
Senior Security Engineer, Vulnerability Management
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in United States, +1 more state.
• Oversee the complete response process for product security incidents, encompassing discovery, triage, remediation, and disclosure.
• Take ownership and enhance 1Password's Product Security Incident Response Team (PSIRT) function, which includes incident classification frameworks, severity models, escalation paths, and response playbooks.
• Facilitate coordinated vulnerability disclosure processes and manage the timelines and communications related to responsible disclosures with external security researchers.
• Collaborate with Product Security, Engineering, Legal, Communications, and Customer Success teams during active security incidents.
• Conduct post-incident reviews and convert findings into systematic enhancements across products, processes, and detection capabilities.
• Develop and sustain incident response tools, automation, and reporting mechanisms to minimize detection and response times.
• Contribute to security advisories aimed at customers, CVE disclosures, and public communications regarding incidents.
• Assess and incorporate AI-driven tools and workflows for incident detection and response.
• Provide mentorship to other engineers and help advance the maturity of product security and incident response capabilities.
• Participate in an on-call rotation to provide coverage outside of regular business hours.
• Create incident response tools utilizing AI and demonstrate tangible impacts from systems and automation initiatives.
• A minimum of 5 years of professional experience in IT or Engineering with a focus on security.
• Practical experience in leading or engaging in security incident response, preferably within a product or SaaS company environment.
• Familiarity with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers.
• Strong decision-making skills under pressure during time-sensitive situations with incomplete information.
• Experience in establishing or formalizing incident response capabilities, including playbooks, runbooks, severity frameworks, and escalation processes.
• Background in drafting or contributing to customer security advisories, CVEs, or public-facing incident communications.
• Excellent communication skills, effective across engineers, executives, and customers.
• Proficiency in reading and writing code for forensic analysis, automation, and tooling purposes.
• Ability to adapt and remain resilient in fast-paced environments with changing priorities.
• Experience utilizing AI/ML to enhance security workflows, automate repetitive tasks, or improve detection and response capabilities.
• Knowledge of CVSS, EPSS, and vulnerability severity frameworks.
• Understanding of Software Bill of Materials (SBOMs) and supply chain risk considerations.
• Familiarity with compliance standards and certifications such as SOC 2 and ISO 27001.
• Relevant certifications such as GCIH, GCFE, GCFA, or PNPT are beneficial but not mandatory.
• Proven track record in developing AI-enabled security or incident response tools and articulating design decisions, iterations, workflow changes, and measurable impacts.
• Candidates must already possess legal authorization to work in the United States or Canada; no work authorization, relocation assistance, or visa sponsorship/transferring will be provided.
• Successful candidates must undergo a background check.
• Health benefits
• Dental benefits
• 401(k) (for roles based in the USA)
• RRSP (for roles based in Canada)
• Generous paid time off (PTO)
• Equity grant / RSU program available for most employees
• Incentive programs, where applicable
• Maternity and parental leave top-up programs
• Retirement matching program
• Complimentary 1Password account
• Paid volunteer days
• Peer-to-peer recognition through Bonusly
• Remote-first work environment
• Opportunities for travel for in-person engagement, including annual department-wide offsites, team meetings, and customer/industry events
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.