Manager, Security Incident Response
Quick Summary
• Build, lead, and develop a team of incident responders and security builders, setting clear expectations, creating meaningful ownership, and supporting growth.
1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.
At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.
If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.
As our Manager, Security Incident Response, you are at the center of how 1Password handles the moments that matter most. You will build and lead a team of builders: responders who don't just work incidents, but engineer the automation, tooling, and systems that make response faster and more scalable over time. You will guide program maturity, scale the team's capabilities through AI-assisted tooling, reinforce operational excellence, and step in as incident manager during complex, high-severity events. Success in this role blends strong people leadership with technical depth and sound judgment. As part of the Security leadership team, you will shape response strategy, build effective cross-functional partnerships, and help protect a product trusted by millions.
This role reports to the Senior Manager, Threat Operations.
Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers.
This is a remote opportunity within Canada and the US.
• 5+ years in security incident response, with 2+ years as a people manager or technical leader supporting career development and performance management.
• Experience building or scaling incident response automation, tooling, or AI-assisted workflows (triage, enrichment, investigation), with sound judgment about where automation should and shouldn’t make decisions.
• Experience setting clear expectations, defining ownership, delegating work, and measuring outcomes.
• Experience managing high-pressure security incidents with clarity, structure, and calm.
• Strong understanding of cloud-native, SaaS, and identity-driven attack techniques and how to respond to them.
• Strong communication skills, including the ability to explain complex findings, tradeoffs, and recommendations to technical and non-technical audiences.
• Experience breaking down strategic initiatives into projects, coordinating team sprints, and managing work across competing priorities.
• Passion for fostering psychological safety and stability in stressful environments.
• A people-first leader who prioritizes team development, psychological safety, and performance.
• A builder at heart, someone who thinks in systems and automation, not just case queues, and hires and develops engineers with that same instinct.
• Proactive in identifying gaps, inefficiencies, or operational risks and bringing forward actionable solutions, including where AI or automation can close them.
• Effective at driving alignment across teams with differing priorities and perspectives.
• Calm and decisive during high-pressure situations, with the judgment to prioritize effectively and make difficult tradeoffs.
• A clear and transparent communicator who can align teams with differing priorities, surface tradeoffs, and advocate for sound security decisions.
• Motivated by protecting people, data, and the business.
• Build, lead, and develop a team of incident responders and security builders, setting clear expectations, creating meaningful ownership, and supporting growth.
• Delegate effectively based on team strengths, development goals, capacity, and operational needs while maintaining accountability for outcomes.
• Define and drive the security incident response roadmap and strategic priorities, including maturing agentic incident response, structured threat hunting, and insider risk investigations as sustained, scaled capabilities rather than one-time builds.
• Balance competing priorities across incident response, strategic initiatives, and team development; make tradeoffs clear and push back when timelines, approaches, or requests create unnecessary risk or unsustainable workload.
• Scale team capacity through AI-assisted tooling and automation, maintaining appropriate controls around human judgment, approval, auditability, and rollback.
• Oversee detection, triage, containment, remediation, and post-incident learning, serving as an escalation point and incident manager for complex or high-severity events.
• Partner with Detection Engineering, Cyber Threat Intelligence, Red Team and other teams to improve cross-functional processes and close detection or response gaps identified through investigations.
• Evolve playbooks, training, tabletop exercises, metrics, and reporting to strengthen operational readiness and program maturity.
• Participate in the on-call rotation, serving as the leadership escalation or incident manager during major or complex incidents.
• Track and report on incident trends, operational metrics, and program maturity, including the impact of automation and AI tooling on response time and coverage.
USA-based roles only: The annual base salary for this role is between $192,000 USD and $278,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.
Canada-based roles only: The annual base salary for this role is between $171,000 CAD and $248,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.
Responsibilities
~2 min read1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.
Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we’ll work to meet your needs.
Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you.
Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.
1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form. For additional information see our Candidate Privacy Notice.
Location & Eligibility
Listing Details
- Posted
- September 1, 2026
- First seen
- September 2, 2026
- Last seen
- September 2, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 61%
- Scored at
- September 2, 2026
Signal breakdown
Please let 1password know you found this job on Jobera.
3 other jobs at 1password
View all →Explore open roles at 1password.
Similar Security jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.