1PASSWORD

Senior Security Engineer, Vulnerability Management

1PASSWORD$153K — $214K *
US-Anywhere
+ 2 other locationsRemote
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of IT or Engineering experience with a security focus
  • Hands-on experience in security incident response in a product or SaaS context
  • Familiar with coordinated vulnerability disclosure and working with external security researchers
  • Proven ability to make clear and defensible decisions under pressure
  • Experience developing incident response playbooks and escalation processes
  • Skilled in writing customer security advisories and incident communications
  • Comfortable reading and writing code for forensic analysis and automation
  • Adaptable to fast-paced environments with shifting priorities
  • Experience with AI/ML tools to enhance security workflows

Responsibilities

  • Lead end-to-end security incident response, from discovery to disclosure
  • Develop and refine the 1Password PSIRT function and incident classification frameworks
  • Drive vulnerability disclosure processes with bug bounty partners
  • Coordinate responses across multiple departments during incidents
  • Conduct post-incident reviews to improve systems and processes
  • Create and maintain incident response tooling and automation
  • Draft customer-facing security advisories and public communications
  • Integrate AI-powered tools to enhance incident detection and response
  • Mentor engineers to strengthen product security capabilities

Benefits

  • Health and wellbeing programs including maternity and parental leave top-up
  • Competitive health benefits package
  • Generous paid time off policy
  • Restricted stock unit (RSU) program for most employees
  • Retirement matching program
  • Complimentary 1Password account
  • Paid volunteer days for community engagement
  • Peer recognition program through Bonusly
  • Remote-first work environment
Full Job Description
We are excited to welcome a Senior Security Engineer to join our Product Security team at 1Password. Product Security helps enable 1Password to build and deliver secure products with confidence. We own the end-to-end security lifecycle across our products, platforms, and infrastructure, including our vulnerability management program, bug bounty program, coordinated disclosure, pentesting, and supply chain security. As part of this team, the Senior Security Engineer will lead and mature our incident response capabilities, working in close partnership with Engineering, Legal, Communications, and Customer Success to coordinate the company's response when product security incidents occur. This is a high-impact role for someone who thrives under pressure, cares deeply about protecting users, and wants to do meaningful work at a company trusted by millions. How we're using AI today Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers. This is a remote opportunity within Canada and the US. What we're looking for: - 5+ years of career experience in IT or Engineering with a security focus - Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company context - Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers - Strong judgment under pressure: you make clear, defensible decisions during time-sensitive situations with incomplete information - Experience building or formalizing incident response capabilities from the ground up (playbooks, runbooks, severity frameworks, escalation processes) - Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications - Strong communication skills across a wide range of audiences, from engineers to executives to customers - Comfort reading and writing code to support forensic analysis, automation, and tooling - Adaptable and resilient: you thrive in fast-paced environments where priorities can shift quickly - Experience leveraging AI/ML capabilities to accelerate security workflows, automate repetitive tasks, or improve detection and response Bonus points for: - Familiarity with CVSS, EPSS, and vulnerability severity frameworks as they apply to incident prioritization - Experience in a consumer or B2B SaaS environment where customer trust and public perception are high stakes - Familiarity with Software Bill of Materials (SBOMs) and supply chain risk as it relates to security incidents - Experience with compliance standards and certifications (e.g., SOC 2, ISO 27001) and their intersection with incident reporting obligations - Relevant certifications such as GCIH, GCFE, GCFA, PNPT, or similar (valued but not required) What you can expect: As part of this program, the Senior Security Engineer will: - Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure. - Own and evolve 1Password's PSIRT function, including incident classification frameworks, severity models, escalation paths, and response playbooks - Drive coordinated vulnerability disclosure (CVD) processes, partnering with our bug bounty program and external security researchers to manage responsible disclosure timelines and communications - Serve as the primary coordinator across Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents - Lead post-incident reviews (PIRs) and translate findings into systemic improvements across our products, processes, and detection capabilities - Develop and maintain incident response tooling, automation, and reporting that reduce time-to-detect and time-to-respond - Contribute to customer-facing security advisories, CVE disclosures, and public incident communications in partnership with Legal and Communications - Evaluate and integrate AI-powered tooling and workflows that improve the speed and effectiveness of incident detection and response - Mentor other engineers and help shape the long-term maturity of our product security and incident response capabilities. - Serve on an on-call rotation with out-of-business-hours coverage. At 1Password, we build with AI: At 1Password, using AI to do more with less isn't a bonus - it's how we operate, and it's especially central to this role. We expect you to come in and actively build Incident Response tooling with AI, not just use off-the-shelf tools. - A proven builder: You've built something - an agentic evidence collection workflow, an AI-assisted vendor questionnaire reviewer, an LLM-powered control narrative pipeline - and you can walk through what you built, the choices you made, what you iterated on, and what the measurable impact was. - Systems thinking: When you describe an automation you built, you can explain how it changed downstream workflows, not just what it saved on the immediate task. USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD, plus immediate participation in 1Password's generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. This posting is for an existing vacancy. What we offer We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: Health and wellbeing Maternity and parental leave top-up programs Competitive health benefits Generous PTO policy Growth and future RSU program for most employees Retirement matching program Free 1Password account Community Paid volunteer days Peer-to-peer recognition through Bonusly Remote-first work environment *Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.

Similar Jobs

More Jobs at 1PASSWORD

More Information Technology Jobs

Find similar Senior Security Engineer, Vulnerability Management jobs: