Senior Security Engineer I - Customer Trust
Job description
Senior Security Engineer I - Customer Trust at Smartsheet.
About the role
In this role, you will play a crucial part in fostering customer confidence in Smartsheet's security protocols. Your primary responsibility will be to manage and respond to security inquiries from customers based in the United States. By addressing their concerns and facilitating their use of our platform, you will help enhance customer trust and satisfaction.
Key facts
What you'll do
- Oversee the intake process for security questionnaires and requests from U.S. customers, ensuring they are prioritized and addressed efficiently.
- Provide clear, accurate, and technically sound responses to customer inquiries related to security, showcasing your understanding of Smartsheet's security practices.
- Manage the workflow of incoming security assessments, ensuring that all requests are completed promptly and that customers are kept updated on their status.
- Build and nurture strong relationships with customer security teams, serving as a reliable advisor on security matters.
- Collaborate closely with sales and customer success teams to address any security-related questions that could affect the progression of deals.
- Identify complex security inquiries and escalate them to specialized internal teams for thorough resolution.
- Respond to customer inquiries regarding compliance with various standards, including HIPAA, NIST, CCPA, and PCI DSS, ensuring that all responses are accurate and informative.
- Continuously seek out and implement enhancements to streamline the process of completing security questionnaires, thereby improving the overall customer experience.
Requirements
- A minimum of 5 years of experience in roles related to customer trust, vendor risk management, security assessments, or customer-facing security engineering, particularly within SaaS or cloud environments.
- A degree in Computer Science, Computer Engineering, Cybersecurity, or a related discipline, or equivalent practical experience in the field.
- Proven experience in completing customer security questionnaires, conducting vendor assessments, and responding to security information requests effectively.
- Familiarity with Governance, Risk, and Compliance (GRC) frameworks and standards, including SOC 2, ISO 27001, and NIST.
- A solid understanding of technical security aspects related to cloud architectures (AWS, GCP, Azure), application security, access controls, encryption, and data protection.
- Exceptional written and verbal communication skills, with the ability to convey complex technical security concepts to a variety of audiences.
- Proficiency in managing multiple requests simultaneously, effectively prioritizing tasks, and maintaining organized workflows.
- A collaborative mindset, capable of working effectively across various internal teams to achieve common goals.
- Authorization to work in the United States is required.
Nice to have
- Professional security certifications such as CISSP, CCSK, CISM, or CompTIA Security+ are advantageous.
- Experience with vendor risk and questionnaire management platforms like Targhee, OneTrust, or SAFE would be beneficial.
- A background in SaaS security operations or experience in Security Operations Center (SOC) environments is a plus.
- Knowledge of AI governance, emerging AI risks, and insights into how customers assess AI security in SaaS products would be valuable.
Skills & tools
- Proficiency in GRC frameworks such as SOC 2, ISO 27001, and NIST
- Knowledge of cloud architecture including AWS, GCP, and Azure
- Expertise in application security, access controls, and encryption techniques
- Familiarity with logging and incident response protocols
- Understanding of data protection regulations such as HIPAA, CCPA, and PCI DSS
- Experience with questionnaire and vendor risk management platforms like Targhee, OneTrust, and SAFE
Practical notes
The salary range for this position in the United States is between $145,000 and $210,000 USD.
Benefits provided include employer-subsidized medical, vision, and dental insurance, a 401k matching program, monthly stipends, flexible time off, life insurance, disability coverage, paid holidays, parental leave, volunteer days, access to professional development opportunities, and various company-funded perks.
This role offers the flexibility of telecommuting from any registered location within the United States.