Senior Security Engineer, Application Security
7 days ago
1Password is growing faster than ever. We've surpassed $400M in ARR and we're continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth.
About 1Password
At 1Password, we're building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world's most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.
If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.
We are excited to welcome a Senior Engineer to join our Application Security team at 1Password. Application Security enables 1Password to build and deliver secure products with confidence. We're responsible for the Security Engineering around Product Development - things like Static and Dynamic Application Security Testing, Pentesting, Security AI Tooling, our Bug Bounty Program, Vulnerability Management, and more.
As part of the Application Security team, this Senior Engineer will primarily focus on building and maturing our Vulnerability Management Program, whose mission is to continuously identify, assess, prioritize, and drive remediation of security vulnerabilities across our products, platforms, and infrastructure — ensuring that 1Password maintains the highest standards of trust and safety for our users.
As part of this program, the Senior Security Engineer will:
-
Design, build, integrate and scale new security solutions to power our vulnerability management program.
-
Develop and maintain tools that correlate, enrich, and prioritize security vulnerability findings from multiple data sources.
-
Develop and maintain comprehensive dashboards and reporting metrics around our vulnerability management program, tailored to different audiences (technical, non-technical, compliance, senior leadership, etc.)
-
Conduct detailed analysis used to inform security development teams to eliminate classes of vulnerabilities
-
Partner with product and development teams to improve vulnerability triage workflows, validate findings, and come up with remediation strategies consistent with good user experiences.
-
Contribute to the design of risk-scoring and SLA models that align with business priorities.
-
Mentor other engineers and help shape the evolution of our vulnerability management strategy.
This is a remote opportunity within Canada and the US.
What we're looking for:
-
You have 5+ years of career experience in IT or Engineering with a security focus
-
You have a passion for and strong experience with any of: bug bounty programs, vulnerability research, validation, remediation or pentesting
-
You have experience with internal tool development and engineering enablement
-
You have a strong foundational understanding of software development principles, and are comfortable reading and writing code
-
You work well in a team environment with positive communications amongst a variety of technical and non-technical stakeholders
-
You are comfortable owning and setting technical direction for small to medium sized initiatives
-
You're adaptable and resilient, thriving in fast-paced environments with shifting priorities
Bonus points for:
-
Experience with Rust and/or Golang, or a demonstrated ability to pick up new languages quickly.
-
Experience with popular compliance standards and certifications (e.g. SOC2, ISO, PCI)
-
Experience building or maintaining vulnerability management programs in medium to large sized organizations
USA-based roles only: The annual base salary for this role is between $156,000 USD and $210,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.
Canada-based roles only: The annual base salary for this role is between $143,000 CAD and $193,000 CAD, plus immediate participation in 1Password's generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.
At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.
Our culture
At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first.
You'll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone . Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We're looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results.
We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged at 1Password—it's an essential part of how we will be successful at 1Password.
Our approach to remote work
We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events.
What we offer
We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer:
Health and wellbeing
Maternity and parental leave top-up programs
Competitive health benefits
Generous PTO policy
Growth and future
RSU program for most employees
Retirement matching program
Free 1Password account
Community
Paid volunteer days
Peer-to-peer recognition through Bonusly
Remote-first work environment
*Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.
You belong here.
1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.
Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at and we'll work to meet your needs.
Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you.
Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.
1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form. For additional information see our Candidate Privacy Notice.
-
Staff Security Engineer
1 week ago
Remote - United States, Remote - Canada Paxos Full time US$175,000 - US$250,000 per yearAbout Paxos Today's financial infrastructure is archaic, expensive, inefficient and risky — supporting a system that leaves out more people than it lets in. So we're rebuilding it. We're on a mission to open the world's financial system to everyone by enabling the instant movement of any asset, any time, in a trustworthy way. For over a decade, we've...
-
Security Engineer
2 weeks ago
, , Canada N3XT Full timeSecurity Engineer - Application Security Join to apply for the Security Engineer - Application Security role at N3XT . Liberating Money We're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle...
-
Application Security Engineer
6 hours ago
Canada - Remote Certn Full time US$80,000 - US$120,000 per yearWho We AreAt Certn, we're revolutionizing background screening with The World's Easiest Background Check — fast, global, and powered by tech. We're not about outdated processes and red tape. We're about innovation, speed, and impact. If you're looking for a place where ownership, collaboration, and creativity thrive, this is it.The OpportunityWe're looking...
-
Senior Security Engineer, Application Security
2 weeks ago
, , Canada 1Password Full time1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle, Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we’re building the foundation for a safe, productive digital future....
-
, , Canada 1Password Full timeSenior Security Engineer, Application Security Join to apply for the Senior Security Engineer, Application Security role at 1Password. 1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle, Red...
-
Senior Application Security Engineer
4 weeks ago
, , Canada Webflow Full timeAbout the role: At Webflow, our mission is to bring development superpowers to everyone. As the pioneer of the Website Experience Platform (WXP), we’re redefining how teams Build, Manage, and Optimize for the web — combining visual development, powerful content management systems, AI-driven personalization, seamless hosting, and end-to-end analytics in a...
-
Application Security Engineer
1 week ago
Remote, Canada N3xt Full time $150,000 - $200,000 per yearLiberating MoneyApplication Security EngineerWe are looking for a highly skilled Application Security Engineer to own the security of our software ecosystem. You will not be writing feature code all day; instead, you will be the bridge between security and engineering.We are specifically looking for a "Builder-turned-Breaker". Someone who started their...
-
Senior Security Engineer, Application Security
3 weeks ago
, , Canada GitLab Full timeSenior Security Engineer, Application Security (AMER) Join to apply for the Senior Security Engineer, Application Security (AMER) role at GitLab. GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create...
-
Senior Application Security Engineer
2 days ago
, , Canada Sardine Full timeJoin to apply for the Senior Application Security Engineer role at Sardine . Who We Are We are a leader in fraud prevention and AML compliance. Our platform uses device intelligence, behavior biometrics, machine learning, and AI to stop fraud before it happens. Today, over 300 banks, retailers, and fintechs worldwide use Sardine to stop identity fraud,...
-
Senior Application Security Engineer
4 weeks ago
, , Canada GlossGenius Full timeGlossGenius is building an ecosystem enabling entrepreneurs to succeed. We empower small business owners to focus on being creators, not admins, by offering a range of business management tools including booking and scheduling, marketing, analytics, payment processing and much more. Over 100,000 small business owners have chosen to rely on GlossGenius every...