[All remote jobs](https://jobicy.com/jobs.md)[![1Password logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200909195848-296323.png)](https://jobicy.com/company/1password.md)[1Password](https://jobicy.com/company/1password.md)

# Senior Developer (Windows), Product Security

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/1password.md)ShareRemote from[USA](https://jobicy.com/job-region/usa.md), [Canada](https://jobicy.com/job-region/canada.md)SalaryUSD 153k–214k / yrDepartment[Cybersecurity](https://jobicy.com/categories/cybersecurity.md)EmploymentFull TimeExperienceSeniorPublished2 Oct 2026Apply before1 Nov 2026Listing views25Application actions2Application toolkit

## Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

## The role, at a glance.

This is a senior product-security engineering role focused on delivering and maintaining security-critical capabilities in 1Password’s Windows application ecosystem. The developer will build secure features and shared libraries, resolve vulnerabilities, guide teams on secure coding, and contribute to security design and operational practices. Strong Windows security expertise is required, including Rust, FFI, OS architecture, TPM/HSM concepts, and features such as Windows Hello, BitLocker, Secure Boot, and Credential Guard. The role also requires cross-functional communication, technical leadership, code review, mentoring, and comfort operating in a fast-paced remote-first environment across Canada and the United States.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

5/5RelaxedFast-paced

### Autonomy Level

4/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThe role requires deep, specialized expertise across Windows platform security, cryptography/authentication, Rust FFI, and production secure-software engineering. It also carries leadership expectations, vulnerability-response responsibilities, and the need to translate nuanced security risks for diverse stakeholders.

## Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate$183,500US market range$150k–$225k0$248k

AI insightFor the US-based version of this role, the disclosed annual base-salary range is $153,000–$214,000 USD, producing a midpoint of $183,500 USD. This compares competitively with an estimated US market range of $150,000–$225,000 USD for a senior Windows-focused product security engineer; actual total compensation may be higher because the posting also mentions equity and applicable incentive programs. A separate Canadian annual base-salary range is disclosed in CAD and is not combined with the USD figures.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Windows security](https://jobicy.com/jobs?search_keywords=Windows%20security.md)[Product security](https://jobicy.com/jobs?search_keywords=Product%20security.md)[Rust](https://jobicy.com/jobs?search_keywords=Rust.md)[C/C++](https://jobicy.com/jobs?search_keywords=CC%2B%2B.md)[C#](https://jobicy.com/jobs?search_keywords=C%23.md)[FFI development](https://jobicy.com/jobs?search_keywords=FFI%20development.md)[Cryptography](https://jobicy.com/jobs?search_keywords=Cryptography.md)[Authentication protocols](https://jobicy.com/jobs?search_keywords=Authentication%20protocols.md)[TPM and HSM](https://jobicy.com/jobs?search_keywords=TPM%20and%20HSM.md)[Secure coding](https://jobicy.com/jobs?search_keywords=Secure%20coding.md)

Sample interview questionsDescribe a Windows security feature you implemented or integrated, and how you assessed its threat model.I would identify the protected assets, trust boundaries, attacker capabilities, and likely misuse paths before implementation. For example, when integrating a hardware-backed credential flow, I would validate key storage and access policies, define secure fallback behavior, test privilege-boundary failures, and document residual risks for reviewers and stakeholders.

How would you design a Rust FFI boundary for a Windows-specific security component?

I would keep the FFI surface minimal, use stable C-compatible types, explicitly define ownership and lifetime rules, and avoid passing Rust-managed objects across the boundary. I would convert errors into well-defined status codes or structured error objects, validate all external inputs, prevent panics from crossing the boundary, and add integration, fuzz, and memory-safety tests.

What considerations matter when using TPM or HSM-backed keys in a desktop application?

Important considerations include key lifecycle, attestation where applicable, exportability restrictions, user and device binding, recovery paths, algorithm support, and handling devices without the expected hardware capability. I would also ensure that application logic does not mistake hardware-backed storage for complete protection and would account for malware, compromised user sessions, and authorization-policy weaknesses.

How do you handle a newly reported vulnerability in a production application?

I start by validating reproducibility, severity, exploitability, affected versions, and exposure. I coordinate containment and remediation, create a tested fix with appropriate review, plan release and customer communication with the security response process, and complete a retrospective that addresses root cause, detection gaps, and preventive engineering controls.

How would you help a product team adopt secure coding practices without becoming a delivery bottleneck?

I would engage early in design reviews, provide reusable security patterns and libraries, automate checks in CI/CD, and prioritize guidance based on risk. Clear documentation, actionable code-review feedback, lightweight threat modeling, and office hours help teams make secure decisions independently while escalating only the highest-risk issues.

Opportunity details

## About this role.

1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.

About 1Password

At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.

If you’re excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.

Security and data privacy are at the core of everything we do at 1Password. The Product Security Team is responsible for implementing new security features across our macOS, iOS, Android, Windows, Linux and Web applications as well as building libraries to share common security-critical code, resolving security vulnerabilities across our applications, and promoting secure coding practices across the organization.

As a Senior Developer on our Device Security squad, you will play a key role in implementing the next generation of security features in our applications, and help shape our security operations and best practices. You’ll be intimately involved in ensuring secure coding practices across our code-base, guiding product teams on best practices, resolving security vulnerabilities in our products when they arise, and demonstrating leadership in the area of secure coding and development.

How we’re using AI today

Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers.

This is a remote opportunity within Canada and the US.

What we’re looking for:

*

4+ years of experience in software development with a security angle; development experience with modern encryption techniques and libraries or authentication protocols

*

4+ years of hands-on experience with Windows security development with technical expertise in languages such as Rust, C#, C/C++, Go or TypeScript

*

Experience with Rust development and creating FFI interfaces, especially for Windows. Knowledge of Windows OS architecture and platform-specific optimization techniques

*

Familiarity with TPM and HSM functionality with proven experience in Windows security features such as Windows Hello, BitLocker, Secure Boot, and Credential Guard

*

A strong understanding of and passion for the security domain; that could include understanding of topics in the sub-domains of cryptography, network security, application security, common threat vectors, and access control mechanisms etc.

*

Excellent written and verbal communication skills; our security team often communicates nuanced topics to a variety of internal audiences, and has to understand these nuances during the design phase

*

You’re a self starter with strong organizational skills who enjoys solving moderately complex problems with a demonstrated ability to tackle problems and propose effective solutions

*

Knowledge of and practical experience with Agentic AI Model capabilities and workflows

Bonus points:

*

Experience with SAML, OAuth and OpenID Connect

*

Experience working on a SaaS product

*

Leadership experience as a software developer in a team environment

*

Experience with GitHub or GitLab as well as CI/CD pipelines

*

Experience with system analysis and performance monitoring tools such as DataDog, SemGrep, Sonarqube, Fortify etc.

*

Personal experience using 1Password

What you can expect:

*

Work within a small team of developers who are specialists in Rust, Go, Swift, and Security Development

*

Implement new security features for the next generation of 1Password and develop secure libraries to share common security-critical code across our applications

*

Assist in security design efforts or scoping initiatives for new features by identifying major tasks and breaking down, estimating, and planning work

*

Demonstrate leadership in security development and act as a trusted point of contact for management and other developers

*

Code, test, debug, deliver and maintain production software systems for new and existing product features

*

Collaborate with a variety of teams across our hybrid core architecture from Design to QA, as well as security engineering for design guidance and secure coding practices

*

Work with your teammates to communicate technical requirements to stakeholders and solve technical problems in a scalable and realistic way

*

Mentor junior and new team members by helping them understand team expectations, providing technical guidance, sharing knowledge, and engaging in pair programming sessions

*

Review code for others to maintain high code quality, knowledge share within the team, and support creating a safe environment of giving and receiving feedback

*

Stay informed about the latest industry trends, technologies, and best practices in security development

USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD, plus immediate participation in 1Password’s benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

At 1Password, we approach each individual’s compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.

This posting is for an existing vacancy.

Our culture
At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first.

You’ll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, [1Password is not for everyone](https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/). Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you’re looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We’re looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results.

How we work with AI
We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn’t just encouraged—it’s an essential part of how we will be successful at 1Password.

This approach extends to our hiring process—candidates are welcome to use AI tools responsibly and thoughtfully during the application process.

Our approach to remote work
We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events.

What we offer
We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer:

Health and wellbeing
👶 Maternity and parental leave top-up programs
🩺 Competitive health benefits
🏝 Generous PTO policy

Growth and future
📈 RSU program for most employees
💸 Retirement matching program
🔑 Free 1Password account

Community
🤝 Paid volunteer days
🏆 Peer-to-peer recognition through Bonusly
🌎 Remote-first work environment
*Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.

You belong here.

1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.

Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we’ll work to meet your needs.

Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we’re experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you’ve got questions or concerns about this, your talent partner would be happy to address them with you.

Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.

1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See [here](https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf) for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing [this form](https://jobs.ashbyhq.com/1password/automation-notice). For additional information see our [Candidate Privacy Notice](https://1password.com/files/candidate-privacy-notice.pdf).

Show more

[Apply now >](https://jobicy.com/jobs/154432-senior-developer-windows-product-security.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

*
![Nebius logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/06/d90c0566-221.webp)
Nebius Oct 2  New

### [Cloud Workplace Engineer](https://jobicy.com/jobs/154423-cloud-workplace-engineer.md)

About Nebius: Nebius is leading a new era in cloud infrastructure for the global AI economy. We are building a full-stack AI cloud platform that supports developers and enterprises from…

*
![Keyfactor, Inc. logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/ba8ae349-221.png)
Keyfactor, Inc. Oct 2  New

### [Information Security Engineer](https://jobicy.com/jobs/152303-information-security-engineer.md)

About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure for AI and machines, helping the world’s largest enterprises…

*
![TRM Labs logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/34aa038c-221.png)
TRM Labs Oct 1  New

### [Senior All-Source Intelligence Analyst](https://jobicy.com/jobs/154320-senior-all-source-intelligence-analyst.md)

Build a Safer World. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build…

*
![Reddit logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/10/Reddit.jpg)
Reddit Oct 1  New

### [Staff Product Security Engineer](https://jobicy.com/jobs/152256-staff-product-security-engineer.md)

Reddit is a community of communities. It’s built on shared interests, passion, and trust, and is home to the most open and authentic conversations on the internet. Every day, Reddit…

*
![Apollo.io logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/f3c639242c4d1f4cb9c0730ac3842a72.jpeg)
Apollo.io Oct 1  New

### [Senior Application Security Engineer](https://jobicy.com/jobs/152253-senior-application-security-engineer-2.md)

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world’s largest enterprises….

*
![Maven Clinic logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2026/07/c4b2d5ecf34b-221.webp)
Maven Clinic Oct 1  New

### [Staff Software Engineer – Product Security](https://jobicy.com/jobs/152250-staff-software-engineer-product-security.md)

Maven Clinic is the world’s largest virtual clinic for women and families on a mission to make healthcare work for all of us. Through Maven Enterprise, the company partners with…

*
![TRM Labs logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/34aa038c-221.png)
TRM Labs Oct 1  New

### [Staff Cyber Threat Intelligence Analyst](https://jobicy.com/jobs/152155-staff-cyber-threat-intelligence-analyst.md)

Build a Safer World. TRM Labs provides AI-powered intelligence solutions that help public and private sector agencies investigate and disrupt crime. TRM’s platforms enable investigators to trace illicit activity, build…

*
![YipitData logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/e1bee9df-221.jpg)
YipitData Oct 1  New

### [Product Security Engineer](https://jobicy.com/jobs/152175-product-security-engineer.md)

About Us: YipitData is the leading market research and analytics firm for the disruptive economy and most recently raised $475M from The Carlyle Group at a valuation of over $1B….

*
![OpenAI logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2023/03/0523b13262b12c215d8009938f5c14f1.jpeg)
OpenAI Sep 30

### [Software Engineer, Infrastructure Security](https://jobicy.com/jobs/152102-software-engineer-infrastructure-security.md)

About the Team Security is at the foundation of OpenAI’s mission to ensure that artificial general intelligence benefits all of humanity. The Security team protects OpenAI’s technology, people, and products….

*
![Quora logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2020/09/WRILS-200916172339-629302.jpg)
Quora Sep 29

### [Detection & CorpSec Engineer](https://jobicy.com/jobs/151966-detection-corpsec-engineer.md)

[Quora is a privately held, “remote-first” company. This position can be performed remotely from anywhere in Canada or the United States. Please visit careers.quora.com/eligible-countries for details regarding employment eligibility by…

[Browse all jobs](https://jobicy.com/jobs.md)