[![Image]() Meet Jobicy Copilot — free AI autofill for job applications + remote job alerts ›](#)   [All remote jobs](https://jobicy.com/jobs.md)Open role[![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)](https://jobicy.com/company/1password.md)Remote opportunity at[1Password](https://jobicy.com/company/1password.md)

# Senior Security Engineer, Incident Response

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/1password.md)Share20 Sep 2026Published35Listing views3Application actions20 Oct 2026Apply before  Opportunity details

## About this role.

AI SummaryThis senior cybersecurity role leads complex incident response investigations across a cloud-native/SaaS environment while improving the operational systems that support response. The engineer owns incidents from initial detection through containment, recovery, root-cause analysis, and post-incident review. Core work includes threat hunting, incident coordination, security automation, orchestration, playbook development, and AI-assisted triage and investigation workflows. The role requires at least five years of incident response experience, strong scripting ability, executive-ready communication, and calm judgment during high-severity events.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThe position combines senior-level incident command with hands-on engineering, threat investigation, automation, and cross-functional coordination in high-pressure situations. Success depends on independent technical judgment, rapid decision-making, and the ability to communicate risk and actions to both technical teams and executives.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$183,500US market range$150k–$220k0$242k

AI insightThe disclosed US annual base-salary range is $153,000–$214,000 USD, with a midpoint of $183,500 USD. This sits within the estimated US market range of $150,000–$220,000 USD annually for a senior security incident-response engineer with cloud/SaaS investigation, automation, and incident-leadership responsibilities; equity and incentive programs are additional and are not included in the base-salary calculation.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Incident Response](https://jobicy.com/jobs?search_keywords=Incident%20Response.md)[Security Engineering](https://jobicy.com/jobs?search_keywords=Security%20Engineering.md)[Threat Hunting](https://jobicy.com/jobs?search_keywords=Threat%20Hunting.md)[Cloud Security](https://jobicy.com/jobs?search_keywords=Cloud%20Security.md)[SaaS Security](https://jobicy.com/jobs?search_keywords=SaaS%20Security.md)[Security Automation](https://jobicy.com/jobs?search_keywords=Security%20Automation.md)[Python](https://jobicy.com/jobs?search_keywords=Python.md)[Go](https://jobicy.com/jobs?search_keywords=Go.md)[Bash](https://jobicy.com/jobs?search_keywords=Bash.md)[Incident Management](https://jobicy.com/jobs?search_keywords=Incident%20Management.md)

Sample interview questionsDescribe a complex security incident you led from detection through recovery.I would explain the initial signal, how I assessed severity and declared the incident, and how I established an incident command structure. I would cover containment decisions, evidence collection, stakeholder updates, recovery validation, and the post-incident actions that prevented recurrence.

How would you investigate suspected credential compromise in a cloud-native SaaS environment?

I would first validate the alert and preserve relevant identity, endpoint, cloud audit, application, and network telemetry. I would scope affected identities and resources, look for anomalous authentication and privilege activity, contain confirmed access through credential revocation or session controls, and document evidence and decisions throughout the investigation.

Give an example of automation you would build to improve security incident response.

I would prioritize a workflow that enriches alerts with identity, asset criticality, recent activity, threat intelligence, and ownership data through APIs. The automation should reduce repetitive triage, create consistent case records, retain analyst approval for consequential actions, and measure improvements in time to triage and containment.

How do you communicate during a high-severity incident when facts are incomplete?

I provide concise, time-bound updates that clearly distinguish confirmed facts, working hypotheses, business impact, actions underway, owners, and next update time. I avoid speculation, communicate uncertainty directly, and tailor technical detail for responders while giving leaders a clear view of risk and decisions required.

How would you apply AI-assisted tooling to incident response without reducing accuracy?

I would use AI for bounded tasks such as alert summarization, enrichment suggestions, evidence correlation, and draft case documentation, with human review for investigative conclusions and response actions. I would validate outputs against source telemetry, protect sensitive data, monitor quality, and maintain auditable workflows and fallback procedures.

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.

About 1Password

At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.

If you’re excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.

At 1Password, security isn’t just a feature – it’s our foundation. The Security Operations team’s mission is to protect the business by securing the systems, tools, and processes that power how we work. Our mission is to keep 1Password productive, resilient, and safe through proactive monitoring, rapid response, and continuous improvement of preventative and detective controls.

As a Senior Security Engineer on the Incident Response team, you will lead complex security investigations while also building the systems and automation that make response faster, more reliable, and more scalable.

This role blends deep investigative expertise, hands-on engineering, and structured incident coordination. You will drive incidents end-to-end, build automation and workflows that reduce response friction, and contribute to a culture of learning and psychological safety during high-pressure situations.

This is a high-impact role with meaningful ownership across both incident execution and operational engineering.

This role reports to the Manager of Security Incident Response.

How we’re using AI today

Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers.

This is a remote opportunity within Canada and the US.

What we’re looking for:

*

An experienced incident lead who can independently drive complex investigations and coordinate diverse stakeholders.

*

A builder who enjoys improving systems, automation, and workflows – not just responding to alerts.

*

Calm and decisive under pressure, with strong judgment in ambiguous or high-severity situations.

*

Structured and organized, with strong project management skills to own complex projects

*

A clear communicator who can translate technical findings into actionable guidance for both technical and non-technical audiences.

*

A collaborative teammate who values blameless learning and psychological safety

*

5+ years of experience in security incident response roles, with 3+ years focused on security engineering and automation.

*

Proven experience leading complex security incidents in cloud-native or SaaS environments.

*

Experience building automation or internal tooling to improve security operations.

*

Proficiency in scripting or programming (e.g., Python, Go, Bash) and working with APIs or orchestration platforms.

*

Familiarity with applying AI/ML-assisted workflows to operational security use cases.

*

Strong understanding of modern attacker techniques and incident response methodologies.

*

Strong written and verbal communication skills, including executive-facing summaries.

What you can expect:

*

Lead and execute security incidents end-to-end, from initial signal through containment, recovery, and post-incident review

*

Assess severity, declare incidents, and drive structured coordination and decision-making during active response

*

Perform hands-on investigations and threat hunting to determine root cause, attacker behavior, scope, and impact

*

Design and build automation to reduce triage, investigation, and response time

*

Develop scalable systems and workflows that improve incident response and incident management

*

Identify recurring pain points and detection/response gaps, and implement durable engineering solutions

*

Improve incident response playbooks, case management, and orchestration tooling

*

Apply AI-assisted tooling to enhance triage, enrichment, and investigative workflows while maintaining accuracy

USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD plus immediate participation in 1Password’s benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

At 1Password, we approach each individual’s compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.

Our culture

At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first.

You’ll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you’re looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We’re looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results.

How we work with AI

We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn’t just encouraged—it’s an essential part of how we will be successful at 1Password.

This approach extends to our hiring process—candidates are welcome to use AI tools responsibly and thoughtfully during the application process. To us, this means we do ask that you join live interviews without using AI tools so we can get to know how you communicate, solve problems, and collaborate with others.

Our approach to remote work

We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events.

What we offer

We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer:

Health and wellbeing

👶 Maternity and parental leave top-up programs

🏝 Generous PTO policy

💖 Four company-wide wellness days

Growth and future

📈 Company equity for all full-time employees

💸 Retirement matching program

🔑 Free 1Password account

Community

🤝 Paid volunteer days

🌎 Employee-led inclusion and belonging programs and ERGs

🏆 Peer-to-peer recognition through Bonusly

You belong here.

1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.

Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we’ll work to meet your needs.

Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we’re experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you’ve got questions or concerns about this, your talent partner would be happy to address them with you.

Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.

1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See [here](https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf) for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing [this form](https://jobs.ashbyhq.com/1password/automation-notice). For additional information see our [Candidate Privacy Notice](https://1password.com/files/candidate-privacy-notice.pdf).

Show more

[Apply now >](https://jobicy.com/jobs/153700-senior-security-engineer-incident-response.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Fastly logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/10/127f9e4bbbdb8767bef358a23bf7f73d.jpeg)
Fastly  Sep 20

### [Senior Security Technical Account Manager](https://jobicy.com/jobs/153750-senior-security-technical-account-manager.md)

Fastly helps people stay better connected with the things they love. Fastly’s edge cloud platform enables customers to create great digital experiences quickly, securely, and reliably by processing, serving, and…

*
![SkySlope logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/1e0d9f0517a4959cdef118a420f873a6.jpeg)
SkySlope  Sep 20

### [Security Engineering Manager](https://jobicy.com/jobs/153718-security-engineering-manager.md)

OUR ORIGIN STORY 🎂 In 2011 SkySlope started as an idea born at the kitchen table of our CEO, with just him and two others. Headquartered in Sacramento, California, we…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 20

### [Security Engineer, Insider Threat Detection & Response](https://jobicy.com/jobs/153709-security-engineer-insider-threat-detection-response.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 20

### [Senior Technical Program Manager – Security](https://jobicy.com/jobs/151221-senior-technical-program-manager-security.md)

About the Team OpenAI builds powerful AI systems like ChatGPT, the OpenAI API, and enterprise products that serve millions of users across the globe. As we scale, securing our infrastructure,…

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI  Sep 20

### [Software Engineer, Security Observability](https://jobicy.com/jobs/151224-software-engineer-security-observability.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![Synthesia logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/c69aad11-221.webp)
Synthesia  Sep 20

### [Application Security Engineering Manager](https://jobicy.com/jobs/146803-application-security-engineering-manager.md)

Synthesia is the world’s leading AI video platform for business, used by over 90% of the Fortune 100. Founded in 2017, the company is headquartered in London, with offices and…

*
![Roboflow logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/8cd75e4b-221.webp)
Roboflow  Sep 19

### [Security Engineer](https://jobicy.com/jobs/153639-security-engineer-2.md)

Who We Are Our mission is to make the world programmable. Sight is one of the key ways we understand the world, and soon this will be true for the…

*
![Ping Identity logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/09/63e8d5a6-221.png)
Ping Identity  Sep 19

### [Demo Engineering Business Analyst](https://jobicy.com/jobs/153623-demo-engineering-business-analyst.md)

About Ping Identity: At Ping Identity, we believe in making digital experiences both secure and seamless for all users, without compromise. We call this digital freedom. And it’s not just…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius  Sep 18

### [Offensive Security Lead](https://jobicy.com/jobs/149365-offensive-security-lead.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius  Sep 18

### [Vulnerability Operation Center Lead](https://jobicy.com/jobs/149362-vulnerability-operation-center-lead.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…