Senior PSIRT Incident Responder

DocuSign

DocuSign

Dublin, Ireland

Posted on May 29, 2026

Senior PSIRT Incident Responder

ID 2026-29423
Location
IE-Dublin
Category
Security
Position Type
Regular

Company Overview

Docusign brings agreements to life. Over 1.5 million customers and more than a billion people in over 180 countries use Docusign solutions to accelerate the process of doing business and simplify people’s lives. With intelligent agreement management, Docusign unleashes business-critical data that is trapped inside of documents. Until now, these were disconnected from business systems of record, costing businesses time, money, and opportunity. Using Docusign’s Intelligent Agreement Management platform, companies can create, commit, and manage agreements with solutions created by the #1 company in e-signature and contract lifecycle management (CLM).

What you'll do

As a Senior PSIRT Responder, you will play a foundational role in scaling Docusign’s newly formed Product Security Incident Response function. Partnering closely with our PSIRT Lead, you will serve as the second-most senior technical authority on the team, driving the coordination, investigation, and remediation of security vulnerabilities across our product and platform infrastructure. This is a high-autonomy, high-impact role where you will deeply analyze application and cloud-based threats, mentor growing team members, and help shape the operational maturity of our vulnerability disclosure and bug bounty channels.


While leadership handles the majority of external relations, you will serve as a technical subject matter expert who may occasionally interface directly with key customers or partners to provide technical clarity on high-priority inquiries.


This position is an individual contributor role reporting to the Director of Offensive Security.


Responsibility

  • Co-lead the end-to-end lifecycle of product security incidents alongside the PSIRT Lead, ensuring robust validation, containment, and root-cause remediation
  • Investigate and analyze product and cloud-infrastructure security issues in collaboration with engineering, product, legal, and customer support teams using industry frameworks (OWASP, CVSS, MITRE ATT&CK, CWE)
  • Ensure timely, compliant, and effective incident management, moving issues efficiently from initial triage through remediation and closure
  • Manage and optimize Docusign's public Bug Bounty and Vulnerability Disclosure Programs (VDP), evaluating incoming submissions for true security risk
  • Translate complex security findings into clear, actionable technical advice for internal engineering stakeholders
  • Support security leadership by occasionally addressing deep technical questions from key customers or external security researchers
  • Collaborate with the PSIRT Lead to design, mature, and scale internal IR playbooks, automation tooling, and metrics for the expanding team
  • Participate in a predictable, shared team on-call rotation (Note: Our page volume is historically low)

Job Designation

Hybrid: Employee divides their time between in-office and remote work. Access to an office location is required. (Frequency: Minimum 2 days per week; may vary by team but will be weekly in-office expectation)

Positions at Docusign are assigned a job designation of either In Office, Hybrid or Remote and are specific to the role/job. Preferred job designations are not guaranteed when changing positions within Docusign. Docusign reserves the right to change a position's job designation depending on business needs and as permitted by local law.

What you bring

Basic

  • 8+ years of hands-on experience executing the full incident response lifecycle (NIST/SANS) across hybrid and cloud-native environments (e.g., AWS, Azure, GCP), encompassing vulnerability triage, cloud-attack analysis, containment, remediation, and driving post-incident Root Cause Analysis (RCA)
  • Hands-on incident response experience working directly within major cloud environments (AWS, Azure, or GCP)
  • Deep technical mastery of Application and Cloud-based attacks, with a strong understanding of frameworks like the OWASP Top 10 and OWASP Cloud Top 10
  • Solid understanding of cybersecurity principles, incident response lifecycles, and security best practices
  • Solid understanding of CVSS (Common Vulnerability Scoring System) for rating vulnerabilities, MITRE ATT&CK for adversary tactics and techniques, and CWE (Common Weakness Enumeration) for identifying and categorizing software weaknesses
  • Demonstrated experience managing or significantly contributing to Vulnerability Disclosure Programs (VDP) or Bug Bounty programs
  • Strong analytical and problem-solving skills, with a keen eye for detail
  • Excellent written and verbal communication skills, with the ability to explain technical concepts clearly
  • Ability to work effectively as part of a team and independently under pressure


Preferred

  • Deep architectural understanding within major cloud environments (AWS, Azure, or GCP)
  • Advanced industry certifications demonstrating senior expertise, such as GCIH, GCFA, GIAC, CISSP, CCSP, CCSK, or equivalent
  • Familiarity or exposure to emerging AI security concepts and frameworks (e.g., OWASP Top 10 for LLMs)
  • Familiarity with query languages (e.g., KQL, SQL) for log analysis and security telemetry investigation
  • Bachelor's degree in Computer Science, Information Security, or a related field

Life at DocuSign

Working here

Docusign is committed to building trust and making the world more agreeable for our employees, customers and the communities in which we live and work. You can count on us to listen, be honest, and try our best to do what’s right, every day. At Docusign, everything is equal.

We each have a responsibility to ensure every team member has an equal opportunity to succeed, to be heard, to exchange ideas openly, to build lasting relationships, and to do the work of their life. Best of all, you will be able to feel deep pride in the work you do, because your contribution helps us make the world better than we found it. And for that, you’ll be loved by us, our customers, and the world in which we live.

Accommodation

Docusign is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application procedures. If you need such an accommodation, or a religious accommodation, during the application process, please contact us at accommodations@docusign.com.

If you experience any issues, concerns, or technical difficulties during the application process please get in touch with our Talent organization at taops@docusign.com for assistance.

Applicant and Candidate Privacy Notice

Options

Sorry the Share function is not working properly at this moment. Please refresh the page and try again later.
Share on your newsfeed

Need help finding the right job?

We can recommend jobs specifically for you! Click here to get started.