Remotery

Senior Security Engineer, Vulnerability Management

Posted Aug 4

This is a fully remote position, open to applicants in United States, +1 more state.

📋 Description

• Oversee the complete response process for product security incidents, encompassing discovery, triage, remediation, and disclosure.

• Take ownership and enhance 1Password's Product Security Incident Response Team (PSIRT) function, which includes incident classification frameworks, severity models, escalation paths, and response playbooks.

• Facilitate coordinated vulnerability disclosure processes and manage the timelines and communications related to responsible disclosures with external security researchers.

• Collaborate with Product Security, Engineering, Legal, Communications, and Customer Success teams during active security incidents.

• Conduct post-incident reviews and convert findings into systematic enhancements across products, processes, and detection capabilities.

• Develop and sustain incident response tools, automation, and reporting mechanisms to minimize detection and response times.

• Contribute to security advisories aimed at customers, CVE disclosures, and public communications regarding incidents.

• Assess and incorporate AI-driven tools and workflows for incident detection and response.

• Provide mentorship to other engineers and help advance the maturity of product security and incident response capabilities.

• Participate in an on-call rotation to provide coverage outside of regular business hours.

• Create incident response tools utilizing AI and demonstrate tangible impacts from systems and automation initiatives.


⛳️ Requirements

• A minimum of 5 years of professional experience in IT or Engineering with a focus on security.

• Practical experience in leading or engaging in security incident response, preferably within a product or SaaS company environment.

• Familiarity with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers.

• Strong decision-making skills under pressure during time-sensitive situations with incomplete information.

• Experience in establishing or formalizing incident response capabilities, including playbooks, runbooks, severity frameworks, and escalation processes.

• Background in drafting or contributing to customer security advisories, CVEs, or public-facing incident communications.

• Excellent communication skills, effective across engineers, executives, and customers.

• Proficiency in reading and writing code for forensic analysis, automation, and tooling purposes.

• Ability to adapt and remain resilient in fast-paced environments with changing priorities.

• Experience utilizing AI/ML to enhance security workflows, automate repetitive tasks, or improve detection and response capabilities.

• Knowledge of CVSS, EPSS, and vulnerability severity frameworks.

• Understanding of Software Bill of Materials (SBOMs) and supply chain risk considerations.

• Familiarity with compliance standards and certifications such as SOC 2 and ISO 27001.

• Relevant certifications such as GCIH, GCFE, GCFA, or PNPT are beneficial but not mandatory.

• Proven track record in developing AI-enabled security or incident response tools and articulating design decisions, iterations, workflow changes, and measurable impacts.

• Candidates must already possess legal authorization to work in the United States or Canada; no work authorization, relocation assistance, or visa sponsorship/transferring will be provided.

• Successful candidates must undergo a background check.


🏝️ Benefits

• Health benefits

• Dental benefits

• 401(k) (for roles based in the USA)

• RRSP (for roles based in Canada)

• Generous paid time off (PTO)

• Equity grant / RSU program available for most employees

• Incentive programs, where applicable

• Maternity and parental leave top-up programs

• Retirement matching program

• Complimentary 1Password account

• Paid volunteer days

• Peer-to-peer recognition through Bonusly

• Remote-first work environment

• Opportunities for travel for in-person engagement, including annual department-wide offsites, team meetings, and customer/industry events

People also viewed

Legacy Community Health1 day ago

IT Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
NeoGuardian1 day ago

Cyber Security Engineer I – Blue Team

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Fresh Consulting1 day ago

Staff Software Engineer – Security, Cryptography

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
CrowdStrike1 day ago

Staff AI Security Scientist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$235k – $350k/year
ApplyView job
CrowdStrike1 day ago

Security Advisor, Falcon Complete

AU flagAustralia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Supply Chimp1 day ago

Cybersecurity Specialist

PH flagPhilippines OnlyFull-timeCybersecurity / Security EngineerPHP 62.5k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers