Technical Risk Manager - Sr. Security Engineer I
Smartsheet- Base salary
- $175k–$228k Published base salary range
- Location
- Hybrid - Bellevue, WA or Remote - US Remote eligibility
- Employment
- Full-time Senior
About the job
About the Role
Smartsheet is seeking a Sr. Security Engineer I to own the Security Risk Management program end-to-end, including risk identification, analysis, and quantification; maintaining the enterprise risk register; and driving mitigation strategies. This role also oversees the Third-Party Risk Management (TPRM) function. The position reports to the Senior Director, GRC Engineering and can be based in Bellevue, WA or remotely from anywhere in the US where Smartsheet is a registered employer.
Responsibilities
- Own and mature Smartsheet's Security Risk Management program: risk identification, analysis, scoring, and quantification (e.g., FAIR-based or similar) across internal systems, third parties, and emerging initiatives.
- Maintain the enterprise risk register—ratings, ownership, mitigation status, and residual risk—and drive it toward a living, decision-useful tool.
- Lead risk analysis and reviews for new initiatives, architecture changes, and significant findings, translating technical exposure into business-relevant risk statements for leadership.
- Develop and drive risk mitigation strategy: work with risk owners across engineering, IT, and business teams to define remediation plans, track them to closure, and escalate what isn't moving.
- Oversee Smartsheet's Third-Party Risk Management (TPRM) program: vendor risk tiering, security assessment/questionnaire review, ongoing monitoring, and issue tracking.
- Build and present risk reporting and KPIs/KRIs to security and business leadership.
- Partner with GRC, Field Security Engineering, and engineering leads to ensure risk findings from audits, pen tests, and questionnaires feed back into the same risk register and prioritization process.
Qualifications
- 4+ years of experience in security risk management, enterprise risk, or GRC, including direct ownership of a risk register and risk assessment process.
- Working familiarity with risk quantification approaches (FAIR, OCTAVE, or similar).
- Enough technical fluency to understand cloud architecture, application security concepts, and common vulnerability/risk findings to discuss them credibly with engineering teams.
- Experience running or closely supporting a Third-Party Risk Management program: vendor tiering, questionnaire review, and ongoing monitoring.
- Excellent written and verbal communication skills.
- Strong organizational skills and comfort managing many concurrent risk items and vendor relationships.
- Professional certifications: CRISC, CISSP, CISM, or equivalent.
- Experience with GRC or TPRM tooling (Vanta, Drata, OneTrust, Archer, ServiceNow GRC, or similar).
- Background supporting SOC 2, ISO 27001, or FedRAMP programs.
- Experience presenting risk posture to senior leadership or board-level audiences.
- Legally eligible to work in the U.S. on an ongoing basis.
Compensation & Benefits
US Base Salary Pay Range: $175,000—$227,500 USD. This role is eligible for a market competitive incentive opportunity.
Benefits include: employer subsidized medical/vision and dental coverage, 401k Match (50% of your contribution up to the first 6% of your eligible pay), monthly stipend, Flexible Time Away Program plus Sick Time Off, life insurance, short-term and long-term disability plans, 12 paid holidays per year, up to 24 weeks of Parental Leave, personal paid Volunteer Day, professional growth opportunities including Udemy online courses, company funded perks including counseling membership and local retail discounts, and teleworking options from any registered location in the U.S. (role specific).
Skills & tags
Compare the essentials before you leave: pay, remote scope, employment type, source, and the employer apply destination.