Skip to content
1Password1PasswordUnited States

Senior Security Engineer, Vulnerability Management

Leads product security incident response, coordinated vulnerability disclosure, PSIRT maturity, and customer-facing communications. The role requires 5+ years of security-focused IT or engineering experience, strong cross-functional judgment, coding ability, and experience building incident response tooling, including AI-powered workflows.

153k – 214k/yr
Remote5+ YOESecurity Engineering

About the role

Responsibilities

  • Lead end-to-end response to product security incidents, from discovery and triage through remediation and disclosure.
  • Own and evolve the Product Security Incident Response Team (PSIRT) function, including incident classification frameworks, severity models, escalation paths, and response playbooks.
  • Drive coordinated vulnerability disclosure (CVD) processes and partner with bug bounty programs and external security researchers.
  • Coordinate Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents.
  • Lead post-incident reviews and translate findings into systemic improvements across products, processes, and detection capabilities.
  • Develop and maintain incident response tooling, automation, and reporting to reduce time to detect and respond.
  • Contribute to customer-facing security advisories, CVE disclosures, and public incident communications.
  • Evaluate and integrate AI-powered tooling and workflows for incident detection and response.
  • Mentor other engineers and help mature product security and incident response capabilities.
  • Participate in an on-call rotation with out-of-business-hours coverage.

Requirements

  • 5+ years of career experience in IT or Engineering with a security focus.
  • Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company.
  • Experience with coordinated vulnerability disclosure and external security researcher relationships.
  • Strong judgment under pressure and the ability to make clear, defensible decisions with incomplete information.
  • Experience building or formalizing incident response capabilities, including playbooks, runbooks, severity frameworks, and escalation processes.
  • Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications.
  • Strong communication skills across engineers, executives, and customers.
  • Ability to read and write code for forensic analysis, automation, and tooling.
  • Adaptability and resilience in a fast-paced environment.
  • Experience using AI/ML capabilities to accelerate security workflows, automate repetitive tasks, or improve detection and response.

Nice-to-haves

  • Familiarity with CVSS, EPSS, and vulnerability severity frameworks.
  • Experience in a consumer or B2B SaaS environment where customer trust and public perception are high stakes.
  • Familiarity with Software Bill of Materials (SBOMs) and supply chain risk.
  • Experience with SOC 2, ISO 27001, and incident reporting obligations.
  • Certifications such as GCIH, GCFE, GCFA, PNPT, or similar.
  • Experience building AI-powered security workflows and explaining their downstream impact.

Compensation and Benefits

  • USA-based roles: annual base salary of $153,000 USD to $214,000 USD, plus health, dental, 401(k), paid time off, equity, and applicable incentive programs.
  • Canada-based roles: annual base salary of $144,000 CAD to $202,000 CAD, plus health, dental, RRSP, paid time off, equity, and applicable incentive programs.

Skills

Incident ResponseVulnerability Managementcoordinated vulnerability disclosurebug bountycvssepsssbomsupply chain securityAI/MLPythonforensic analysisAutomationcveSOC 2ISO 27001
1Password

Senior Developer, Product Security

1PasswordUnited States

Senior security-focused developer implementing new security features and secure libraries for iOS and hybrid apps at 1Password. Requires 5+ years of security development experience, 3+ years with iOS and Rust.

153k – 214k/yrRemote5+ YOESecurity Engineering
Censys

Senior Security Research Scientist

CensysSan Francisco, CA +3

Conducts internet-wide security research using scan data to identify trends, vulnerabilities, and threats. Analyzes large datasets with tools like BigQuery and Snowflake, partners with engineering teams, and shares insights publicly. Requires deep knowledge of internet protocols.

153k – 212k/yrRemoteSecurity Engineering
1Password

Senior Developer (Windows), Product Security

1PasswordUnited States

Senior Developer builds Windows security features using Rust and other languages, develops secure libraries, resolves vulnerabilities, and leads secure coding practices. Requires 4+ years experience in Windows security development and cryptography.

153k – 214k/yrRemote4+ YOESecurity Engineering
Brex

Senior GRC Lead

BrexSan Francisco, CA +2

Senior GRC Engineer at Brex automating compliance workflows, building security tool integrations and GRC automations, implementing controls for frameworks like SOC 2/PCI/ISO, and supporting audits while translating regulatory needs into technical solutions. Requires 5+ years GRC/security engineering experience, Python/API skills, and a builder mindset for scalable automation.

154k – 192k/yrHybrid5+ YOESecurity Engineering
xAI

Security Engineer

xAINew York, NY +2

GRC Security Engineer building Compliance-as-Code, automated controls, and continuous compliance for fintech/payments (PCI DSS, NYDFS, FFIEC). Partners with engineering to embed regulatory requirements into systems while enabling business velocity in a regulated AI/fintech environment.

152k – 228k/yrHybrid8+ YOESecurity Engineering