Senior Security Engineer, Incident Response

1Password $153K - $214K/year Posted 3 days ago

100% remote US only · US (remote)

About the role

1Password's Security Operations team protects the business by securing the systems, tools, and processes that power how the company works. As a Senior Security Engineer on the Incident Response team, you will lead complex security investigations while building the systems and automation that make response faster, more reliable, and more scalable. The role blends deep investigative expertise, hands-on engineering, and structured incident coordination: you drive incidents end-to-end, build automation and workflows that reduce response friction, and contribute to a culture of learning and psychological safety during high-pressure situations. It is a high-impact role with meaningful ownership across both incident execution and operational engineering, reporting to the Manager of Security Incident Response.

Responsibilities

  • Lead and execute security incidents end-to-end, from initial signal through containment, recovery, and post-incident review.
  • Assess severity, declare incidents, and drive structured coordination and decision-making during active response.
  • Perform hands-on investigations and threat hunting to determine root cause, attacker behavior, scope, and impact.
  • Design and build automation to reduce triage, investigation, and response time.
  • Develop scalable systems and workflows that improve incident response and incident management.
  • Identify recurring pain points and detection/response gaps, then implement durable engineering solutions.
  • Improve incident response playbooks, case management, and orchestration tooling.
  • Apply AI-assisted tooling to enhance triage, enrichment, and investigative workflows while maintaining accuracy.

Qualifications

  • 5+ years of experience in security incident response roles, with 3+ years focused on security engineering and automation.
  • Proven experience leading complex security incidents in cloud-native or SaaS environments.
  • Experience building automation or internal tooling to improve security operations.
  • Proficiency in scripting or programming (Python, Go, Bash) and working with APIs or orchestration platforms.
  • Familiarity with applying AI/ML-assisted workflows to operational security use cases.
  • Strong understanding of modern attacker techniques and incident response methodologies.
  • Calm and decisive under pressure, with strong judgment in ambiguous or high-severity situations.
  • Clear communicator who can translate technical findings into actionable guidance for technical and non-technical audiences, including executive-facing summaries.

Skills

How to apply

Apply directly on the employer's application page. Your application goes straight to them.

Republished listing

This opportunity was discovered on 1Password's public careers page and is republished here for discovery purposes. Applications are handled by the employer.

1Password team? Claim this listing or ask us to remove it.