Search Remote Jobs

Senior Security Engineer, Vulnerability Management

Job not on LinkedIn

🔥 7 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of 1Password

1Password

501 - 1000 employees

Founded 2009

🔒 Cybersecurity

☁️ SaaS

⚡ Productivity

💰 $620M Series C on 2022-01

Cybersecurity • SaaS • Productivity

1Password is a leading password management and cybersecurity company that offers solutions for both individual and business customers to securely store and manage passwords, secrets, and sensitive information. With features like extended access management (XAM), 1Password empowers users to manage access to every application and web account, ensuring security across all devices with alerts for possible breaches. Trusted by over 150,000 businesses, 1Password provides comprehensive security solutions that enhance productivity by enabling easy and secure sharing of credentials and managing permissions, while maintaining high visibility and control. Their services cater to enterprises and families, providing protection from bad actors in today's SaaS-centric hybrid work environment.

📋 Description

• Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure • Own and evolve 1Password's PSIRT function, including incident classification frameworks, severity models, escalation paths, and response playbooks • Drive coordinated vulnerability disclosure processes and manage responsible disclosure timelines and communications with external security researchers • Coordinate Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents • Lead post-incident reviews and translate findings into systemic improvements across products, processes, and detection capabilities • Develop and maintain incident response tooling, automation, and reporting to reduce time-to-detect and time-to-respond • Contribute to customer-facing security advisories, CVE disclosures, and public incident communications • Evaluate and integrate AI-powered tooling and workflows for incident detection and response • Mentor other engineers and shape the maturity of product security and incident response capabilities • Serve on an on-call rotation with out-of-business-hours coverage • Build Incident Response tooling with AI and demonstrate measurable impact from systems and automation work

🎯 Requirements

• 5+ years of career experience in IT or Engineering with a security focus • Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company context • Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers • Strong judgment under pressure during time-sensitive situations with incomplete information • Experience building or formalizing incident response capabilities, including playbooks, runbooks, severity frameworks, and escalation processes • Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications • Strong communication skills across engineers, executives, and customers • Ability to read and write code for forensic analysis, automation, and tooling • Adaptability and resilience in fast-paced environments with shifting priorities • Experience leveraging AI/ML to accelerate security workflows, automate repetitive tasks, or improve detection and response • Familiarity with CVSS, EPSS, and vulnerability severity frameworks • Familiarity with Software Bill of Materials (SBOMs) and supply chain risk • Experience with compliance standards and certifications such as SOC 2 and ISO 27001 • Relevant certifications such as GCIH, GCFE, GCFA, or PNPT are valued but not required • Proven experience building AI-enabled security or incident response tooling and explaining design choices, iterations, downstream workflow changes, and measurable impact • Must already be legally authorized to work in the United States or Canada; no work authorization, relocation assistance, or visa sponsorship/transferring is offered • Successful applicants must complete a background check

🏖️ Benefits

• Health benefits • Dental benefits • 401(k) (USA-based roles) • RRSP (Canada-based roles) • Generous paid time off (PTO) • Equity grant / RSU program for most employees • Incentive programs, where applicable • Maternity and parental leave top-up programs • Retirement matching program • Free 1Password account • Paid volunteer days • Peer-to-peer recognition through Bonusly • Remote-first work environment • Travel for in-person engagement, including annual department-wide offsites, team meetings, and customer/industry events

Apply Now

Similar Jobs

🔥 32 minutes ago

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Artificial Intelligence

Senior Security Researcher tracking Russian-language eCrime actors across hidden services, forums, and online communities for CrowdStrike’s cybersecurity platform. Producing actionable intelligence and threat analysis.

🗣️🇷🇺 Russian Required

🗣️🇺🇦 Ukrainian Required

🔥 32 minutes ago

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Artificial Intelligence

Senior Security Researcher building AI-powered collection infrastructure for CrowdStrike, a global cybersecurity company. Analyzing deep-web threats, automating data operations, and responding to customer-impacting intelligence gaps.

🔥 32 minutes ago

CrowdStrike

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

🤖 Artificial Intelligence

CrowdStrike cybersecurity consultant delivering generative AI-enabled source code reviews. Coordinating penetration tests, improving assessment technologies, and mentoring red team members.

🔥 46 minutes ago

McNees Wallace & Nurick

201 - 500

⚖️ Legal

Security Engineer leading cybersecurity strategy, infrastructure, incident response, and risk management for McNees, a Pennsylvania full-service law firm. Advising leadership and strengthening enterprise security across IT operations.

🔥 2 hours ago

GuidePoint Security

201 - 500

💼 Consulting

🏥 Healthcare

📦 Logistics

Network Security Engineer implementing Zscaler SASE and enterprise firewall solutions for GuidePoint Security, a cybersecurity services and solutions provider. Delivering customer consulting, cloud firewall deployments, security documentation, and emerging AI-enabled solutions.