and drive extraordinary impact. We’re building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,000+ customers against bad actors and threats means we’re continuing to push the envelope - just like we’ve been doing for the past 20 years. If you’re ready to solve some of the toughest challenges in cybersecurity, we’re ready to help you take command of your career. Join us.

Full TimeRemoteTeam 1,001-5,000Since 2000H1B Sponsor

Incident Handler II, Detection & Response Services We are looking for people with a passion for investigation and forensic analysis to join our MDR SOC team at Rapid7. As an Incident Handler II, you will work side by side MDR SOC analysts and MDR Incident Responders to investigate incidents ranging from commodity malware to sophisticated threat actors. About the Team Rapid7's Managed Detection and Response (MDR) team is built from the ground up to bring motivated and passionate security talent face to face with emerging threats, practical challenges, and evil at scale. Our MDR service uses an impact-driven mindset to focus efforts on effective solutions, encouraging personal and technical innovation within the SOC. MDR provides 24/7/365 monitoring, threat hunting, incident response, and more with a focus on endpoint detection and behavioral intelligence. About the Role As an Incident Handler II in Rapid7's SOC, you will be responsible for investigating and analyzing malicious activity in a multitude of customer environments. You will be enabled to complete investigations scaling in complexity from account compromises and commodity malware infections, to complex web server compromises and zero-day vulnerability exploitation. The trigger for the majority of these investigations will be from inbound customer requests, but you will also receive investigations handed off to you from frontline analysts. There may be times where you're triaging alerts using Rapid7's award-winning SIEM, InsightIDR, where you'll find malicious activity that you'll need to investigate and escalate to customers. In these investigations, your Cybersecurity Advisor colleagues will be largely responsible for direct communication with the customers regarding your investigations, however you will be expected to engage with customers as needed to drive more complex investigations forward. Lastly, you're the go-to person for handling incident response engagements run by Rapid7's Incident Response team. In this role, you will: - As a core duty, you will conduct investigations into a variety of malicious activity on workstations, servers, and in the cloud. You will investigate all levels of incidents, including Incident Response engagements in which you will provide analysis assistance to Rapid7's Incident Responders, including scoping, timeline analysis, finding IAV, and helping update documents as needed. - Own complex investigations that may need various levels of delegation, customer communication, documentation, and collaboration across teams. - Be an escalation point for complex and advanced incidents. - Communicate with Cybersecurity Advisors regarding investigation findings, Requests For Information from clients, and remediation and mitigation recommendations. - Directly communicate with customers regarding investigation findings or to assist in driving an investigation forward as needed. - Prepare Incident Reports for each minor incident investigation you complete, which follow MITRE's ATT&CK Framework and include your own forensic, malware, and root-cause analysis. - Communicate with other analysts to share new intelligence regarding tactics, techniques, and trends utilized by threat actors. - Provide continuous input to Rapid7's Threat Intelligence and Detection Engineering team regarding new detection opportunities. - Assist in customer engagement opportunities pertaining to the function of your role in the MDR service as necessary. - Participate in projects that directly relate to your role in an effort to increase positive customer outcomes. - Utilize Rapid7's world-class software to triage and investigate alerts to identify potential compromises in customer environments as necessary. The skills you'll bring include: - 3-4 years of experience in a cybersecurity related position (SOC and/or SIEM analysis experience preferred) - Dedication to putting each customer's needs and concerns at the forefront of all decision making. - Understanding of core operating system concepts in Windows, MacOS/Darwin, and Linux. This includes at least an understanding of common internal system tools and directory structures. - Proficiency with analyzing forensic artifacts to determine root cause analysis in investigation - Windows largely preferred, but bonus points for experience with Linux, AWS, Azure, and GCP) - A fundamental understanding of how threat actors utilize tactics such as lateral movement, privilege escalation, defense evasion, persistence, command and control, and exfiltration. - Effective verbal communication skills that foster collaboration between the MDR SOC and the Incident Response team; this role serves as the bridge between our major service delivery functions. - Strong written communication skills - Some experience with static and dynamic malware analysis. - Passion for continuous learning and growth in the cybersecurity world. We know that the best ideas and solutions come from multi-dimensional teams. That's because these teams reflect a variety of backgrounds and professional experiences. If you are excited about this role and feel your experience can make an impact, please don't be shy - apply today. About Rapid7 At Rapid7, we are on a mission to create a secure digital world for our customers, our industry, and our communities. We do this by embracing tenacity, passion, and collaboration to challenge what's possible and drive extraordinary impact. Here, we're building a dynamic workplace where everyone can have the career experience of a lifetime. We challenge ourselves to grow to our full potential. We learn from our missteps and celebrate our victories. We come to work every day to push boundaries in cybersecurity and keep our 10,000 global customers ahead of whatever's next. Join us and bring your unique experiences and perspectives to tackle some of the world's biggest security challenges. #LI-WP1 #LI-Remote About Rapid7 At Rapid7, our vision is to create a secure digital world for our customers, our industry, and our communities. We do this by harnessing our collective expertise and passion to challenge what's possible and drive extraordinary impact. We're building a dynamic and collaborative workplace where new ideas are welcome. Protecting 11,500+ customers against bad actors and threats means we're continuing to push the envelope just like we' ve been doing for the past 20 years. If you 're ready to solve some of the toughest challenges in cybersecurity, we're ready to help you take command of your career. Join us. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, protected veteran status or any other status protected by applicable national, federal, state or local law.

Virginia
State of Georgia logo

Contract Analyst

State of Georgia

The State of Georgia, otherwise known as the "Peach State" or the "Empire State of the South," was the fourth American territory inducted into the United States

Assist Contract Managers with drafting, reviewing, and processing contracts, amendments, and renewals. Maintain contract files (digital and/or physical) to ensure documentation is complete and audit-ready....

Georgia