[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)](https://jobicy.com/company/1password.md)Remote opportunity at[1Password](https://jobicy.com/company/1password.md)

# Manager, Security Incident Response

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/1password.md)Share12 Sep 2026Published47Listing views1Application actions12 Oct 2026Apply before  Opportunity details

## About this role.

AI Summary1Password is hiring a Security Incident Response Manager to lead and develop a team responsible for high-severity incident response, automation, and operational maturity. The role combines people leadership with hands-on technical judgment across cloud-native, SaaS, and identity-focused threats. This leader will own response strategy, improve playbooks and metrics, partner with detection and threat intelligence teams, and act as an incident manager during complex events. The team is expected to scale its capacity through AI-assisted tooling while preserving human approval, auditability, and rollback controls. It is a remote role open to candidates located in the United States or Canada, with periodic travel for in-person engagement.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a senior security leadership role requiring both deep incident-response expertise and the ability to manage people, high-stakes escalations, and a strategic program roadmap. The fast-paced environment, on-call leadership expectations, cross-functional dependencies, and responsibility for AI-enabled operational change make the role highly demanding.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianHighly competitive$235,000US market range$190k–$280k0$308k

AI insightThe disclosed US annual base-salary range is $192,000–$278,000 USD, with a midpoint of $235,000 USD. This aligns with an estimated US market base-pay range of $190,000–$280,000 USD for a senior security incident response manager leading cloud/SaaS response operations; equity and incentive compensation may be additional. A separate Canada-specific annual base range of CAD 171,000–248,000 is also disclosed but is not combined with the USD analysis.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Security incident response](https://jobicy.com/jobs?search_keywords=Security%20incident%20response.md)[Incident management](https://jobicy.com/jobs?search_keywords=Incident%20management.md)[Security operations leadership](https://jobicy.com/jobs?search_keywords=Security%20operations%20leadership.md)[Cloud security](https://jobicy.com/jobs?search_keywords=Cloud%20security.md)[SaaS security](https://jobicy.com/jobs?search_keywords=SaaS%20security.md)[Identity security](https://jobicy.com/jobs?search_keywords=Identity%20security.md)[Threat hunting](https://jobicy.com/jobs?search_keywords=Threat%20hunting.md)[Incident response automation](https://jobicy.com/jobs?search_keywords=Incident%20response%20automation.md)[AI-assisted security workflows](https://jobicy.com/jobs?search_keywords=AI-assisted%20security%20workflows.md)[People management](https://jobicy.com/jobs?search_keywords=People%20management.md)

Sample interview questionsDescribe a complex, high-severity security incident you managed. How did you organize the response and communicate with stakeholders?I established a clear incident command structure, confirmed scope and immediate containment actions, and assigned owners for investigation, remediation, communications, and evidence preservation. I maintained a predictable update cadence tailored to technical teams and executives, documenting facts, decisions, risks, and next steps. After recovery, I led a blameless review that converted findings into prioritized detection, control, and process improvements.

How would you decide where AI-assisted automation is appropriate in an incident response program?

I would begin with repetitive, measurable tasks such as alert enrichment, context gathering, case summarization, and evidence correlation. Any workflow affecting containment, customer impact, or irreversible changes would retain explicit human approval, logging, auditability, and rollback mechanisms. I would validate quality with controlled pilots and metrics such as false-positive reduction, analyst time saved, response time, and decision accuracy.

How do you develop incident responders while maintaining reliable 24/7 operational coverage?

I use a skills matrix, clear role expectations, and development plans that pair responders with increasingly complex ownership opportunities. Rotations, tabletop exercises, mentoring, and structured post-incident reviews build capability without relying on real crises alone. Capacity planning and sustainable on-call practices are essential so development does not create burnout or weaken coverage.

What metrics would you use to evaluate the maturity and effectiveness of an incident response program?

I would track time to detect, triage, contain, remediate, and close, segmented by severity and incident type. I would also measure recurrence, playbook coverage, alert fidelity, investigation quality, automation adoption, and the completion rate of post-incident corrective actions. Metrics should drive decisions and risk reduction rather than reward speed at the expense of sound investigation.

How would you partner with Detection Engineering, Threat Intelligence, and Red Team after an incident exposes a security gap?

I would turn the incident into a shared, evidence-based problem statement that identifies the attack path, missed signals, control gaps, and business impact. Together, we would prioritize durable improvements such as new detections, telemetry, hardening actions, threat hypotheses, and validation exercises. I would assign accountable owners, define success criteria and timelines, and track the work through completion.

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.

About 1Password

At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.

If you’re excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.

As our Manager, Security Incident Response, you are at the center of how 1Password handles the moments that matter most. You will build and lead a team of builders: responders who don’t just work incidents, but engineer the automation, tooling, and systems that make response faster and more scalable over time. You will guide program maturity, scale the team’s capabilities through AI-assisted tooling, reinforce operational excellence, and step in as incident manager during complex, high-severity events. Success in this role blends strong people leadership with technical depth and sound judgment. As part of the Security leadership team, you will shape response strategy, build effective cross-functional partnerships, and help protect a product trusted by millions.

This role reports to the Senior Manager, Threat Operations.

How we’re using AI today

Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers.

This is a remote opportunity within Canada and the US.

What we’re looking for:

• 5+ years in security incident response, with 2+ years as a people manager or technical leader supporting career development and performance management.

• Experience building or scaling incident response automation, tooling, or AI-assisted workflows (triage, enrichment, investigation), with sound judgment about where automation should and shouldn’t make decisions.

• Experience setting clear expectations, defining ownership, delegating work, and measuring outcomes.

• Experience managing high-pressure security incidents with clarity, structure, and calm.

• Strong understanding of cloud-native, SaaS, and identity-driven attack techniques and how to respond to them.

• Strong communication skills, including the ability to explain complex findings, tradeoffs, and recommendations to technical and non-technical audiences.

• Experience breaking down strategic initiatives into projects, coordinating team sprints, and managing work across competing priorities.

• Passion for fostering psychological safety and stability in stressful environments.

Who you are:

• A people-first leader who prioritizes team development, psychological safety, and performance.

• A builder at heart, someone who thinks in systems and automation, not just case queues, and hires and develops engineers with that same instinct.

• Proactive in identifying gaps, inefficiencies, or operational risks and bringing forward actionable solutions, including where AI or automation can close them.

• Effective at driving alignment across teams with differing priorities and perspectives.

• Calm and decisive during high-pressure situations, with the judgment to prioritize effectively and make difficult tradeoffs.

• A clear and transparent communicator who can align teams with differing priorities, surface tradeoffs, and advocate for sound security decisions.

• Motivated by protecting people, data, and the business.

What you can expect:

• Build, lead, and develop a team of incident responders and security builders, setting clear expectations, creating meaningful ownership, and supporting growth.

• Delegate effectively based on team strengths, development goals, capacity, and operational needs while maintaining accountability for outcomes.

• Define and drive the security incident response roadmap and strategic priorities, including maturing agentic incident response, structured threat hunting, and insider risk investigations as sustained, scaled capabilities rather than one-time builds.

• Balance competing priorities across incident response, strategic initiatives, and team development; make tradeoffs clear and push back when timelines, approaches, or requests create unnecessary risk or unsustainable workload.

• Scale team capacity through AI-assisted tooling and automation, maintaining appropriate controls around human judgment, approval, auditability, and rollback.

• Oversee detection, triage, containment, remediation, and post-incident learning, serving as an escalation point and incident manager for complex or high-severity events.

• Partner with Detection Engineering, Cyber Threat Intelligence, Red Team and other teams to improve cross-functional processes and close detection or response gaps identified through investigations.

• Evolve playbooks, training, tabletop exercises, metrics, and reporting to strengthen operational readiness and program maturity.

• Participate in the on-call rotation, serving as the leadership escalation or incident manager during major or complex incidents.

• Track and report on incident trends, operational metrics, and program maturity, including the impact of automation and AI tooling on response time and coverage.

USA-based roles only: The annual base salary for this role is between $192,000 USD and $278,000 USD, plus immediate participation in 1Password’s benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

Canada-based roles only: The annual base salary for this role is between $171,000 CAD and $248,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

At 1Password, we approach each individual’s compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.

This posting is for an existing vacancy.

Our culture
At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first.

You’ll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, [1Password is not for everyone](https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/). Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you’re looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We’re looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results.

How we work with AI
We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn’t just encouraged—it’s an essential part of how we will be successful at 1Password.

This approach extends to our hiring process—candidates are welcome to use AI tools responsibly and thoughtfully during the application process. To us, this means we do ask that you join live interviews without using AI tools so we can get to know how you communicate, solve problems, and collaborate with others.

Our approach to remote work
We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events.

What we offer
We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer:

Health and wellbeing
👶 Maternity and parental leave top-up programs
🩺 Competitive health benefits
🏝 Generous PTO policy

Growth and future
📈 RSU program for most employees
💸 Retirement matching program
🔑 Free 1Password account

Community
🤝 Paid volunteer days
🏆 Peer-to-peer recognition through Bonusly
🌎 Remote-first work environment
*Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.

You belong here.

1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.

Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we’ll work to meet your needs.

Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we’re experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you’ve got questions or concerns about this, your talent partner would be happy to address them with you.

Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.

1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See [here](https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf) for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing [this form](https://jobs.ashbyhq.com/1password/automation-notice). For additional information see our [Candidate Privacy Notice](https://1password.com/files/candidate-privacy-notice.pdf).

Show more

[Apply now >](https://jobicy.com/jobs/153123-manager-security-incident-response.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Sporty Group logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8e6c246a-221.png)
Sporty Group  Sep 12

### [Offensive Security Engineer](https://jobicy.com/jobs/149060-offensive-security-engineer.md)

About the roleMission Strengthen Sporty’s offensive security posture by proactively testing and identifying vulnerabilities across our external perimeter, standalone virtual private servers (VPS), physical office infrastructure, and endpoint defenses. The…

*
![Rithum logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/fe3986d8-221-1.jpeg)
Rithum  Sep 12

### [Staff Information Security Engineer – AI First](https://jobicy.com/jobs/153112-staff-information-security-engineer-ai-first.md)

Rithum™ is the world’s most trusted commerce network, accelerating how brands, suppliers, and retailers work together to deliver seamless e-commerce experiences. We provide an unmatched platform for brands and retailers,…

*
![Liftoff logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/c47aea9f-221.png)
Liftoff  Sep 12

### [Security Engineer, Detection & Response](https://jobicy.com/jobs/153102-security-engineer-detection-response.md)

Liftoff is a leading AI-powered performance marketing platform for the mobile app economy. Our end-to-end technology stack helps app marketers acquire and retain high-value users, while enabling publishers to maximize…

*
![Stripe logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/WRILS-201011073943-272457.png)
Stripe  Sep 11

### [Abuse Research Engineer](https://jobicy.com/jobs/153053-abuse-research-engineer.md)

Who we are About Stripe Stripe is a financial infrastructure platform for businesses. Millions of companies—from the world’s largest enterprises to the most ambitious startups—use Stripe to accept payments, grow…

*
![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)
Ping Identity  Sep 11

### [Cyber Security Engineer II](https://jobicy.com/jobs/153056-cyber-security-engineer-ii.md)

About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just…

*
![Luna Physical Therapy logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/fcb34e841928-221.webp)
Luna Physical Therapy  Sep 11

### [Director , Information Security and IT](https://jobicy.com/jobs/153041-director-information-security-and-it.md)

Luna is seeking a Director of Information Security & IT to lead the strategy, execution, and continuous evolution of the company’s enterprise technology and information security programs. Reporting to the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert Intern – AI Track](https://jobicy.com/jobs/152979-blockchain-security-expert-intern-ai-track.md)

About the Company Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Security Audit Track](https://jobicy.com/jobs/152975-blockchain-security-expert-security-audit-track.md)

About You You’re a self-starter. You believe in tackling the most important problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand that #startuplife…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Sep 10

### [Blockchain Security Expert – Chain Security Evaluation Track](https://jobicy.com/jobs/152970-blockchain-security-expert-chain-security-evaluation-track.md)

About You You’re a self-starter who thrives on tackling the toughest and most meaningful problems, even if they are the most difficult problems. You’re comfortable with the unknown and understand…

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Sep 10

### [SecOps Security Engineer (Staff-level, L6)](https://jobicy.com/jobs/152968-secops-security-engineer-staff-level-l6.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…