Technical Risk Manager - Sr. Security Engineer I
Smartsheet · Bellevue, WA, USA
About this role
**About Smartsheet** Smartsheet empowers teams to manage work seamlessly and scale solutions smarter. In this role, you’ll help answer a critical question: *“How risky is this?”*—for risks inside Smartsheet’s environment and the risks coming through every vendor and partner. **Role: Technical Risk Manager – Sr. Security Engineer I** Own Smartsheet’s Security Risk Management program end-to-end, including risk identification, analysis, and quantification; maintain the enterprise risk register; and drive mitigation strategies leadership can act on. You’ll also oversee Third-Party Risk Management (TPRM). This role is highly cross-functional: you’ll translate technical risk into business language, partner with engineering and GRC teams, and help determine what to fix first, what to accept, and what vendor relationships truly cost in risk. **Location** Reports to the Senior Director, GRC Engineering. Based in Bellevue, WA office *or* remotely from anywhere in the US where Smartsheet is a registered employer. --- ## You Will - Own and mature Smartsheet’s Security Risk Management program: risk identification, analysis, scoring, and quantification (e.g., FAIR-based or similar) across internal systems, third parties, and emerging initiatives. - Maintain the enterprise risk register (ratings, ownership, mitigation status, residual risk) and evolve it into a living, decision-useful tool. - Lead risk analysis and reviews for new initiatives, architecture changes, and significant findings—translating technical exposure into business-relevant risk statements. - Develop and drive risk mitigation strategy: define remediation plans with risk owners, track to closure, and escalate items that aren’t moving. - Oversee Third-Party Risk Management (TPRM): vendor risk tiering, security assessment/questionnaire review, ongoing monitoring, and issue tracking. - Build and present risk reporting and KPIs/KRIs to security and business leadership. - Partner with GRC, Field Security Engineering, and engineering leads so audit/pen test/questionnaire findings feed back into the same risk register and prioritization process. ## You Have - 4+ years of experience in security risk management, enterprise risk, or GRC, including direct ownership of a risk register and risk assessment process. - Familiarity with risk quantification approaches (FAIR, OCTAVE, or similar) and the judgment to apply them practically. - Technical fluency to discuss cloud architecture, application security concepts, and common vulnerability/risk findings with engineering teams (hands-on engineering experience not required). - Experience running or closely supporting a Third-Party Risk Management program (vendor tiering, questionnaire review, ongoing monitoring). - Excellent written and verbal communication skills—able to brief engineering leads and executives with clear takeaways. - Strong organizational skills; comfortable managing many concurrent risk items and vendor relationships. - Professional certifications: CRISC, CISSP, CISM, or equivalent. - Experience with GRC/TPRM tooling (e.g., Vanta, Drata, OneTrust, Archer, ServiceNow GRC, or similar). - Background supporting SOC 2, ISO 27001, or FedRAMP programs and understanding how risk management ties to those certifications. - Experience presenting risk posture to senior leadership or board-level audiences. - Legally eligible to work in the U.S. on an ongoing basis. --- ## Current US Perks & Benefits - Employer-subsidized medical/vision/d
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.