Senior Security Engineer, Incident Response

1Password 1Password · Enterprise · United States, Canada · Remote · Technology

This role focuses on building and automating security incident response processes, including leveraging AI-assisted tooling to enhance investigations. The primary focus is on engineering solutions to improve response time and scalability within an enterprise security context.

What you'd actually do

  1. Lead and execute security incidents end-to-end, from initial signal through containment, recovery, and post-incident review
  2. Assess severity, declare incidents, and drive structured coordination and decision-making during active response
  3. Perform hands-on investigations and threat hunting to determine root cause, attacker behavior, scope, and impact
  4. Design and build automation to reduce triage, investigation, and response time
  5. Develop scalable systems and workflows that improve incident response and incident management

Skills

Required

  • 5+ years of experience in security incident response roles
  • 3+ years focused on security engineering and automation
  • Proven experience leading complex security incidents in cloud-native or SaaS environments
  • Experience building automation or internal tooling to improve security operations
  • Proficiency in scripting or programming (e.g., Python, Go, Bash)
  • working with APIs or orchestration platforms
  • Strong understanding of modern attacker techniques and incident response methodologies
  • Strong written and verbal communication skills, including executive-facing summaries

Nice to have

  • Familiarity with applying AI/ML-assisted workflows to operational security use cases

What the JD emphasized

  • security engineering and automation
  • building automation or internal tooling
  • applying AI/ML-assisted workflows