FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Senior Security Engineer, Vulnerability Management
1PasswordSenior Security Engineer leading product security incident response for 1Password’s password management and unified access platform. Building AI-powered tooling, vulnerability disclosure processes, and PSIRT capabilities.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in leading product security incident response, including developing incident response tooling and frameworks, managing vulnerability disclosures, and mentoring engineering teams. Proficient in leveraging AI for security workflows and maintaining compliance with industry standards.
Highest-signal resume keywords
Incident Response LeadershipCoordinated Vulnerability DisclosureAI-Powered Security ToolingSecurity Advisory CommunicationCompliance Standards Familiarity
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Security Incident ResponseIncident Response ToolingForensic AnalysisAutomation DevelopmentVulnerability Severity FrameworksCVE DisclosuresAI/ML IntegrationIncident PlaybooksRunbooksSupply Chain Risk Management
Soft Skills
Strong Communication SkillsJudgment Under PressureAdaptabilityResilience
Tools & Technologies
AI-Powered ToolingIncident Response AutomationSecurity AdvisoriesSoftware Bill of Materials (SBOM)
Certifications & Qualifications
GCIHGCFEGCFAPNPT
Industry Keywords
SOC 2ISO 27001CVSSEPSSProduct SecuritySaaS Security
About the role
Key responsibilities & impact- Lead end-to-end response to product security incidents, from discovery, triage, remediation, and disclosure
- Own and evolve 1Password's PSIRT function, including incident classification frameworks, severity models, escalation paths, and response playbooks
- Drive coordinated vulnerability disclosure processes and manage responsible disclosure timelines and communications with external security researchers
- Coordinate Product Security, Engineering, Legal, Communications, and Customer Success during active security incidents
- Lead post-incident reviews and translate findings into systemic improvements across products, processes, and detection capabilities
- Develop and maintain incident response tooling, automation, and reporting to reduce time-to-detect and time-to-respond
- Contribute to customer-facing security advisories, CVE disclosures, and public incident communications
- Evaluate and integrate AI-powered tooling and workflows for incident detection and response
- Mentor other engineers and shape the maturity of product security and incident response capabilities
- Serve on an on-call rotation with out-of-business-hours coverage
- Build Incident Response tooling with AI and demonstrate measurable impact from systems and automation work
Requirements
What you’ll need- 5+ years of career experience in IT or Engineering with a security focus
- Hands-on experience leading or participating in security incident response, ideally in a product or SaaS company context
- Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers
- Strong judgment under pressure during time-sensitive situations with incomplete information
- Experience building or formalizing incident response capabilities, including playbooks, runbooks, severity frameworks, and escalation processes
- Experience drafting or contributing to customer security advisories, CVEs, or public-facing incident communications
- Strong communication skills across engineers, executives, and customers
- Ability to read and write code for forensic analysis, automation, and tooling
- Adaptability and resilience in fast-paced environments with shifting priorities
- Experience leveraging AI/ML to accelerate security workflows, automate repetitive tasks, or improve detection and response
- Familiarity with CVSS, EPSS, and vulnerability severity frameworks
- Familiarity with Software Bill of Materials (SBOMs) and supply chain risk
- Experience with compliance standards and certifications such as SOC 2 and ISO 27001
- Relevant certifications such as GCIH, GCFE, GCFA, or PNPT are valued but not required
- Proven experience building AI-enabled security or incident response tooling and explaining design choices, iterations, downstream workflow changes, and measurable impact
- Must already be legally authorized to work in the United States or Canada; no work authorization, relocation assistance, or visa sponsorship/transferring is offered
- Successful applicants must complete a background check
Benefits
Comp & perks- Health benefits
- Dental benefits
- 401(k) (USA-based roles)
- RRSP (Canada-based roles)
- Generous paid time off (PTO)
- Equity grant / RSU program for most employees
- Incentive programs, where applicable
- Maternity and parental leave top-up programs
- Retirement matching program
- Free 1Password account
- Paid volunteer days
- Peer-to-peer recognition through Bonusly
- Remote-first work environment
- Travel for in-person engagement, including annual department-wide offsites, team meetings, and customer/industry events