
Staff Security Engineer – Security Incident Response
Posted Sep 14

Posted Sep 14
This is a fully remote position, open to applicants in United States, +1 more country.
• Act as a senior technical authority and architect for Security Incident Response.
• Function as the incident manager and point of technical escalation for intricate, high-severity situations.
• Guide the response to the most challenging security incidents.
• Develop and implement AI-assisted and automated systems for triage, investigation, and containment.
• Establish safety protocols, approval processes, audit capabilities, and rollback strategies for automated and AI-assisted responses.
• Oversee readiness initiatives, including tabletop exercises and incident gamedays, from scenario creation to debriefing and measurable enhancements.
• Enhance threat hunting and insider risk capabilities.
• Strategize, organize, and execute multi-quarter capability-maturity projects.
• Mentor and provide technical guidance to fellow engineers.
• Collaborate with Security Operations, Product Security, and Engineering teams to address investigation, hunting, and simulation gaps.
• Promote a culture of psychological safety and blameless learning during retrospectives, gamedays, and tabletop debriefs.
• Create reusable systems, tools, and operational patterns to bolster response across PSIRT, Privacy, and Engineering.
• Report directly to the Manager of Security Incident Response.
• Extensive experience leading complex, high-severity security incidents across various environments, including roles as an incident commander or similar technical leader.
• Proficiency in designing and implementing AI-assisted or automated solutions for security operations, including triage, investigation, and containment.
• Strong software engineering capabilities.
• Experience in developing production tools, automation, or systems rather than merely operating existing security platforms.
• Proven track record of managing a security program or capability roadmap from start to finish, encompassing planning, sequencing, and executing multi-quarter initiatives.
• Deep understanding of cloud-native, SaaS, and identity-driven attack methodologies and response strategies.
• Experience in designing and facilitating tabletop exercises, gamedays, or similar preparedness programs.
• Excellent written and verbal communication abilities, including the skill to convey technical trade-offs to senior leadership and cross-functional stakeholders.
• Experience in mentoring engineers or enhancing the technical and investigative skills of a team.
• Ability to make informed decisions with limited information during high-pressure situations.
• Capacity to manage a capability from conception through execution.
• Ability to collaborate as a technical partner with leaders and cross-functional teams.
• Must be legally authorized to work in the United States or Canada; 1Password does not provide work authorization, relocation support, sponsorship, or visa transfers.
• Successful candidates must undergo a background check.
• Work from your home country.
• Health benefits.
• Dental benefits.
• 401(k) for roles based in the USA.
• RRSP for positions based in Canada.
• Generous paid time off.
• Equity grant.
• Incentive programs where applicable.
• Maternity and parental leave top-up programs.
• RSU program available for most employees.
• Retirement matching program.
• Complimentary 1Password account.
• Paid volunteer days.
• Peer-to-peer recognition via Bonusly.
• Remote-first working environment.
• Opportunities for travel for in-person engagements, including annual department-wide offsites, team meetings, and customer/industry events.
• Accommodations available upon request during the recruitment process.
Talan
Pragmatike
Supply Chimp
Pragmatike
Get handpicked remote jobs straight to your inbox weekly.