Skip to main content

Technical Risk Manager - Sr. Security Engineer I

Smartsheet
Hybrid - Bellevue, WA or Remote - USUpdated 1d ago
Base salary
$175k–$228k
Published base salary range
Location
Hybrid - Bellevue, WA or Remote - US
Remote eligibility
Employment
Full-time
Senior
Role family
Security
B2B SaaS
Apply on job-boards.greenhouse.io
Job actionsApply now
Job actionsApply now

About the job

About the Role

Smartsheet is seeking a Sr. Security Engineer I to own the Security Risk Management program end-to-end, including risk identification, analysis, and quantification; maintaining the enterprise risk register; and driving mitigation strategies. This role also oversees the Third-Party Risk Management (TPRM) function. The position reports to the Senior Director, GRC Engineering and can be based in Bellevue, WA or remotely from anywhere in the US where Smartsheet is a registered employer.

Responsibilities

  • Own and mature Smartsheet's Security Risk Management program: risk identification, analysis, scoring, and quantification (e.g., FAIR-based or similar) across internal systems, third parties, and emerging initiatives.
  • Maintain the enterprise risk register—ratings, ownership, mitigation status, and residual risk—and drive it toward a living, decision-useful tool.
  • Lead risk analysis and reviews for new initiatives, architecture changes, and significant findings, translating technical exposure into business-relevant risk statements for leadership.
  • Develop and drive risk mitigation strategy: work with risk owners across engineering, IT, and business teams to define remediation plans, track them to closure, and escalate what isn't moving.
  • Oversee Smartsheet's Third-Party Risk Management (TPRM) program: vendor risk tiering, security assessment/questionnaire review, ongoing monitoring, and issue tracking.
  • Build and present risk reporting and KPIs/KRIs to security and business leadership.
  • Partner with GRC, Field Security Engineering, and engineering leads to ensure risk findings from audits, pen tests, and questionnaires feed back into the same risk register and prioritization process.

Qualifications

  • 4+ years of experience in security risk management, enterprise risk, or GRC, including direct ownership of a risk register and risk assessment process.
  • Working familiarity with risk quantification approaches (FAIR, OCTAVE, or similar).
  • Enough technical fluency to understand cloud architecture, application security concepts, and common vulnerability/risk findings to discuss them credibly with engineering teams.
  • Experience running or closely supporting a Third-Party Risk Management program: vendor tiering, questionnaire review, and ongoing monitoring.
  • Excellent written and verbal communication skills.
  • Strong organizational skills and comfort managing many concurrent risk items and vendor relationships.
  • Professional certifications: CRISC, CISSP, CISM, or equivalent.
  • Experience with GRC or TPRM tooling (Vanta, Drata, OneTrust, Archer, ServiceNow GRC, or similar).
  • Background supporting SOC 2, ISO 27001, or FedRAMP programs.
  • Experience presenting risk posture to senior leadership or board-level audiences.
  • Legally eligible to work in the U.S. on an ongoing basis.

Compensation & Benefits

US Base Salary Pay Range: $175,000—$227,500 USD. This role is eligible for a market competitive incentive opportunity.

Benefits include: employer subsidized medical/vision and dental coverage, 401k Match (50% of your contribution up to the first 6% of your eligible pay), monthly stipend, Flexible Time Away Program plus Sick Time Off, life insurance, short-term and long-term disability plans, 12 paid holidays per year, up to 24 weeks of Parental Leave, personal paid Volunteer Day, professional growth opportunities including Udemy online courses, company funded perks including counseling membership and local retail discounts, and teleworking options from any registered location in the U.S. (role specific).

Skills & tags

What you can verify before applying

Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.