This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Application Security enables 1Password to build and deliver secure products with confidence. We’re responsible for the Security Engineering around Product Development - things like Static and Dynamic Application Security Testing, Pentesting, Security AI Tooling, our Bug Bounty Program, Vulnerability Management, and more. As part of the Application Security team, this Senior Engineer will primarily focus on building and maturing our Vulnerability Management Program, whose mission is to continuously identify, assess, prioritize, and drive remediation of security vulnerabilities across our products, platforms, and infrastructure — ensuring that 1Password maintains the highest standards of trust and safety for our users.
Job Responsibility:
Design, build, integrate and scale new security solutions to power our vulnerability management program
Develop and maintain tools that correlate, enrich, and prioritize security vulnerability findings from multiple data sources
Develop and maintain comprehensive dashboards and reporting metrics around our vulnerability management program, tailored to different audiences (technical, non-technical, compliance, senior leadership, etc.)
Conduct detailed analysis used to inform security development teams to eliminate classes of vulnerabilities
Partner with product and development teams to improve vulnerability triage workflows, validate findings, and come up with remediation strategies consistent with good user experiences
Contribute to the design of risk-scoring and SLA models that align with business priorities
Mentor other engineers and help shape the evolution of our vulnerability management strategy
Requirements:
5+ years of career experience in IT or Engineering with a security focus
Passion for and strong experience with any of: bug bounty programs, vulnerability research, validation, remediation or pentesting
Experience with internal tool development and engineering enablement
Strong foundational understanding of software development principles, and are comfortable reading and writing code
Work well in a team environment with positive communications amongst a variety of technical and non-technical stakeholders
Comfortable owning and setting technical direction for small to medium sized initiatives
Adaptable and resilient, thriving in fast-paced environments with shifting priorities
Nice to have:
Experience with Rust and/or Golang, or a demonstrated ability to pick up new languages quickly
Experience with popular compliance standards and certifications (e.g. SOC2, ISO, PCI)
Experience building or maintaining vulnerability management programs in medium to large sized organizations