# Senior Security Engineer, Vulnerability Management

**Company:** [1Password](https://hotfix.jobs/companies/1password)
**Location:** Remote
**Role:** Security Engineering
**Salary:** $153k – $214k/yr
**Experience:** 5+ years
**Skills:** Incident Response, Vulnerability Management, coordinated vulnerability disclosure, bug bounty, cvss, epss, sbom, supply chain security, AI/ML, Python, forensic analysis, Automation, cve, SOC 2, ISO 27001
**Posted:** 2026-08-04

> Leads product security incident response, coordinated vulnerability disclosure, PSIRT maturity, and customer-facing communications. The role requires 5+ years of security-focused IT or engineering experience, strong cross-functional judgment, coding ability, and experience building incident response tooling, including AI-powered workflows.

## Job Description

## Responsibilities
- Lead end-to-end response to product security incidents, from discovery and triage through remediation and disclosure.
- Own and evolve the Product Security Incident Response Team (PSIRT) function, including incident classification frameworks, severity models, escalation paths, and response playbooks.
- Drive coordinated vulnerability disclosure (CVD) processes and partner with bug bounty programs and external security researchers.
- Coordinate Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents.
- Lead post-incident reviews and translate findings into systemic improvements across products, processes, and detection capabilities.
- Develop and maintain incident response tooling, automation, and reporting to reduce time to detect and respond.
- Contribute to customer-facing security advisories, CVE disclosures, and public incident communications.
- Evaluate and integrate AI-powered tooling and workflows for incident detection and response.
- Mentor other engineers and help mature product security and incident response capabilities.
- Participate in an on-call rotation with out-of-business-hours coverage.

## Requirements
- 5+ years of career experience in IT or Engineering with a security focus.
- Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company.
- Experience with coordinated vulnerability disclosure and external security researcher relationships.
- Strong judgment under pressure and the ability to make clear, defensible decisions with incomplete information.
- Experience building or formalizing incident response capabilities, including playbooks, runbooks, severity frameworks, and escalation processes.
- Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications.
- Strong communication skills across engineers, executives, and customers.
- Ability to read and write code for forensic analysis, automation, and tooling.
- Adaptability and resilience in a fast-paced environment.
- Experience using AI/ML capabilities to accelerate security workflows, automate repetitive tasks, or improve detection and response.

## Nice-to-haves
- Familiarity with CVSS, EPSS, and vulnerability severity frameworks.
- Experience in a consumer or B2B SaaS environment where customer trust and public perception are high stakes.
- Familiarity with Software Bill of Materials (SBOMs) and supply chain risk.
- Experience with SOC 2, ISO 27001, and incident reporting obligations.
- Certifications such as GCIH, GCFE, GCFA, PNPT, or similar.
- Experience building AI-powered security workflows and explaining their downstream impact.

## Compensation and Benefits
- USA-based roles: annual base salary of $153,000 USD to $214,000 USD, plus health, dental, 401(k), paid time off, equity, and applicable incentive programs.
- Canada-based roles: annual base salary of $144,000 CAD to $202,000 CAD, plus health, dental, RRSP, paid time off, equity, and applicable incentive programs.

## Similar roles

- [Senior Developer, Product Security](https://hotfix.jobs/jobs/bc5c951c-0b14-43d4-85b0-d9db2f3ee585) - 1Password - Remote - $153k – $214k/yr
- [Senior Security Research Scientist](https://hotfix.jobs/jobs/cc7a76ad-0132-4842-9ec4-6a7a1a9c1ab3) - Censys - Remote - $153k – $212k/yr
- [Senior Developer (Windows), Product Security](https://hotfix.jobs/jobs/0e453479-0aa7-431b-9be3-5c0c27ff5d62) - 1Password - Remote - $153k – $214k/yr
- [Senior GRC Lead](https://hotfix.jobs/jobs/452c8e36-8819-473d-ad5a-157578cd6701) - Brex - San Francisco, CA - $154k – $192k/yr
- [Security Engineer](https://hotfix.jobs/jobs/85c2ee9d-3653-4525-87a8-70e70da6c342) - xAI - New York, NY - $152k – $228k/yr

**Apply:** https://hotfix.jobs/jobs/97e9722a-1ced-4782-a660-40c52bd1a0d3
**Canonical:** https://hotfix.jobs/jobs/97e9722a-1ced-4782-a660-40c52bd1a0d3