Senior Security Engineer, Detection and Response

Job Description

At 1Password, customer privacy and security come first and foremost; this commitment informs everything we do, and the Security Team is responsible for upholding this commitment. We are a passionate team that truly cares about protecting our customers, and we’re looking for new team members that share this passion.

As a Senior Security Engineer on the Detection and Response team, you will be contributing to the development and implementation of strategies to detect and respond to security threats across 1Password. You will work closely with cross-functional teams to ensure the continuous improvement of our security posture and the protection of our assets against emerging threats. This role offers the opportunity to make a significant impact in safeguarding our systems and data against cyber threats.

Join us and unleash the excitement of protecting the digital world.

This is a Remote opportunity within Canada and the US.


What we're looking for:
  • Minimum 5 years of experience in a technical engineering role, at least 3 of those years in a security role with a focus on Detection Engineering, Incident Response, Digital Forensics and/or Threat Intelligence
  • A high level of comfort with incident response frameworks, and experience calmly, and blamelessly leading complex security incidents
  • Proficient in leveraging security logs and/or a SIEM to detect, investigate, and respond to security events
  • Experience developing SOAR solutions for enhancing behavior analytics and security response automations
  • Experience with Detection-as-Code to automate detection engineering workflows
  • Knowledge of threat actor TTPs and current threat landscape to develop threat-based detections
  • Experience with runtime security, EDR, and forensic analysis tools on various operating systems
  • Proficient in threat hunting and log analysis across multiple environments
  • Knowledge of cloud environments (e.g., AWS, GCP) including security best practices for deployment of cloud services
  • Experience in scripting and programming languages (e.g., Python, Bash) for data analysis, automation and tool development
  • Experience with software development lifecycle, project management, Terraform, and CI/CD in GitLab or GitHub
  • Strong problem-solving skills with minimal supervision and takes ownership of responsibilities, identifying and addressing challenges proactively
  • Excellent communication skills with a drive for collaboration and leveling up team members
  • Passion for fostering psychological safety and stability in high-stress environments

  • What you can expect:
  • Develop threat detections and response plans across 1Password’s infrastructure, products, internal tools and corporate environments
  • Own individual and team projects from scoping to planning, ensuring deliverables are met and in alignment with Security OKRs
  • Build strong relationships with partner and stakeholder teams in order to advise on improvements that enable detection capabilities and response procedures
  • Design and build systems to automate security processes and workflows to improve efficiency and scalability
  • Partner with developers, engineers and other departments to improve security logging and address security issues for the product
  • Lead response to potential security incidents, and help design and implement remediations
  • Participate in an on-call rotation with potential for work on nights or weekends in the event a significant security issue is identified
  • Standardize, write response playbooks that can be utilized by all members of the team
  • Mentor and train team members to uphold a high team standard
  • Participate in security audits, vendor assessments and security tabletop exercises
  • Be a subject matter expert on the team’s security tooling, processes and procedures