Modern work management platform
Sr. Security Engineer 1 (Customer Trust)
Location
United States
Posted
8 days ago
Salary
$145K - $193K / year
No structured requirement data.
Job Description
For over 20 years, Smartsheet has helped people and teams achieve–well, anything. From seamless work management to smart, scalable solutions, we’ve always worked with flow. We’re building tools that empower teams to automate the manual, uncover insights, and scale smarter. But more than that, we’re creating space– space to think big, take action, and unlock the kind of work that truly matters. Because when challenge meets purpose, and passion turns into progress, that’s magic at work, and it’s what we show up for everyday.
The Sr. Security Engineer I is a critical technical role focused on deal acceleration, platform security evangelism, and the development of security features and capabilities that enhance our customer security and governance capabilities. You will support security and compliance during sales motions and bridge communication between complex customer security requirements and technical product engineering. You will work directly with customer security leaders (security engineers through CISOs) to communicate and clarify product security posture and controls results (such as pen test results), and will work with Smartsheet engineering to build security features that meet real-world customer requirements.. You will display product understanding through highly customized presentation demonstrations to customers and at conferences and events.
This role reports to the Manager, Customer Trust and Engineering and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer.
You Will:
- Serve as a trusted advisor to enterprise customers, CISOs, CIOs, and guiding them on Smartsheet security, compliance, and risk management.
- Evaluate customer infrastructure diagrams and data flows, and how Smartsheet can help with automation without compromising security.
- Present scanning results (NIST 800-53 gaps, vulnerability scans, DAST/pen test, IaC scans) to customers including walking through remediations. Help customers interpret scan results and develop deviation rationales for findings that can't be directly remediated.
- Bridge the gap between FedRAMP, NIST 800-53 control language and Smartsheet implementation. Explain what NIST 800-53 controls mean in terms of Terraform configs, Kubernetes manifests, CI/CD pipelines and cloud configuration of Smartsheet across AWS and GCP.
- Provide executive-level support during major customer security incidents and ensure lessons learned inform improvements. Understand and adhere to legal, regulatory and compliance requirements while working on sensitive security incidents.
- Represent our cloud and AI security strategy at industry events, conferences, and customer councils.
- Capture new business by responding to complex customer security questionnaires and technical inquiries using automation and AI tooling, ensuring security-related impediments to closing deals are removed efficiently.
- Work alongside product engineering and Corporate IT to define technical specs for security features and protective measures that meet evolving customer requirements.
- Translate customer security concerns and regulatory needs into clear technical problem definitions for internal teams.
- Create and distribute technical assets (white papers, solution code, blog posts, and video demonstrations).
You Have:
- Strong analytical and problem solving skills
- Ability to explain CI/CD and SDLC best practices and how Smartsheet is deployed.
- Hands-on experience with AAA implementations (SSO, IdP, MFA enforcement, session management, etc.).
- Hands-on experience with enterprise system and application integrations, and with security tooling such as EDR, VPNs, Vulnerability scanners, CSPM, and SIEM/CASB.
- 5+ years of total experience in cyber security, specifically within security engineering, security architecture, or sales engineering.
- Familiarity with NIST 800-53, ISO, SOC 2, FedRAMP, GDPR, and HIPAA.
- Excellent written and verbal communication skills, with the ability to influence stakeholders at all levels and create external-facing technical content.
- Bachelor’s degree in a related field or equivalent experience, and/or professional certifications such as CISSP, CCSP, GCSA, CISA, or CRISC.
- Experience conducting security reviews and threat modeling on infrastructure, software, and services.
Current US Perks & Benefits:
- Medical/vision and dental coverage options for full-time employees
- 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay)
- Monthly stipend to support your work and productivity
- Flexible Time Away Program, plus Sick Time Off
- US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans
- US employees receive 12 paid holidays per year
- Up to 24 weeks of Parental Leave
- Personal paid Volunteer Day to support our community
- Opportunities for professional growth and development including access to Udemy online courses
- Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account
- Teleworking options from any registered location in the U.S. (role specific)
Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity.
Get to Know Us:
At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together.
Equal Opportunity Employer:
Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, and India. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information.
If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know.
#LI-Remote
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Chief Information Security Officer (CISO)
Nymbus, Inc.Nymbus empowers banks and global financial institutions to modernize their capabilities and drive measurable value in today’s digital marketplace. We believe innovation should bring excitement and confidence — not complexity and uncertainty. At Nymbus, we are redefining digital banking and creating meaningful impact for our partners and their customers. Our success starts with our people. If you’re looking to grow your career in a fast-moving fintech environment where operational excellence and innovation intersect, we invite you to explore this opportunity. Nymbus is a remote-first organization. This position is fully remote; however, occasional travel may be required for client meetings or designated team gatherings.
The CISO will own and continuously mature the enterprise Information Security Program, aligning controls with major regulatory frameworks like NIST, FFIEC, and PCI DSS. This role involves translating strategy into measurable execution plans, driving remediation of findings, and leading the security team across detection engineering, vulnerability management, and security architecture functions.
Director, Information Security
Human Rights WatchHuman Rights Watch is one of the world’s leading independent organizations dedicated to defending and protecting human rights. By focusing international attention where human rights are violated, we give voice to the oppressed and hold oppressors accountable for their crimes. Our rigorous, objective investigations and strategic, targeted advocacy build intense pressure for action and raise the cost of human rights abuse. For 30 years, Human Rights Watch has worked tenaciously to lay the legal and moral groundwork for deep-rooted change and has fought to bring greater justice and security to people around the world.
FULL-TIME JOB VACANCY Director, Information Security Information Security Division Multiple Locations Considered Application Deadline: March 29th Human Rights Watch (“HRW”) is seeking a highly skilled and forward-thinking Director of Information Security to lead our efforts in en...
The Senior Risk Mitigation and Security Manager plays a critical role in protecting the credit union through strong risk management, vendor oversight, and business continuity programs. This position ensures appropriate bond and insurance coverage and supports robust information s...
Senior Incident Response Engineer
RemitlyLexisNexis® Risk Solutions provides customers with solutions and decision tools that combine public and industry specific content with advanced technology and analytics to assist them in evaluating and predicting risk and enhancing operational efficiency. We use the power of data and advanced analytics to help our customers make better, timelier decisions. By bringing clarity to information, we ultimately help make communities safer, insurance rates more accurate, commerce more transparent, business decisions easier and processes more efficient. You can learn more about LexisNexis Risk at the link below: LexisNexis Risk Solutions
The role involves serving as the senior technical member of the incident response team, focusing on improving security resilience and readiness through the development and execution of response plans and forensic investigations across physical and cloud environments. Key duties include leading full-life-cycle incident response, developing comprehensive reports, and proactively collecting intelligence to detect high-confidence threats to the enterprise.