1password
1password1d ago
New↻ Repost

Senior Security Engineer, Vulnerability Management

(united StatesRemotefull-timesenior
EngineeringSecurity Engineer
0 views0 saves0 applied

Quick Summary

Key Responsibilities

As part of this program, the Senior Security Engineer will: Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure.

Technical Tools
EngineeringSecurity Engineer

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.

At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.

If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.

We are excited to welcome a Senior Security Engineer to join our Product Security team at 1Password. Product Security helps enable 1Password to build and deliver secure products with confidence. We own the end-to-end security lifecycle across our products, platforms, and infrastructure, including our vulnerability management program, bug bounty program, coordinated disclosure, pentesting, and supply chain security.

As part of this team, the Senior Security Engineer will lead and mature our incident response capabilities, working in close partnership with Engineering, Legal, Communications, and Customer Success to coordinate the company's response when product security incidents occur. This is a high-impact role for someone who thrives under pressure, cares deeply about protecting users, and wants to do meaningful work at a company trusted by millions.

Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers.

This is a remote opportunity within Canada and the US.

  • 5+ years of career experience in IT or Engineering with a security focus

  • Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company context

  • Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers

  • Strong judgment under pressure: you make clear, defensible decisions during time-sensitive situations with incomplete information

  • Experience building or formalizing incident response capabilities from the ground up (playbooks, runbooks, severity frameworks, escalation processes)

  • Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications

  • Strong communication skills across a wide range of audiences, from engineers to executives to customers

  • Comfort reading and writing code to support forensic analysis, automation, and tooling

  • Adaptable and resilient: you thrive in fast-paced environments where priorities can shift quickly

  • Experience leveraging AI/ML capabilities to accelerate security workflows, automate repetitive tasks, or improve detection and response

Nice to Have

~1 min read
  • Familiarity with CVSS, EPSS, and vulnerability severity frameworks as they apply to incident prioritization

  • Experience in a consumer or B2B SaaS environment where customer trust and public perception are high stakes

  • Familiarity with Software Bill of Materials (SBOMs) and supply chain risk as it relates to security incidents

  • Experience with compliance standards and certifications (e.g., SOC 2, ISO 27001) and their intersection with incident reporting obligations

  • Relevant certifications such as GCIH, GCFE, GCFA, PNPT, or similar (valued but not required)

As part of this program, the Senior Security Engineer will:

  • Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure.

  • Own and evolve 1Password's PSIRT function, including incident classification frameworks, severity models, escalation paths, and response playbooks

  • Drive coordinated vulnerability disclosure (CVD) processes, partnering with our bug bounty program and external security researchers to manage responsible disclosure timelines and communications

  • Serve as the primary coordinator across Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents

  • Lead post-incident reviews (PIRs) and translate findings into systemic improvements across our products, processes, and detection capabilities

  • Develop and maintain incident response tooling, automation, and reporting that reduce time-to-detect and time-to-respond

  • Contribute to customer-facing security advisories, CVE disclosures, and public incident communications in partnership with Legal and Communications

  • Evaluate and integrate AI-powered tooling and workflows that improve the speed and effectiveness of incident detection and response

  • Mentor other engineers and help shape the long-term maturity of our product security and incident response capabilities.

  • Serve on an on-call rotation with out-of-business-hours coverage.

Responsibilities

~2 min read

1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.

Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we’ll work to meet your needs.

Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you.

Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.

1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form. For additional information see our Candidate Privacy Notice.

Location & Eligibility

Where is the job
Worldwide
Fully remote, anywhere in the world
Who can apply
Same as job location

Listing Details

Posted
August 4, 2026
First seen
August 5, 2026
Last seen
August 5, 2026

Posting Health

Days active
0
Repost count
1
Trust Level
54%
Scored at
August 5, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

1passwordSenior Security Engineer, Vulnerability Management