Startups

Technical Risk Manager - Sr. Security Engineer I

Smartsheet · Bellevue, WA, USA · On-site

← All jobs
About Smartsheet

Backed by Insight.

About the role

Smartsheet needs a clear, defensible answer to "how risky is this?" for the risks that live inside our own environment and the risks that come in through every vendor and partner we rely on. We're looking for a Sr.

What they're looking for

  • 4+ years of experience in security risk management, enterprise risk, or GRC, including direct ownership of a risk register and risk assessment process
  • Working familiarity with risk quantification approaches (FAIR, OCTAVE, or similar) and the judgment to apply them practically rather than academically
  • Experience running or closely supporting a Third-Party Risk Management program: vendor tiering, questionnaire review, and ongoing monitoring
  • Excellent written and verbal communication skills, you can brief a risk finding to an engineering lead and to an executive and have both walk away with the right takeaway
  • Strong organizational skills and comfort managing many concurrent risk items and vendor relationships without losing track of status
  • Professional certifications: CRISC, CISSP, CISM, or equivalent
More about this role

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.

Smartsheet needs a clear, defensible answer to "how risky is this?" for the risks that live inside our own environment and the risks that come in through every vendor and partner we rely on. We're looking for a Sr. Security Engineer I to own our Security Risk Management program end-to-end—running risk identification, analysis, and quantification; maintaining the enterprise risk register; and driving mitigation strategies that leadership can act on—while also overseeing our Third-Party Risk Management (TPRM) function. You don't need to be a hands-on security engineer to succeed here: you need to understand our technology and architecture well enough to have a real conversation with engineering teams about their risk exposure, and you...

Read the full posting on Smartsheet's site ↗

Security

Build your edge while you search

Free tools for founders and investors, plus VC Unfiltered, our take on startups, venture and the people who build them.