Senior Security Engineer leading product security incident response for 1Password’s password management and unified access platform. Building AI-powered tooling, vulnerability disclosure processes, and PSIRT capabilities.
Responsibilities
Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure
Own and evolve 1Password's PSIRT function, including incident classification frameworks, severity models, escalation paths, and response playbooks
Drive coordinated vulnerability disclosure processes and manage responsible disclosure timelines and communications with external security researchers
Coordinate Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents
Lead post-incident reviews and translate findings into systemic improvements across products, processes, and detection capabilities
Develop and maintain incident response tooling, automation, and reporting to reduce time-to-detect and time-to-respond
Contribute to customer-facing security advisories, CVE disclosures, and public incident communications
Evaluate and integrate AI-powered tooling and workflows for incident detection and response
Mentor other engineers and shape the maturity of product security and incident response capabilities
Serve on an on-call rotation with out-of-business-hours coverage
Build Incident Response tooling with AI and demonstrate measurable impact from systems and automation work
Requirements
5+ years of career experience in IT or Engineering with a security focus
Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company context
Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers
Strong judgment under pressure during time-sensitive situations with incomplete information
Experience building or formalizing incident response capabilities, including playbooks, runbooks, severity frameworks, and escalation processes
Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications
Strong communication skills across engineers, executives, and customers
Ability to read and write code for forensic analysis, automation, and tooling
Adaptability and resilience in fast-paced environments with shifting priorities
Experience leveraging AI/ML to accelerate security workflows, automate repetitive tasks, or improve detection and response
Familiarity with CVSS, EPSS, and vulnerability severity frameworks
Familiarity with Software Bill of Materials (SBOMs) and supply chain risk
Experience with compliance standards and certifications such as SOC 2 and ISO 27001
Relevant certifications such as GCIH, GCFE, GCFA, or PNPT are valued but not required
Proven experience building AI-enabled security or incident response tooling and explaining design choices, iterations, downstream workflow changes, and measurable impact
Must already be legally authorized to work in the United States or Canada; no work authorization, relocation assistance, or visa sponsorship/transferring is offered
Successful applicants must complete a background check
Benefits
Health benefits
Dental benefits
401(k) (USA-based roles)
RRSP (Canada-based roles)
Generous paid time off (PTO)
Equity grant / RSU program for most employees
Incentive programs, where applicable
Maternity and parental leave top-up programs
Retirement matching program
Free 1Password account
Paid volunteer days
Peer-to-peer recognition through Bonusly
Remote-first work environment
Travel for in-person engagement, including annual department-wide offsites, team meetings, and customer/industry events
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.