Senior Security Engineer, Grc Automation

1Password 1Password · Enterprise · United States, Canada · Remote · Technology

1Password is seeking a Senior Security Engineer, GRC Automation to design and implement automation, dashboards, and integrations for their Governance, Risk, and Compliance (GRC) operations. This role involves operationalizing a GRC platform, integrating it with internal systems, and ensuring automated assurance processes. The ideal candidate has a background in security engineering, DevSecOps, or solutions engineering with experience in GRC platforms, scripting, and compliance frameworks. Familiarity with AI governance, privacy, and security considerations for LLMs and agentic systems is also required, along with the ability to evaluate where AI-driven approaches are appropriate in GRC workflows.

What you'd actually do

  1. Lead the implementation and integration of our GRC platform, ensuring it is fully operationalized across key systems and workflows.
  2. Build automated workflows for control testing, evidence collection, and audit readiness.
  3. Develop and maintain integrations between the GRC platform and systems of record (e.g., ticketing systems, IAM, asset inventories, configuration management).
  4. Design dashboards and reporting to track control health, trust signals, and audit performance.
  5. Help define and operationalize scalable assurance approaches for internal AI usage and AI-enabled product capabilities.

Skills

Required

  • 5+ years of experience in security engineering, DevSecOps, solutions engineering, or GRC automation roles.
  • Proven experience working with GRC, compliance, or audit teams to build automation that supports evidence collection, control testing, or security monitoring.
  • Direct experience implementing and integrating GRC platforms (e.g., Drata, Vanta, Tines, JupiterOne) into production environments.
  • Strong scripting and integration skills using Python, JavaScript, APIs, webhooks, or workflow automation tools.
  • Ability to work cross-functionally with Security, Compliance, Legal, and Infrastructure teams to translate policies into scalable technical systems.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53, and how they map to real-world infrastructure and operations.
  • Experience applying automation or AI tools to improve GRC, audit, or assurance workflows, with an understanding of validation, accuracy, and trust tradeoffs.
  • Familiarity with AI governance, privacy, and security considerations for LLMs and agentic systems (e.g., sensitive data exposure, prompt injection, system misuse).
  • Ability to evaluate where AI-driven approaches are appropriate in GRC workflows versus where deterministic controls and human review are required.
  • Builder mindset with modern tools (including AI), with the ability to experiment, evaluate, and operationalize solutions rather than only consume them.

Nice to have

  • Hands-on experience with event-driven automation platforms like Tines and their use in control validation and alerting.
  • Expertise in building evidence pipelines, tagging telemetry, or creating GRC dashboards (e.g., Looker, Metabase).
  • Strong understanding of cloud-native security architecture and its relationship to compliance controls (e.g., AWS IAM, encryption, logging).
  • Experience working in customer trust, privacy engineering, or supporting sales/GTM teams with compliance assurance content.
  • Experience supporting AI governance, AI risk assessments, or privacy-by-design reviews for AI-enabled systems.
  • Experience applying AI to audit, compliance, or third-party risk workflows in a way that improves scale while preserving trust, traceability, and human oversight.

What the JD emphasized

  • operationalizing our newly selected GRC platform
  • solutions engineering or DevSecOps background
  • applying automation or AI tools to improve GRC, audit, or assurance workflows
  • AI governance, privacy, and security considerations for LLMs and agentic systems
  • evaluate where AI-driven approaches are appropriate in GRC workflows versus where deterministic controls and human review are required
  • Builder mindset with modern tools (including AI)