Senior Security Engineer, Vulnerability Management

New
1
1PasswordCybersecurity / SaaS
Remote (United States | Canada)Full-TimeSenior
SalaryUSA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD. Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD.
Apply NowOpens the employer's application page

Job Details

Experience
5+ years of career experience in IT or Engineering with a security focus
Required Skills
SaaS

Requirements

  • 5+ years of career experience in IT or Engineering with a security focus.
  • Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company context.
  • Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers.
  • Strong judgment under pressure: you make clear, defensible decisions during time-sensitive situations with incomplete information.
  • Experience building or formalizing incident response capabilities from the ground up (playbooks, runbooks, severity frameworks, escalation processes).
  • Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications.
  • Strong communication skills across a wide range of audiences, from engineers to executives to customers.
  • Comfort reading and writing code to support forensic analysis, automation, and tooling.
  • Experience leveraging AI/ML capabilities to accelerate security workflows, automate repetitive tasks, or improve detection and response.
  • Familiarity with CVSS, EPSS, and vulnerability severity frameworks.
  • Familiarity with Software Bill of Materials (SBOMs) and supply chain risk.
  • Relevant certifications such as GCIH, GCFE, GCFA, or PNPT (valued but not required).

Responsibilities

  • Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure.
  • Own and evolve 1Password's PSIRT function, including incident classification frameworks, severity models, escalation paths, and response playbooks.
  • Drive coordinated vulnerability disclosure (CVD) processes, partnering with our bug bounty program and external security researchers.
  • Serve as the primary coordinator across Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents.
  • Lead post-incident reviews (PIRs) and translate findings into systemic improvements across our products, processes, and detection capabilities.
  • Develop and maintain incident response tooling, automation, and reporting that reduce time-to-detect and time-to-respond.
  • Contribute to customer-facing security advisories, CVE disclosures, and public incident communications.
  • Evaluate and integrate AI-powered tooling and workflows that improve the speed and effectiveness of incident detection and response.
  • Mentor other engineers and help shape the long-term maturity of our product security and incident response capabilities.
  • Serve on an on-call rotation with out-of-business-hours coverage.
View Full Description & ApplyYou'll be redirected to the employer's site
USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD. Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD.
Apply Now