1PASSWORD

Staff Security Engineer, Security Incident Response

1PASSWORD$192K — $278K *
US-AnywhereRemote in United States
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience leading high-severity security incidents, acting as an incident commander or equivalent.
  • Proven track record in designing AI-assisted automation for security operations with a sound judgment to identify automation boundaries.
  • Strong background in software engineering with experience in building security tools rather than just operating them.
  • End-to-end ownership of security programs, including planning and executing roadmap initiatives.
  • Deep understanding of cloud-native and identity-related attack techniques and effective response strategies.
  • Experience in designing and conducting tabletop exercises or similar readiness programs, translating findings into actionable improvements.
  • Strong communication skills for relaying technical trade-offs to leadership and stakeholders.

Responsibilities

  • Serve as the primary incident manager for complex, high-severity events, ensuring sound judgement and decision-making under pressure.
  • Design and implement AI-assisted systems to enhance incident triage, investigation, and containment processes.
  • Establish safety controls and rollback mechanisms for automated actions, ensuring critical decisions remain human-controlled.
  • Lead the development of readiness programs like tabletop exercises, guiding scenario design, execution, and improvement translation.
  • Identify and prioritize enhancements in threat hunting and insider risk capabilities, contributing to the strategic roadmap.
  • Deliver multiple-quarter initiatives to mature security capabilities, applying project management rigor to longer-term plans.
  • Mentor and elevate the technical skills of other engineers on the team, fostering a collaborative learning environment.

Benefits

  • Health and wellness benefits including maternity and parental leave top-ups.
  • Generous paid time off policy.
  • Equity options through a Restricted Stock Unit (RSU) program for eligible employees.
  • Retirement matching through RRSP or 401k plans.
  • Paid volunteer days to encourage community involvement.
  • Peer recognition program via Bonusly to celebrate team contributions.
  • Flexible remote-first work environment, with some in-person roles available.
Full Job Description
As a Staff Security Engineer on Security Incident Response, you'll serve as a senior technical leader and builder for the team, helping shape both how we respond to incidents today and how our response capabilities evolve over time.This role is about advancing what the team is capable of, not just responding when something breaks. You'll design and build the AI-assisted systems that extend the team's reach, lead the response to the most complex incidents, and own programs that make the organization more prepared over time, from tabletop exercises and gamedays to the continued advancement of threat hunting and insider risk capabilities. You bring engineering depth, sound incident judgment, and the ability to plan, and deliver complex work against a longer-term maturity roadmap not just execute against a queue. This is a senior individual contributor role with organization-wide impact on how 1Password investigates, contains, and learns from security incidents. This role reports to the Manager, Security Incident Response. How we're using AI today Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers. This is a remote opportunity within Canada and the US. What we're looking for: - Significant experience leading complex, high-severity security incidents across multiple environments, including serving as an incident commander or equivalent technical lead. - Experience designing and building AI-assisted or agentic automation for security operations (triage, investigation, containment), with sound judgment about where automation should and shouldn't hold decision authority. - Strong software engineering skills, and experience building production tooling, automation, or systems rather than only operating existing security platforms. - Experience owning a security program or capability roadmap end to end, including planning, sequencing, and delivering multi-quarter work. - Strong understanding of cloud-native, SaaS, and identity-driven attack techniques and response approaches. - Experience designing and running tabletop exercises, gamedays, or comparable readiness programs and translating findings into improvements.. - Strong written and verbal communication skills, including the ability to represent technical tradeoffs to senior leadership and cross-functional stakeholders. - Experience mentoring engineers or otherwise raising the technical and investigative capabilities of a team. How you'll work: - You look for opportunities to build systems that scale the team's capabilities rather than relying on repeated manual effort, and you're interested in thoughtfully applying AI and automation where they can improve security outcomes. - An experienced incident commander who brings structure to complex incidents, makes sound decisions with incomplete information, and helps teams move forward during high-pressure situations. - You're comfortable taking ownership of a capability from strategy through execution, including defining priorities, sequencing work, navigating dependencies, and delivering against a longer-term roadmap. - You can operate as a technical partner to leaders and cross-functional teams, independently representing technical priorities, risks, and tradeoffs. - You value continuous improvement and contribute to an environment where teams can examine incidents, decisions, and failures openly and turn what they learn into stronger systems and practices. What you can expect: - Serve as incident manager and technical escalation point for complex, high-severity events, bringing structure, sound judgement, and clear decision-making under pressure. - Design and build AI-assisted and automated systems that improve how quickly and consistently the team can triage, investigate, and contain incidents. - Establish appropriate safety controls, approval gates, auditability, and rollback mechanisms for automated and AI-assisted actions, ensuring high-impact decisions remain appropriately human-controlled. - Own the team's readiness programs, including tabletop exercises and incident gamedays, from scenario design and execution through debriefing and translating finishes into concrete (or measurable) improvements - Advance the team's threat hunting and insider risk capabilities by identifying opportunities, defining priorities, and delivering roadmap work that improves investigative depth and coverage - Plan, sequence, and deliver multi-quarter initiatives that mature the team's capabilities, bringing project management discipline to work that doesn't fit neatly into a sprint. - Mentor and provide technical leadership to other engineers, strengthening engineering rigor and investigative judgement across the team. - Partner with Security Operations, Product Security, and Engineering teams to close gaps surfaced through investigations, hunting, and simulations. - Foster psychological safety and blameless learning across incident retrospectives, gamedays, and tabletop debriefs. - Extend strong incident response practices beyond the immediate team by building reusable systems, tooling, and operating patterns that strengthen response capabilities across areas such as PSIRT, Privacy, and Engineering. USA-based roles only: The annual base salary for this role is between $192,000 USD and $278,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. Canada-based roles only: The annual base salary for this role is between $167,000 CAD and $242,000 CAD, plus immediate participation in 1Password's generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. This posting is for an existing vacancy. What we offer We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: Health and wellbeing Maternity and parental leave top-up programs Competitive health benefits Generous PTO policy Growth and future RSU program for most employees Retirement matching program Free 1Password account Community Paid volunteer days Peer-to-peer recognition through Bonusly Remote-first work environment *Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.

Similar Jobs

More Jobs at 1PASSWORD

More Information Technology Jobs

Find similar Staff Security Engineer, Security Incident Response jobs: