Senior Security Engineer, Vulnerability Management

1Password 1Password · Enterprise · United States, Canada · Remote · Technology

This role focuses on building and scaling a vulnerability management program, with a specific emphasis on integrating and evaluating AI-powered tools and agentic workflows to enhance vulnerability detection and remediation efficiency. The engineer will design, build, and integrate security solutions, develop tools for correlating and prioritizing findings, create dashboards, and partner with development teams on triage and remediation strategies.

What you'd actually do

  1. Design, build, integrate and scale new security solutions to power our vulnerability management program.
  2. Develop and maintain tools that correlate, enrich, and prioritize security vulnerability findings from multiple data sources.
  3. Develop and maintain comprehensive dashboards and reporting metrics around our vulnerability management program, tailored to different audiences (technical, non-technical, compliance, senior leadership, etc.)
  4. Conduct detailed analysis used to inform security development teams to eliminate classes of vulnerabilities.
  5. Partner with product and development teams to improve vulnerability triage workflows, validate findings, and come up with remediation strategies consistent with good user experiences.

Skills

Required

  • 5+ years of career experience in IT or Engineering with a security focus
  • strong experience with any of: bug bounty programs, vulnerability research, validation, remediation or pentesting
  • experience leveraging AI/ML capabilities to accelerate security workflows, automate repetitive tasks, or enhance detection and remediation efforts
  • experience with internal tool development and engineering enablement
  • strong foundational understanding of software development principles
  • comfortable reading and writing code
  • work well in a team environment with positive communications amongst a variety of technical and non-technical stakeholders
  • comfortable owning and setting technical direction for small to medium sized initiatives
  • adaptable and resilient, thriving in fast-paced environments with shifting priorities

Nice to have

  • Experience with Rust and/or Golang, or a demonstrated ability to pick up new languages quickly.
  • Experience with popular compliance standards and certifications (e.g. SOC2, ISO, PCI)
  • Experience building or maintaining vulnerability management programs in medium to large sized organizations
  • Familiarity with Software Bill of Materials (SBOMs) and their application in vulnerability management and software supply chain risk

What the JD emphasized

  • rapidly maturing and scaling our vulnerability management program with new agentic AI tooling and workflows
  • Evaluate, build, and pilot AI-powered tools and workflows that improve the efficiency and effectiveness of vulnerability detection and remediation.

Other signals

  • AI/ML capabilities to accelerate security workflows
  • AI-powered tools and workflows that improve the efficiency and effectiveness of vulnerability detection and remediation
  • agentic AI tooling and workflows