Senior Security Engineer, Vulnerability Management

🔥 il y a 21 heures

🌐 États-Unis, Canada – Distant

info

💵 $153 000 - $214 000 / an

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of 1Password

1Password

501 - 1000 employés

Fondée en 2009

🔒 Cybersecurity

☁️ SaaS

⚡ Productivité

💰 €620 000 000 Series C en 2022-01

Cybersecurity • SaaS • Productivity

1Password est une solution de gestion des mots de passe de référence, conçue pour renforcer la sécurité des particuliers, des familles et des entreprises. Elle offre une plateforme sécurisée pour stocker et gérer les mots de passe, les informations sensibles et les identifiants d’accès sur divers appareils. Avec des fonctionnalités comme Extended Access Management, elle sécurise efficacement l’accès pour chaque identité et chaque application, comblant ainsi les failles laissées par les outils de gestion des accès traditionnels. Plébiscité par 165 000 entreprises et des millions de familles, 1Password est reconnu pour la satisfaction de ses utilisateurs et ses capacités destinées aux entreprises, ce qui en fait un choix de premier plan pour une sécurité numérique complète.

Description

• Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure • Own and evolve 1Password's PSIRT function, including incident classification frameworks, severity models, escalation paths, and response playbooks • Drive coordinated vulnerability disclosure processes and manage responsible disclosure timelines and communications with external security researchers • Coordinate Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents • Lead post-incident reviews and translate findings into systemic improvements across products, processes, and detection capabilities • Develop and maintain incident response tooling, automation, and reporting to reduce time-to-detect and time-to-respond • Contribute to customer-facing security advisories, CVE disclosures, and public incident communications • Evaluate and integrate AI-powered tooling and workflows for incident detection and response • Mentor other engineers and shape the maturity of product security and incident response capabilities • Serve on an on-call rotation with out-of-business-hours coverage • Build Incident Response tooling with AI and demonstrate measurable impact from systems and automation work

🎯 Exigences

• 5+ years of career experience in IT or Engineering with a security focus • Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company context • Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers • Strong judgment under pressure during time-sensitive situations with incomplete information • Experience building or formalizing incident response capabilities, including playbooks, runbooks, severity frameworks, and escalation processes • Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications • Strong communication skills across engineers, executives, and customers • Ability to read and write code for forensic analysis, automation, and tooling • Adaptability and resilience in fast-paced environments with shifting priorities • Experience leveraging AI/ML to accelerate security workflows, automate repetitive tasks, or improve detection and response • Familiarity with CVSS, EPSS, and vulnerability severity frameworks • Familiarity with Software Bill of Materials (SBOMs) and supply chain risk • Experience with compliance standards and certifications such as SOC 2 and ISO 27001 • Relevant certifications such as GCIH, GCFE, GCFA, or PNPT are valued but not required • Proven experience building AI-enabled security or incident response tooling and explaining design choices, iterations, downstream workflow changes, and measurable impact • Must already be legally authorized to work in the United States or Canada; no work authorization, relocation assistance, or visa sponsorship/transferring is offered • Successful applicants must complete a background check

🏖️ Avantages

• Health benefits • Dental benefits • 401(k) (USA-based roles) • RRSP (Canada-based roles) • Generous paid time off (PTO) • Equity grant / RSU program for most employees • Incentive programs, where applicable • Maternity and parental leave top-up programs • Retirement matching program • Free 1Password account • Paid volunteer days • Peer-to-peer recognition through Bonusly • Remote-first work environment • Travel for in-person engagement, including annual department-wide offsites, team meetings, and customer/industry events

Postuler Maintenant

Emplois Similaires

🔥 il y a 21 heures

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Intelligence artificielle

Senior Security Researcher tracking Russian-language eCrime actors across hidden services, forums, and online communities for CrowdStrike’s cybersecurity platform. Producing actionable intelligence and threat analysis.

🗣️🇷🇺 Russe requis

🗣️🇺🇦 Ukrainien requis

🗣️🇺🇸🇬🇧 Anglais requis

🔥 il y a 21 heures

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Intelligence artificielle

CrowdStrike cybersecurity consultant delivering generative AI-enabled source code reviews. Coordinating penetration tests, improving assessment technologies, and mentoring red team members.

🗣️🇺🇸🇬🇧 Anglais requis

🔥 il y a 21 heures

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Intelligence artificielle

Senior Security Researcher building AI-powered collection infrastructure for CrowdStrike, a global cybersecurity company. Analyzing deep-web threats, automating data operations, and responding to customer-impacting intelligence gaps.

🗣️🇺🇸🇬🇧 Anglais requis

Cloud

Cyber Security

Docker

Python

🔥 il y a 21 heures

McNees Wallace & Nurick

201 - 500

⚖️ Juridique

Security Engineer leading cybersecurity strategy, infrastructure, incident response, and risk management for McNees, a Pennsylvania full-service law firm. Advising leadership and strengthening enterprise security across IT operations.

🇺🇸 États-Unis – Télétravail

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

Azure

Cloud

Cyber Security

Firewalls

Python

🔥 il y a 23 heures

GuidePoint Security

201 - 500

💼 Conseil

🏥 Santé

📦 Logistique

Network Security Engineer implementing Zscaler SASE and enterprise firewall solutions for GuidePoint Security, a cybersecurity services and solutions provider. Delivering customer consulting, cloud firewall deployments, security documentation, and emerging AI-enabled solutions.

🗣️🇺🇸🇬🇧 Anglais requis