Security Engineer, DevSecOps; Corporate Security
Listed on 2026-06-04
-
IT/Tech
Cybersecurity, Security Manager
Location: Boise City
About 1
Password
At 1
Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market‑leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today.
Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1
Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.
We are looking for a Staff Security Engineer to found and lead the Dev Sec Ops function within our Corporate Security team. This role works closely with Infrastructure Security and operates at a scope that touches every team that ships code.
This role sits within Corporate Security and reports to the Manager of Corporate Security. This is a remote opportunity within Canada and the US.
What we are looking for- Minimum of 8 years of combined experience in security engineering, Dev Sec Ops , platform security, or closely related engineering roles, with deep focus on securing developer environments, CI/CD, or software supply chains.
- Deep, hands‑on expertise in Git Hub Enterprise security and governance, including branch protections, secret scanning, access controls, repository standards, Actions security, and audit logging at scale.
- Proven ability to design and implement security controls that integrate into CI/CD pipelines without meaningfully degrading developer velocity. Experience with Git Hub Actions and familiarity with how pipeline security scales across a large engineering organization.
- Solid understanding of software supply chain security within developer environments, including dependency hygiene (npm, pip, and similar), token and secret management, secure package consumption practices, and SBOM generation.
- Practical experience solving security challenges introduced by AI‑assisted and agentic development. Evidence of engaging seriously with the problem: making calls about governing AI coding tools in a production environment, defining policy and technical controls for tools like Copilot, Cursor, or Claude Code.
- Comfortable making architectural decisions that span multiple teams. Setting standards and patterns that others adopt; designing scalable, reusable security controls that prevent entire classes of future problems.
- Strong scripting and automation skills in Python, Bash, Terraform, or similar, with demonstrated ability to build tooling that scales security controls without proportional manual effort.
- Ability to build alignment with Platform Engineering and other stakeholders, translate security requirements into developer‑friendly implementations, and influence engineering‑wide standards without direct authority.
- A track record of elevating the people around you through mentorship, documentation, and deliberately creating growth opportunities for other engineers.
- Experience participating in on‑call rotations and contributing to investigations involving developer tooling, source control, or credential exposure.
- Own the Dev Sec Ops function:
Build and lead a well‑run, owned developer security program the technical direction, define the operating model, and drive it with a counterpart in Infrastructure Security. - Own Git Hub and CI/CD security:
Lead the program to harden 1
Password’s Git Hub Enterprise environment and CI/CD pipelines, including governance frameworks, repository standards, Actions security, audit visibility, and secure defaults. - Define AI‑assisted development security:
Own the security model for AI coding tools and agentic workflows, building guardrails, governance standards, and ensuring compliance with risk and policy requirements. - Harden the software supply chain:
Drive improvements to dependency hygiene, secret management practices, token governance, and secure package consumption across engineering. Design controls that scale with minimal friction. - Set standards that engineering teams actually use:
B…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).