Senior Security Engineer, Vulnerability Management
New
1
1PasswordCybersecurity / SaaS
Remote (United States | Canada)Full-TimeSenior
SalaryUSA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD. Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD.
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of career experience in IT or Engineering with a security focus
- Required Skills
- SaaS
Requirements
- 5+ years of career experience in IT or Engineering with a security focus.
- Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company context.
- Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers.
- Strong judgment under pressure: you make clear, defensible decisions during time-sensitive situations with incomplete information.
- Experience building or formalizing incident response capabilities from the ground up (playbooks, runbooks, severity frameworks, escalation processes).
- Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications.
- Strong communication skills across a wide range of audiences, from engineers to executives to customers.
- Comfort reading and writing code to support forensic analysis, automation, and tooling.
- Experience leveraging AI/ML capabilities to accelerate security workflows, automate repetitive tasks, or improve detection and response.
- Familiarity with CVSS, EPSS, and vulnerability severity frameworks.
- Familiarity with Software Bill of Materials (SBOMs) and supply chain risk.
- Relevant certifications such as GCIH, GCFE, GCFA, or PNPT (valued but not required).
Responsibilities
- Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure.
- Own and evolve 1Password's PSIRT function, including incident classification frameworks, severity models, escalation paths, and response playbooks.
- Drive coordinated vulnerability disclosure (CVD) processes, partnering with our bug bounty program and external security researchers.
- Serve as the primary coordinator across Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents.
- Lead post-incident reviews (PIRs) and translate findings into systemic improvements across our products, processes, and detection capabilities.
- Develop and maintain incident response tooling, automation, and reporting that reduce time-to-detect and time-to-respond.
- Contribute to customer-facing security advisories, CVE disclosures, and public incident communications.
- Evaluate and integrate AI-powered tooling and workflows that improve the speed and effectiveness of incident detection and response.
- Mentor other engineers and help shape the long-term maturity of our product security and incident response capabilities.
- Serve on an on-call rotation with out-of-business-hours coverage.
View Full Description & ApplyYou'll be redirected to the employer's site