Technical Risk Manager - Sr. Security Engineer I
Smartsheet · 14 hours ago
For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.
Smartsheet needs a clear, defensible answer to "how risky is this?" for the risks that live inside our own environment and the risks that come in through every vendor and partner we rely on. We're looking for a Sr. Security Engineer I to own our Security Risk Management program end-to-end—running risk identification, analysis, and quantification; maintaining the enterprise risk register; and driving mitigation strategies that leadership can act on—while also overseeing our Third-Party Risk Management (TPRM) function. You don't need to be a hands-on security engineer to succeed here: you need to understand our technology and architecture well enough to have a real conversation with engineering teams about their risk exposure, and you need the judgment and communication skill to turn technical risk into business language that drives decisions. This role sits at the center of how Smartsheet decides what to fix first, what to accept, and what a vendor relationship is actually costing us in risk.
This role reports to the Senior Director, GRC Engineering and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.
You Will:
- Own and mature Smartsheet's Security Risk Management program: risk identification, analysis, scoring, and quantification (e.g., FAIR-based or similar) across internal systems, third parties, and emerging initiatives.
- Maintain the enterprise risk register—ratings, ownership, mitigation status, and residual risk—and drive it toward a living, decision-useful tool rather than a static spreadsheet.
- Lead risk analysis and reviews for new initiatives, architecture changes, and significant findings, translating technical exposure into business-relevant risk statements for leadership.
- Develop and drive risk mitigation strategy: work with risk owners across engineering, IT, and business teams to define remediation plans, track them to closure, and escalate what isn't moving.
- Oversee Smartsheet's Third-Party Risk Management (TPRM) program: vendor risk tiering, security assessment/questionnaire review, ongoing monitoring, and issue tracking for the vendor and partner ecosystem.
- Build and present risk reporting and KPIs/KRIs to security and business leadership, giving them a clear view of top enterprise risks and where mitigation investment should go.
- Partner with GRC, Field Security Engineering, and engineering leads to make sure risk findings from audits, pen tests, and questionnaires feed back into the same risk register and prioritization process.
You Have:
- 4+ years of experience in security risk management, enterprise risk, or GRC, including direct ownership of a risk register and risk assessment process.
- Working familiarity with risk quantification approaches (FAIR, OCTAVE, or similar) and the judgment to apply them practically rather than academically.
- Enough technical fluency to understand cloud architecture, application security concepts, and common vulnerability/risk findings well enough to discuss them credibly with engineering teams—deep hands-on engineering experience is not required.
- Experience running or closely supporting a Third-Party Risk Management program: vendor tiering, questionnaire review, and ongoing monitoring.
- Excellent written and verbal communication skills; you can brief a risk finding to an engineering lead and to an executive and have both walk away with the right takeaway.
- Strong organizational skills and comfort managing many concurrent risk items and vendor relationships without losing track of status.
- Professional certifications: CRISC, CISSP, CISM, or equivalent.
- Experience with GRC or TPRM tooling (Vanta, Drata, OneTrust, Archer, ServiceNow GRC, or similar).
- Background supporting SOC 2, ISO 27001, or FedRAMP programs and an understanding of how risk management ties into those certifications.
- Experience presenting risk posture to senior leadership or board-level audiences.
- Legally eligible to work in the U.S. on an ongoing basis.
Current US Perks & Benefits:
- Employer subsidized medical/vision and dental coverage for full-time employees
- 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
- Monthly stipend to support your work and productivity
- Flexible Time Away Program, plus Sick Time Off
- US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
- US employees receive 12 paid holidays per year
- Up to 24 weeks of Parental Leave
- Personal paid Volunteer Day to support our community
- Opportunities for professional growth and development including access to Udemy online courses
- Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
- Teleworking options from any registered location in the U.S. (role specific)
Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.
US Base Salary Pay Range
$175,000—$227,500 USD
Get to Know Us:
At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.
Equal Opportunity Employer:
Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.
If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.
#LI-Remote