Staff Security Engineer, Devsecops (corporate Security)

1Password 1Password · Enterprise · United States, Canada · Remote · Technology

Staff Security Engineer to found and lead the DevSecOps function within Corporate Security. This role will set the technical vision, drive standards and controls for engineering teams, and build a scalable program. Responsibilities include securing developer environments, CI/CD, software supply chains, and addressing security challenges from AI-assisted and agentic development.

What you'd actually do

  1. Found and lead the DevSecOps function within our Corporate Security team.
  2. Set the technical vision, drive the standards and controls that engineering teams rely on, and build a well-run program that scales with the organization.
  3. Design and implement security controls that integrate into CI/CD pipelines without meaningfully degrading developer velocity.
  4. Solve security challenges introduced by AI-assisted and agentic development.
  5. Make architectural decisions that span multiple teams, setting standards and patterns that other engineers adopt.

Skills

Required

  • Security engineering
  • DevSecOps
  • Platform security
  • Securing developer environments
  • CI/CD security
  • Software supply chain security
  • GitHub Enterprise security and governance
  • GitHub Actions security
  • Dependency hygiene
  • Token and secret management
  • Secure package consumption
  • SBOM generation
  • AI coding tools security
  • Agentic development security
  • Python
  • Bash
  • Terraform
  • Automation
  • Mentorship

Nice to have

  • Familiarity with on-call rotations and investigations involving developer tooling, source control, or credential exposure.

What the JD emphasized

  • Minimum of 8 years of combined experience in security engineering, DevSecOps, platform security, or closely related engineering roles, with deep focus on securing developer environments, CI/CD, or software supply chains.
  • Deep, hands-on expertise in GitHub Enterprise security and governance, including branch protections, secret scanning, access controls, repository standards, Actions security, and audit logging at scale.
  • Proven ability to design and implement security controls that integrate into CI/CD pipelines without meaningfully degrading developer velocity.
  • Practical experience solving security challenges introduced by AI-assisted and agentic development.
  • Comfortable making architectural decisions that span multiple teams.
  • Strong scripting and automation skills in Python, Bash, Terraform, or similar, with demonstrated ability to build tooling that scales security controls without proportional manual effort.
  • Experience participating in on-call rotations and contributing to investigations involving developer tooling, source control, or credential exposure.