Senior Security Engineer, Vulnerability Management
Listed on 2026-08-08
-
IT/Tech
Cybersecurity
1
Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.
Password
At 1
Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign‑in is secure, and every device is trusted. We innovated the market‑leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today.
As one of the most loved brands in cybersecurity, we take a human‑centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1
Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.
If you’re excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast‑paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.
We are excited to welcome a Senior Security Engineer to join our Product Security team duct Security helps enable 1
Password to build and deliver secure products with confidence. We own the end‑to‑end security lifecycle across our products, platforms, and infrastructure, including our vulnerability management program, bug bounty program, coordinated disclosure, pentesting, and supply chain security.
As part of this team, the Senior Security Engineer will lead and mature our incident response capabilities, working in close partnership with Engineering, Legal, Communications, and Customer Success to coordinate the company’s response when product security incidents occur. This is a high‑impact role for someone who thrives under pressure, cares deeply about protecting users, and wants to do meaningful work at a company trusted by millions.
Howwe’re using AI today
Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI‑assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI‑generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers.
This is a remote opportunity within Canada and the US.
What we’re looking for:5+ years of career experience in IT or Engineering with a security focus
Hands‑on experience leading or participating in security incident response, ideally in a product or SaaS company context
Experience with coordinated vulnerability disclosure (CVD) and managing relationships with external security researchers
Strong judgment under pressure: you make clear, defensible decisions during time‑sensitive situations with incomplete information
Experience building or formalizing incident response capabilities from the ground up (playbooks, runbooks, severity frameworks, escalation processes)
Experience drafting or contributing to customer security advisories, CVEs, or public‑facing incident communications
Strong communication skills across a wide range of audiences, from engineers to executives to customers
Comfort reading and writing code to support forensic analysis, automation, and tooling
Adaptable and resilient: you thrive in fast‑paced environments where priorities can shift quickly
Experience leveraging AI/ML capabilities to accelerate security workflows, automate repetitive tasks, or improve detection and response
Familiarity with CVSS, EPSS, and vulnerability severity frameworks as they apply to incident prioritization
Experience in a…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).