> Markdown version of [/jobs/ext/2678030-senior-technical-program-manager-product-security](https://www.wearedevelopers.com/jobs/ext/2678030-senior-technical-program-manager-product-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Technical Program Manager, Product Security - **Company:** Docusign, Inc. - **Location:** Seattle, WA, United States (Remote available) - **Experience:** Expert - **Salary:** $146,400.0 - $206,775.0 - **Contract:** Permanent contract - **Skills:** Agile Methodology, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Open Web Application Security, Systems Development Life Cycle, Secure Coding, Software Vulnerability Management, Google Cloud, Software Security, Information Technology, DocuSign, Devsecops, Security Orchestration, Automation & Response - **Published:** September 1, 2026 - **Apply:** https://jobs.localjobnetwork.com/apply/add/88200339/1 ## About the Role * 8+ years related experience with a Bachelor's degree or 6 years related experience with a Master's degree * Bachelors or Masters degree in Technology or Computer Science or Cybersecurity * Experience with product security practices (secure SDLC, threat modeling, vulnerability management, cloud/application security) * Experience with security frameworks and standards (e.g., OWASP, NIST, ISO 27001) * Experience leading large, cross-functional security or engineering programs * Experience with program planning, prioritization, and driving accountability across teams * Experience with threat modeling, risk management, and vulnerability management Preferred * Hands-on experience enabling shift-left security practices in product development * Proven ability to build and scale Security Champions or developer enablement programs * Familiarity with regulatory and compliance frameworks (SOC 2, ISO 27001, GDPR FedRAMP, etc.) * Experience working with product and engineering teams in an Agile environment * Familiarity with DevSecOps practices and security automation * Experience with security automation tools integrated into CI/CD pipelines * Track record of leading cultural change to foster security-first engineering practices * Relevant certifications (e.g., CISSP, CISM) * Excellent executive communication and stakeholder management skills * Experience with cloud security (AWS, Azure, GCP) ## Description As a Senior TPM in Product Security, you will shape and execute the long-term strategy for building security into our products. You'll spearhead the shift-left movement, ensuring secure development practices are embedded early and consistently across all teams. You will lead organizational change by building scalable programs, driving adoption of secure-by-design principles, and aligning security priorities with business goals. In this role, you'll act as a trusted partner to executives, influencing roadmaps and investment decisions, while enabling engineering teams to move fast without compromising security. This position is an individual contributor role reporting to the Sr. Manager, Security Product Management. Responsibility * Own and scale product security initiatives that span across engineering organizations, balancing risk reduction with innovation * Drive adoption of secure coding, automated security tooling, and early threat modeling across the SDLC * Partner with senior engineering and product leaders to embed security into decision-making, roadmaps, and design principles * Translate technical risk into business impact, providing clear updates, trade-off discussions, and recommendations to executives * Lead organizational change by fostering a developer-first security culture that scales across teams and geographies * Ensure products meet internal security standards, industry frameworks, and regulatory requirements * Define measurable success criteria (e.g., secure coding adoption rates, vulnerability SLAs) and report outcomes to leadership * Ensure coordinated response and remediation for vulnerabilities, leveraging learnings to continuously strengthen processes * Improve security processes, tools, and automation to scale security across the organization Job Designation Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation) Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law. What you bring ## Related Videos - [Organizational Change Through The Power Of Why - DevSecOps Enablement](https://www.wearedevelopers.com/videos/478-organizational-change-through-the-power-of-why-devsecops-enablement) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 151: SEO in an AI world, security fixes and Doomed PDFs](https://www.wearedevelopers.com/magazine/535-dev-digest-151-seo-in-an-ai-world-security-fixes-and-doomed-pdfs) - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Why Attend a Developer Event in 2026?](https://www.wearedevelopers.com/magazine/688-why-attend-a-developer-event-in-2026) - [Dev Digest 188: CfP time, the risks of NPM and IKEA algorithms](https://www.wearedevelopers.com/magazine/635-dev-digest-188-cfp-time-the-risks-of-npm-and-ikea-algorithms) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)