Lead the Public Sector’s Assessment and Authorization program by overseeing ISSO security functions and artifacts to guarantee compliance and maintain operational continuity. In this capacity, you will develop and deliver comprehensive training for team members, standardize the creation of security artifacts, and establish rigorous security standards to maintain audit readiness and operational excellence. The Information System Security Security Manager is a technical individual contributor role. In this capacity, you will act as the primary subject matter expert for the Assessment and Authorization (A&A) process across Docusign’s Public Sector Products and Environments. You will report to the Sr. Director of Public Sector and Insider Risk, managing projects, customer deliverables, and initiatives that help ensure the success of all 3rd Party assessments for the Public Sector. Your primary responsibility will be to own and perform the final review by leading the comprehensive development of Authority to Operate (ATO) packages and System Security Plans (SSP) across GovRAMP, FedRAMP High, and DoD Impact Level (IL) environments. This position requires a leader capable of influencing technical infrastructure, product development, and security work streams to develop and implement effective compliance solutions and rigorous risk assessments. You will serve as a strategic liaison, collaborating across marketing, sales, legal, and customer-facing teams to ensure all initiatives align with relevant compliance standards. Beyond oversight, you will proactively identify potential roadblocks in the FedRAMP Assessment and Authorization process, providing technical guidance to engineering teams to ensure security controls are integrated into the production environments and aligned with current policies and procedures. By fostering deep partnerships with cross-functional stakeholders, you will help translate high-level compliance requirements into actionable technical specifications, ensuring that Docusign’s Public Sector offerings remain resilient, secure, and fully authorized to meet the evolving needs of government agencies. This position is an individual contributor role reporting to the Sr. Director, Public Sector and Insider Risk. Responsibility Own and drive the full lifecycle from system categorization to receiving formal ATO for Federal and DoD information systems Oversee and provide guidance on the maintenance of Assessment and Authorization artifacts, including the System Security Plan (SSP), Security Assessment Plan (SAP), and all Appendix Plans Ensure all ATO package deliverables are audit-ready and align with NIST FedRAMP Special Publications, CNSSI 1253 and the DoD Cloud SRG Lead mature security reviews across core products, microservices, and native cloud environments with high-fidelity artifacts and evidence Maintain and help mature the risk management process using NIST 800-30/37 to ensure compliance and proactive risk reduction Improve risk visibility by integrating data from multiple manual/automated assessments and internal audits Develop playbooks and procedures to support technical teams in executing compliance initiatives Present risk in context-regulatory, business, or cybersecurity to ensure alignment with Executive Leadership guidance Maintain and deliver timely Continuous Monitoring (ConMon) and remediation strategies Collaborate with security teams to operationalize new capabilities that support risk reduction and remediation actions Work with Prod/Dev, Sec Architecture, and Infrastructure teams to mitigate systemic vulnerabilities and operationalize known security gaps Drive the remediation of vulnerabilities, ensuring the Plan of Action and Milestones (POA&M) is accurate and reported monthly Implement mandatory actions from CISA Emergency Directives and DoD IAVM alerts Ensure timely internal security reviews of new products and features prior to deployment Partner with product and infrastructure teams to align workstreams and assess security solutions for US public sector requirements Serve as the lead for responding to complex customer security questionnaires and providing guidance for FedRAMP, StateRAMP, and DoD SRG milestones Join high-level briefings to explain security posture and compliance inheritance to prospective Government clients