Senior Security Engineer, GRC Automation

Remote from
USA flagCanada flag
USA, Canada
Salary, yearly, USD
144,000 - 214,000
Employment type
Full Time,
Job posted
Apply before
27 Jun 2026
Experience level
Senior
Views / Applies
12 / 0

About 1Password

Productive businesses use 1Password to secure employees at scale.

Actively Hiring
Verified job posting
This job post has been manually reviewed for authenticity and compliance.

AI Summary

1Password is seeking a Senior Security Engineer for GRC Automation to design and implement automation, dashboards, and integrations that power Governance, Risk, and Compliance operations. The role involves partnering with the Senior Manager of GRC to build automation for audit readiness, policy enforcement, and customer trust workflows, with a focus on expanding the GRC platform Drata. This is a hands-on technical position for someone with a background in security engineering, DevSecOps, or GRC who thrives in high-impact environments. The ideal candidate has 5+ years of experience, strong scripting skills, and familiarity with compliance frameworks like SOC 2 and ISO 27001. The role is remote within the US or Canada and offers a salary range of $144,000 to $214,000 per year.

Role DNA

Job Complexity
Easy Hard
Pace & Pressure
Relaxed Fast-paced
Autonomy Level
Guided Full Ownership
Communication Load
Independent Highly Collaborative
AI Insight The role requires a high level of technical expertise in GRC automation, scripting, and compliance frameworks, along with project management and cross-functional collaboration, making it challenging but not the hardest.

Salary Analysis

Median Highly Competitive
USD179,000
US Market
USD120k – USD200k
0 USD220k
AI Insight The offered salary range of $144,000 - $214,000 is competitive and above the market median for senior security engineers in the US, reflecting the specialized GRC automation focus and the company's growth stage.

Key Skills

GRC Automation Security Engineering DevSecOps Drata Python Compliance Frameworks API Integration Project Management AI Workflows Audit Readiness

Dear Hiring Manager,

I am excited to apply for the Senior Security Engineer, GRC Automation role at 1Password. With over 6 years of experience in security engineering and DevSecOps, I have a proven track record of building automation that scales compliance operations. At my previous role, I implemented Drata integrations and built AI-assisted workflows for evidence collection, reducing audit preparation time by 40%.

I am particularly drawn to 1Password's mission of balancing productivity and security, and I am confident that my hands-on technical skills and experience with SOC 2 and ISO 27001 align perfectly with your needs. I look forward to the opportunity to contribute to your team and help shape a safer digital future.

Sincerely,
[Your Name]

Describe your experience implementing a GRC platform like Drata or Vanta. What challenges did you face and how did you overcome them?
I led the implementation of Drata at my previous company, integrating it with our cloud infrastructure and SSO provider. The main challenge was mapping existing controls to framework requirements, which we solved by creating a cross-functional team to document and automate evidence collection.
How would you automate evidence collection for SOC 2 controls in a cloud-native environment?
I would use Drata's API along with custom scripts in Python to pull configuration data from AWS, GCP, and our CI/CD pipelines. I'd also set up automated tests to validate controls and generate evidence reports on a scheduled basis.
Can you walk through a time you built an AI-assisted workflow for a compliance problem?
I built a workflow using an LLM to analyze policy documents and map them to NIST 800-53 controls. The system extracted relevant requirements and suggested evidence types, which we validated with manual review. This reduced the initial mapping effort by 50%.
How do you handle stakeholder communication when managing a multi-workstream compliance project?
I establish clear milestones and use a project management tool like Jira to track progress. I hold weekly syncs with stakeholders from security, legal, and infrastructure to address blockers and ensure alignment. I also provide a weekly status report with visual dashboards.
Explain how you would approach integrating a GRC platform with existing security tools like SIEM or vulnerability scanners.
I would first identify the key data points needed for compliance, then use APIs or webhooks to connect the GRC platform with tools like Splunk and Qualys. I'd automate the ingestion of vulnerability scan results and security alerts into the GRC platform for continuous monitoring.

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.

About 1Password

At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.

If you’re excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.

Trust is earned — and we’re building the systems to earn it at scale. 1Password is looking for a Senior Security Engineer – GRC Automation to design and implement automation, dashboards, and integrations that power our Governance, Risk, and Compliance (GRC) operations.

You’ll partner directly with the Senior Manager of GRC to build automation that scales our security and privacy commitments — from audit readiness and policy enforcement to customer trust workflows. A key focus for this role will be operationalizing and expanding our GRC platform (Drata), building AI-assisted workflows that automate evidence collection, control monitoring, and vendor risk — and owning the delivery of those projects from scoping through go-live.

This is a hands-on technical role for someone who’s passionate about making GRC repeatable, visible, and built into how the company works. It sits at the intersection of security engineering, compliance, and platform operations — ideal for someone with a solutions engineering, DevSecOps, or GRC practitioner background who thrives in high-context, high-impact environments. You won’t just build things — you’ll also be in the room with auditors, owning the technical narrative for what you’ve built and why.

This is a remote opportunity within the US or Canada.

What we’re looking for:

  • 5+ years of experience in security engineering, DevSecOps, solutions engineering, or GRC automation roles.

  • Proven experience working with GRC, compliance, or audit teams to build automation that supports evidence collection, control testing, or security monitoring.

  • Direct experience implementing and integrating GRC platforms (e.g., Drata, Vanta, Tines, JupiterOne) into production environments.

  • Strong scripting and integration skills using Python, JavaScript, APIs, webhooks, or workflow automation tools.

  • Ability to work cross-functionally with security, compliance, legal, and infrastructure teams to translate policies into scalable technical systems.

  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53, and how they map to real-world infrastructure and operations.

  • Project management and delivery ownership — experience managing multi-workstream compliance or security projects end-to-end: scoping, milestones, stakeholder communication, and on-time delivery. You can run a project without a PM holding your hand.

  • Experience building AI-assisted workflows — you’ve worked with LLMs, agentic tools, or automation pipelines (beyond click-through tools) to solve a GRC or compliance problem and can walk through what you built, why, and how you validated the output.

  • Confident in auditor-facing settings — you have a commanding presence in technical walkthroughs and can represent your automation work clearly to external auditors, senior stakeholders, and executive audiences. You know the difference between what you built and what it proves.

Bonus points if you have:

  • Hands-on experience with event-driven automation platforms like Tines and their use in control validation and alerting.

  • Expertise in building evidence pipelines, tagging telemetry, or creating GRC dashboards in tools like Looker or Metabase.

  • Strong understanding of cloud-native security architecture and its relationship to compliance controls (e.g., AWS IAM, encryption, logging).

  • Experience working in customer trust, privacy engineering, or supporting sales/GTM teams with compliance assurance content.

  • Familiarity with EU AI Act, NIST AI RMF, or emerging AI governance frameworks — increasingly relevant as 1Password governs access for AI agents alongside human users.

  • CISA, CISSP, or equivalent certification, or actively working toward one.

What you can expect:

  • Lead the implementation and integration of our GRC platform, ensuring it is fully operationalized across key systems and workflows.

  • Build out automated workflows for control testing, evidence collection, and audit readiness.

  • Design and deploy AI-assisted compliance workflows — including agentic evidence collection, LLM-powered vendor questionnaire review, and automated control narrative drafting — with clear validation logic built in.

  • Develop and maintain integrations between the GRC platform and systems of record (e.g., ticketing systems, IAM, asset inventories, configuration management).

  • Manage project delivery across multiple GRC automation initiatives simultaneously — maintaining clear scope, milestones, and stakeholder visibility without sacrificing quality.

  • Design dashboards and reporting to track control health, trust signals, and audit performance.

  • Collaborate with teams across Security, GRC, and Engineering to embed compliance into operational processes like employee onboarding, change management, and incident response.

  • Own the roadmap for automated, resilient internal assurance infrastructure — setting priorities, managing delivery across concurrent workstreams, communicating progress to GRC leadership, and making build vs. buy decisions that scale with the business.

At 1Password, we build with AI:
At 1Password, using AI to do more with less isn’t a bonus — it’s how we operate, and it’s especially central to this role. We expect you to come in and actively build compliance infrastructure with AI, not just use off-the-shelf tools.

  • A proven builder: You’ve built something — an agentic evidence collection workflow, an AI-assisted vendor questionnaire reviewer, an LLM-powered control narrative pipeline — and you can walk through what you built, the choices you made, what you iterated on, and what the measurable impact was.

  • Compliance-as-infrastructure mindset: You think in terms of automation coverage. “What percentage of our control evidence is generated automatically vs. collected manually?” is a question you ask and try to move.

  • AI tradeoff reasoning: You understand where non-deterministic AI is acceptable in compliance workflows (first-pass gap analysis, vendor triage) vs. where deterministic guarantees matter (audit-ready evidence, control conclusions). You build validation steps in — you don’t treat AI output as ground truth.

  • Systems thinking: When you describe an automation you built, you can explain how it changed downstream workflows, not just what it saved on the immediate task.

USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD, plus immediate participation in 1Password’s benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

 

Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

At 1Password, we approach each individual’s compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.

This posting is for an existing vacancy.

Our culture

At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first.

You’ll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone . Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you’re looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We’re looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results.

How we work with AI

We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn’t just encouraged—it’s an essential part of how we will be successful at 1Password.

This approach extends to our hiring process—candidates are welcome to use AI tools responsibly and thoughtfully during the application process.

Our approach to remote work

We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events.

What we offer

We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer:

Health and wellbeing

👶 Maternity and parental leave top-up programs

🩺 Competitive health benefits

🏝 Generous PTO policy

Growth and future

📈 RSU program for most employees

💸 Retirement matching program

🔑 Free 1Password account

Community

🤝 Paid volunteer days

🏆 Peer-to-peer recognition through Bonusly

🌎 Remote-first work environment

*Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.

You belong here.

1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.

Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at [email protected] and we’ll work to meet your needs.

Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we’re experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you’ve got questions or concerns about this, your talent partner would be happy to address them with you.

Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.

1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form. For additional information see our Candidate Privacy Notice.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

How to apply

Did you apply? Let us know, and we’ll help you track your application.

See a few more

Similar Software Engineering remote jobs

Job Search Safety Tips

Here are some tips to help you search and apply for jobs safely:
Watch out for suspicious jobs Don't apply for jobs that offer high pay for little work or offer to hire you without an interview. Read more ›
Check the employer's profile Make sure you're applying for a trustworthy job by visiting the employer's profile and learning more about them. Read more ›
Protect your information Don't share personal details like your bank account or government-issued ID on suspicious websites or messengers. Read more ›
Report jobs that feel unsafe If you see a job that seems misleading, inappropriate or discriminatory, report it for going against our policies and we'll review it.

Share this job

Jobicy+ Subscription

Jobicy

614 professionals pay to access exclusive and experimental features on Jobicy

Free

USD $0/month

For people just getting started

  • • Unlimited applies and searches
  • • Access on web and mobile apps
  • • Weekly job alerts
  • • Access to additional tools like Bookmarks, Applications, and more

Plus

USD $8/month

Everything in Free, and:

  • • Ad-free experience
  • • Daily job alerts
  • • Personal career consultant
  • • AI-powered job advice
Go to account ›