Level

Smartsheet

Technical Risk Manager - Sr. Security Engineer I

AI in this role

Owns the enterprise security risk management and third-party risk management programs end-to-end.

ai-agentssecurity-risk-managementthird-party-riskvendor-riskrisk-quantification

For over 20 years, Smartsheet has empowered teams to manage work seamlessly and scale solutions smarter. Now, in our most ambitious chapter yet, we are uniting human teams with AI agents. By orchestrating the work agents do best, automating manual tasks and uncovering insights at scale, we create the space for people to focus on what truly matters: judgment, creativity, and big thinking. That is magic at work, and it’s what we show up for every day.

Smartsheet needs a clear, defensible answer to "how risky is this?" for the risks that live inside our own environment and the risks that come in through every vendor and partner we rely on. We're looking for a Sr. Security Engineer I to own our Security Risk Management program end-to-end—running risk identification, analysis, and quantification; maintaining the enterprise risk register; and driving mitigation strategies that leadership can act on—while also overseeing our Third-Party Risk Management (TPRM) function. You don't need to be a hands-on security engineer to succeed here: you need to understand our technology and architecture well enough to have a real conversation with engineering teams about their risk exposure, and you need the judgment and communication skill to turn technical risk into business language that drives decisions. This role sits at the center of how Smartsheet decides what to fix first, what to accept, and what a vendor relationship is actually costing us in risk.

This role reports to the Senior Director, GRC Engineering and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.

You Will:

  • Own and mature Smartsheet's Security Risk Management program: risk identification, analysis, scoring, and quantification (e.g., FAIR-based or similar) across internal systems, third parties, and emerging initiatives.
  • Maintain the enterprise risk register—ratings, ownership, mitigation status, and residual risk—and drive it toward a living, decision-useful tool rather than a static spreadsheet.
  • Lead risk analysis and reviews for new initiatives, architecture changes, and significant findings, translating technical exposure into business-relevant risk statements for leadership.
  • Develop and drive risk mitigation strategy: work with risk owners across engineering, IT, and business teams to define remediation plans, track them to closure, and escalate what isn't moving.
  • Oversee Smartsheet's Third-Party Risk Management (TPRM) program: vendor risk tiering, security assessment/questionnaire review, ongoing monitoring, and issue tracking for the vendor and partner ecosystem.
  • Build and present risk reporting and KPIs/KRIs to security and business leadership, giving them a clear view of top enterprise risks and where mitigation investment should go.
  • Partner with GRC, Field Security Engineering, and engineering leads to make sure risk findings from audits, pen tests, and questionnaires feed back into the same risk register and prioritization process.

You Have:

  • 4+ years of experience in security risk management, enterprise risk, or GRC, including direct ownership of a risk register and risk assessment process.
  • Working familiarity with risk quantification approaches (FAIR, OCTAVE, or similar) and the judgment to apply them practically rather than academically.
  • Enough technical fluency to understand cloud architecture, application security concepts, and common vulnerability/risk findings well enough to discuss them credibly with engineering teams—deep hands-on engineering experience is not required.
  • Experience running or closely supporting a Third-Party Risk Management program: vendor tiering, questionnaire review, and ongoing monitoring.
  • Excellent written and verbal communication skills; you can brief a risk finding to an engineering lead and to an executive and have both walk away with the right takeaway.
  • Strong organizational skills and comfort managing many concurrent risk items and vendor relationships without losing track of status.
  • Professional certifications: CRISC, CISSP, CISM, or equivalent.
  • Experience with GRC or TPRM tooling (Vanta, Drata, OneTrust, Archer, ServiceNow GRC, or similar).
  • Background supporting SOC 2, ISO 27001, or FedRAMP programs and an understanding of how risk management ties into those certifications.
  • Experience presenting risk posture to senior leadership or board-level audiences.
  • Legally eligible to work in the U.S. on an ongoing basis.

Current US Perks & Benefits:

  • Employer subsidized medical/vision and dental coverage for full-time employees
  • 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
  • Monthly stipend to support your work and productivity
  • Flexible Time Away Program, plus Sick Time Off
  • US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
  • US employees receive 12 paid holidays per year
  • Up to 24 weeks of Parental Leave
  • Personal paid Volunteer Day to support our community
  • Opportunities for professional growth and development including access to Udemy online courses
  • Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
  • Teleworking options from any registered location in the U.S. (role specific)

Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.

US Base Salary Pay Range$175,000—$227,500 USD

 

Get to Know Us:

At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.

Equal Opportunity Employer:

Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, India, and Singapore. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. 

If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.

 

#LI-Remote

How we rate this

Technical Risk Manager - Sr. Security Engineer I at Smartsheet rates 0 out of 100 for how much of the daily work is AI. That makes it Little AI (AI Level 1 of 4). The level is about AI in the job, not seniority.

Classification

Little AI. AI is not part of the work.

  1. ●●●● Builds AI80 to 100
  2. ●●●○ Works on AI60 to 79
  3. ●●○○ Uses AI40 to 59
  4. ●○○○ Little AI0 to 39

Levels come from how often the tools, models and workflows of the role are named in the posting itself. Open the description and count.

Prepare for this job

A free preview built only from this posting: what it asks for, what you could be asked in an interview, and how to adjust your resume.

Skills and AI tools this role asks for

AI AgentsSecurity Risk ManagementThird Party RiskVendor RiskRisk Quantification

Questions you could be asked

  1. How do you decide when an AI agent can act on its own versus asking for approval first?
  2. Tell me about a project where security risk management was part of your work. What did you do?
  3. Tell me about a project where third party risk was part of your work. What did you do?
  4. Tell me about a project where vendor risk was part of your work. What did you do?
  5. Tell me about a project where risk quantification was part of your work. What did you do?

Adapt your resume

  • List these exact terms on your resume: AI Agents, Security Risk Management, Third Party Risk, Vendor Risk, and Risk Quantification. An applicant tracking system matches the wording, not the idea.
  • Attach one line of real, concrete experience to at least one of them — a tool named with nothing behind it rarely survives a human read.

Want your resume actually rewritten for this job?

The free preview above is everything we have today. A full resume rewrite is not live yet and has no price set. Join the waitlist and we will email you if we open it.

Get new remote AI jobs by email

One email a week with the new remote AI jobs, each rated for how much AI is in the work. No recruiter spam, unsubscribe in one click.

Free. One email a week. Unsubscribe in one click.

Similar roles

Security roles that involve little AI, at other companies.

What kind of AI work fits you?

Answer 12 practical questions in about three minutes. Get a simple profile, the work it points to, and live roles to explore next.

Find my next step

More jobs at Smartsheet

Related searches

Same AI level