{"id":1430500,"url":"https://alion.io/job/smartsheet-technical-risk-manager-sr-security-engineer-i","title":"Technical Risk Manager - Sr. Security Engineer I","company":{"id":1678,"name":"Smartsheet","domain":"smartsheet.com","url":"https://alion.io/company/smartsheet","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":{"grade":"B","score":77,"open_postings":15,"ghost_share":0,"stale_share":0.933,"repost_share":0,"time_to_fill_p50_days":58,"computed_at":"2026-09-29T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["Bellevue, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":175000,"max":227500,"currency":"USD","period":"year","gross":null,"usd_annual":227500},"salary_estimate":null,"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AI Agents","optional":false},{"name":"FedRAMP","optional":false},{"name":"ISO 27001","optional":false},{"name":"ServiceNow","optional":false},{"name":"Smartsheet","optional":false},{"name":"SOC 2","optional":false}],"status":"live","first_seen_at":"2026-09-28T22:46:31Z","employer_posted_date":"2026-09-28","last_verified_at":"2026-09-30T03:26:05Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.\nSmartsheet needs a clear, defensible answer to \"how risky is this?\" for the risks that live inside our own environment and the risks that come in through every vendor and partner we rely on. We're looking for a Sr. Security Engineer I to own our Security Risk Management program end-to-end-running risk identification, analysis, and quantification; maintaining the enterprise risk register; and driving mitigation strategies that leadership can act on-while also overseeing our Third-Party Risk Management (TPRM) function. You don't need to be a hands-on security engineer to succeed here: you need to understand our technology and architecture well enough to have a real conversation with engineering teams about their risk exposure, and you need the judgment and communication skill to turn technical risk into business language that drives decisions. This role sits at the center of how Smartsheet decides what to fix first, what to accept, and what a vendor relationship is actually costing us in risk.\nThis role reports to the Senior Director, GRC Engineering and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.\nYou Will:\nOwn and mature Smartsheet's Security Risk Management program: risk identification, analysis, scoring, and quantification (e.g., FAIR-based or similar) across internal systems, third parties, and emerging initiatives.\nMaintain the enterprise risk register-ratings, ownership, mitigation status, and residual risk-and drive it toward a living, decision-useful tool rather than a static spreadsheet.\nLead risk analysis and reviews for new initiatives, architecture changes, and significant findings, translating technical exposure into business-relevant risk statements for leadership.\nDevelop and drive risk mitigation strategy: work with risk owners across engineering, IT, and business teams to define remediation plans, track them to closure, and escalate what isn't moving.\nOversee Smartsheet's Third-Party Risk Management (TPRM) program: vendor risk tiering, security assessment/questionnaire review, ongoing monitoring, and issue tracking for the vendor and partner ecosystem.\nBuild and present risk reporting and KPIs/KRIs to security and business leadership, giving them a clear view of top enterprise risks and where mitigation investment should go.\nPartner with GRC, Field Security Engineering, and engineering leads to make sure risk findings from audits, pen tests, and questionnaires feed back into the same risk register and prioritization process.\nYou Have:\n4+ years of experience in security risk management, enterprise risk, or GRC, including direct ownership of a risk register and risk assessment process.\nWorking familiarity with risk quantification approaches (FAIR, OCTAVE, or similar) and the judgment to apply them practically rather than academically.\nEnough technical fluency to understand cloud architecture, application security concepts, and common vulnerability/risk findings well enough to discuss them credibly with engineering teams-deep hands-on engineering experience is not required.\nExperience running or closely supporting a Third-Party Risk Management program: vendor tiering, questionnaire review, and ongoing monitoring.\nExcellent written and verbal communication skills; you can brief a risk finding to an engineering lead and to an executive and have both walk away with the right takeaway.\nStrong organizational skills and comfort managing many concurrent risk items and vendor relationships without losing track of status.\nProfessional certifications: CRISC, CISSP, CISM, or equivalent.\nExperience with GRC or TPRM tooling (Vanta, Drata, OneTrust, Archer, ServiceNow GRC, or similar).\nBackground supporting SOC 2, ISO 27001, or FedRAMP programs and an understanding of how risk management ties into those certifications.\nExperience presenting risk posture to senior leadership or board-level audiences.\nLegally eligible to work in the U.S. on an ongoing basis.\nCurrent US Perks & Benefits:\nEmployer subsidized medical/vision and dental coverage for full-time employees\n401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)\nMonthly stipend to support your work and productivity\nFlexible Time Away Program, plus Sick Time Off\nUS employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans\nUS employees receive 12 paid holidays per year\nUp to 24 weeks of Parental Leave\nPersonal paid Volunteer Day to support our community\nOpportunities for professional growth and development including access to Udemy online courses\nCompany Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account\nTeleworking options from any registered location in the U.S. (role specific)\nSmartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.\nUS Base Salary Pay Range\n$175,000—$227,500 USD\nGet to Know Us:\nAt Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths-because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.\nEqual Opportunity Employer:\nSmartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. \nIf there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.","description_format":"text","description_chars":7006,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["401k plan","Life insurance","Parental leave"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Project & Work Management Software"],"lifecycle":[{"event":"open","at":"2026-09-29T01:16:59Z"}],"liveness":{"score":63,"band":"ok","label":"Likely open","p_open":1,"p_active":0.632,"p_room":1,"age_days":0,"expected_fill_days":58,"reasons":["conf:0","stale_co","velocity","win:early"],"computed_at":"2026-09-29T05:45:00Z"},"pay":{"stated_usd_annual":227500,"is_top_pay":true},"html_url":"https://alion.io/job/smartsheet-technical-risk-manager-sr-security-engineer-i","json_url":"https://alion.io/job/smartsheet-technical-risk-manager-sr-security-engineer-i.json","meta":{"generated_at":"2026-09-30T05:18:00Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3679,"day_limit":5000,"remaining_today":1321,"minute_limit":60,"resets_at":"2026-10-01T00:00:00Z"}}}