Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Staff Security Engineer, Detection and Response image - Rise Careers
Job details

Staff Security Engineer, Detection and Response

About 1Password:

We all have important information we need to manage, and protecting it should be easy. Over 150,000 businesses and millions of people log in to 1Password to unlock smart, simple access to everything they care about. Our vision is to create a safer, simpler digital future for everyone, and our culture values simplicity, honesty and a human-centric approach to solving problems. Come help us unlock peace of mind so everyone can stay safer online.


At 1Password, customer privacy and security come first and foremost; this commitment informs everything we do, and the Security Team is responsible for upholding this commitment. We are a passionate team that truly cares about protecting our customers, and we’re looking for new team members that share this passion.


As a Staff Security Engineer on the Detection and Response team, you will be responsible for leading the development and implementation of strategies to detect and respond to security threats across 1Password. You will work closely with cross-functional teams to ensure the continuous improvement of our security posture and the protection of our assets against emerging threats. This role offers the opportunity to make a significant impact in safeguarding our systems and data against cyber threats.


Join us and unleash the excitement of protecting the digital world.


This is a Remote opportunity within Canada and the US.


What we're looking for:
  • Minimum 7 years of experience in a security role with a focus on Detection Engineering, Incident Response, Digital Forensics and/or Threat Intelligence
  • Expertise in designing, building, and fine-tuning systems and processes for detection engineering
  • Expertise in SIEM and SOAR solutions for enhancing behavior analytics and security automations
  • Expertise with Detection-as-Code to automate detection engineering workflows
  • Experience in building logging pipelines for log ingestion into a centralized system
  • Experience leading and collaborating on complex and ambiguous cross-functional projects from design through implementation
  • Experience in leading security incidents to resolution with various incident responders and stakeholders
  • Experience with runtime security, EDR and forensic analysis tools on various operating systems
  • Strong understanding of current threat landscape and threat actor TTPs
  • Experience with threat hunting and log analysis to identify potential security or privacy impacts
  • Experience deploying cloud services (e.g., AWS, GCP) and a strong understanding of cloud security principles
  • Experience in scripting and programming languages (e.g., Python, Bash) for data analysis, automation and tool development
  • Experience with software development lifecycle, project management, Terraform and CI/CD in GitLab or GitHub
  • Excellent communication skills with a drive for collaboration and leveling up team members
  • Passion for fostering psychological safety and stability in high stress environments


What you can expect:
  • Operate as a technical lead to advance the Detection Engineering program
  • Define the team roadmap through collaboration with the manager and Security leaders
  • Establish the scope, timeline, milestones and success criteria for projects, ensuring deliverables are met and in alignment with Security OKRs
  • Build strong relationships with partner and stakeholder teams in order to advise on improvements to detection capabilities and response procedures
  • Manage security incidents through the incident response process from identification to resolution
  • Design and build systems to automate security processes and workflows to improve efficiency and scalability
  • Participate in an on-call rotation with potential for work on nights or weekends in the event a significant security issue is identified
  • Partner with developers, engineers and other departments to improve security logging and address security issues for the product
  • Develop and maintain threat intelligence sources to stay informed about emerging threats and attack vectors
  • Standardize, write and execute response playbooks that can be utilized by all members of the team
  • Mentor and train team members to uphold a high team standard
  • Participate in security audits, vendor assessments and security tabletop exercises
  • Be a subject matter expert on the team’s security tooling, processes and procedures


USA-based roles only: The Annual base salary for this role is between $187,000 USD and $253,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.


Canada-based roles only: The Annual base salary for this role is between $168,000 CAD and $228,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.


At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.


What we offer:


We believe in working hard, and resting hard. We’re always looking for new ways to support our team members, but here’s a glance at what we currently offer:


Health and wellbeing

> 👶 Maternity and parental leave top-up programs

> 👟 Wellness spending account

> 🏝 Generous PTO policy 

> 💖 Company-wide wellness days off scheduled throughout the year 

> 🧠 Wellness Coach membership

> 🩺 Comprehensive health coverage


 Growth and future 

> 📈 Employee stock option program for all full-time employees 

> 💸 Retirement matching program

> 💡 Training budget, 1Password University access, and learning sessions 

> 🔑 Free 1Password account (and friends and family discount!) 


Flexibility and community

> 🤝 Paid volunteer days 

> 🌎 Employee-led DEIB programs and ERGs and ECGs

> 🏠 Fully remote environment

> 🏆 Peer-to-peer recognition through Bonusly


You belong here.


1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.


Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we’ll work to meet your needs.


Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you.


Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.


1Password uses an automated employment decision tool as a part of the recruitment process. See the latest bias audit information. A reasonable accommodation, reasonable alternative selection process, appeal or to exercise your right to opt-out of AADM may be requested by emailing nextbit@agilebits.com with subject "AI accommodation request". For additional information see our Candidate Privacy Notice.

1Password Glassdoor Company Review
4.9 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
1Password DE&I Review
4.8 Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon
CEO of 1Password
1Password CEO photo
Jeff Shiner
Approve of CEO

Average salary estimate

$220000 / YEARLY (est.)
min
max
$187000K
$253000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Staff Security Engineer, Detection and Response, 1Password

At 1Password, we understand that protecting your important information should be both easy and effective. As a Staff Security Engineer focusing on Detection and Response, you'll be on the front lines of safeguarding our customers' data from cyber threats. With over 150,000 businesses relying on 1Password, your expertise will be instrumental in leading the development of strategies aimed at detecting and responding to security threats. You’ll collaborate with enthusiastic cross-functional teams to enhance our security posture and evolve with emerging threats. Your role will not only have you designing and implementing detection systems but also mentoring team members and spearheading incident response processes. Imagine the satisfaction of making a tangible difference in the digital safety of millions! If you have a strong background in security roles, with at least 7 years of experience in detection engineering and incident response, we want to hear from you. You should be well-versed in SIEM, SOAR, automated solutions, and threat intelligence. Embrace the challenge of leading complex projects and enjoy the shared excitement of building a robust security culture at 1Password. As this is a remote position, you’ll have the flexibility to work from wherever you are in Canada or the United States, all while being part of a progressive and inclusive company culture that values wellness, collaboration, and growth. Join us in unlocking peace of mind and safety for everyone in the online world!

Frequently Asked Questions (FAQs) for Staff Security Engineer, Detection and Response Role at 1Password
What are the key responsibilities of a Staff Security Engineer at 1Password?

As a Staff Security Engineer at 1Password, your key responsibilities will include leading the development and implementation of strategies for detecting and responding to security threats, collaborating with cross-functional teams to improve our security posture, managing security incidents, and designing automated systems for security processes. You will also be tasked with mentoring team members and maintaining threat intelligence sources, making significant contributions to the overall security of our product and customer data.

Join Rise to see the full answer
What qualifications are needed for the Staff Security Engineer position at 1Password?

To be considered for the Staff Security Engineer role at 1Password, you should have a minimum of 7 years of experience in security roles focused on detection engineering, incident response, and threat intelligence. Proficiency in SIEM and SOAR solutions, experience with Detection-as-Code, and strong programming skills in languages such as Python are also essential. It's vital that you demonstrate excellent communication skills and a collaborative spirit.

Join Rise to see the full answer
How does 1Password approach security incident management?

At 1Password, the approach to security incident management is thorough and collaborative. Staff Security Engineers, like yourself, will manage incidents through the incident response process, from identification to resolution. This entails working closely with incident responders and stakeholders, establishing clear timelines and scopes, and ensuring that all actions taken align with security objectives and priorities.

Join Rise to see the full answer
What opportunities for growth does 1Password provide to its Staff Security Engineers?

1Password is deeply committed to the professional growth of its staff, including those in the Staff Security Engineer role. Opportunities for growth include access to a training budget, participation in 1Password University, mentoring programs, and the chance to contribute to high-impact projects. The company fosters a culture of collaboration and support, ensuring that each team member can develop their skills and advance in their career.

Join Rise to see the full answer
Is the Staff Security Engineer position at 1Password remote?

Yes, the Staff Security Engineer position at 1Password is fully remote, allowing you to work from anywhere within Canada or the United States. At 1Password, remote work is a core part of our culture, and we have extensive systems in place to ensure that all employees can collaborate effectively, maintain work-life balance, and contribute meaningfully to our mission from the comfort of their own homes.

Join Rise to see the full answer
Common Interview Questions for Staff Security Engineer, Detection and Response
What strategies would you implement to improve detection capabilities at 1Password?

To improve detection capabilities at 1Password, I would analyze the existing SIEM and automation tools, vet the efficacy of current detection rules, and incorporate Detection-as-Code methodologies to streamline workflows. Collaborating with cross-functional teams to ensure access to relevant data for threat hunting would also be essential.

Join Rise to see the full answer
Can you describe your experience with incident response management?

In my previous role, I led multiple incident response teams, managing security incidents from identification to resolution. I ensured clear communication with stakeholders during high-stress situations while utilizing effective playbooks and post-incident reviews to enhance future response strategies.

Join Rise to see the full answer
How do you stay updated with the current threat landscape?

To stay updated with the current threat landscape, I regularly follow industry-leading blogs, engage in forums, and participate in threat intelligence sharing communities. Attending security conferences and workshops also helps me network with peers and learn about emerging tactics and techniques from threat actors.

Join Rise to see the full answer
What programming languages are you proficient in for security automation?

I am proficient in Python and Bash, which I often use for writing automation scripts for data analysis, incident response tasks, and developing custom security tools. My experience with automation helps enhance efficiency and ensure important security processes are executed flawlessly.

Join Rise to see the full answer
How do you handle the pressure of high-stress environments in security?

To handle high-stress environments in security, I focus on establishing clear communication channels with my team, breaking down the incident response process into manageable tasks, and maintaining a calm demeanor. I believe fostering a positive team dynamic encourages collaboration and psychological safety, even in challenging times.

Join Rise to see the full answer
What experience do you have with threat hunting?

I have substantial experience with threat hunting, utilizing various log analysis techniques to identify anomalies and potential threats within our environment. I apply different data sources and threat intelligence to develop proactive investigation hypotheses and improve overall detection capabilities.

Join Rise to see the full answer
How do you prioritize security incidents when multiple arise simultaneously?

Prioritizing security incidents involves assessing the severity, impact, and potential risk associated with each incident. I use established frameworks that categorize incidents based on urgency and potential damage, then allocate resources accordingly to ensure the most critical threats are addressed immediately.

Join Rise to see the full answer
What best practices do you apply to design automated security processes?

When designing automated security processes, I emphasize clear documentation, incorporating feedback loops for continuous improvement, and using Detection-as-Code frameworks. Regular reviews of automation rules and processes ensure they evolve alongside the changing threat landscape.

Join Rise to see the full answer
Can you discuss your experience with cloud security principles?

I have extensive experience with cloud security principles, particularly through hands-on work with AWS and GCP. This includes implementing security controls, managing access permissions, and ensuring compliance with industry standards to protect cloud architectures from various threats.

Join Rise to see the full answer
How do you cultivate collaboration within security teams?

Cultivating collaboration within security teams involves fostering a culture of open communication, support, and knowledge sharing. I regularly initiate brainstorming sessions, encourage team feedback, and mentor less experienced members to create a cohesive, high-functioning unit.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
1Password Remote Remote (US or Canada)
Posted 13 days ago
Dental Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays
Photo of the Rise User
Posted 8 days ago
Dental Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays
Photo of the Rise User
ServiceNow Remote Salarpuria Sattva Knowledge City Knowledge City, Unit II, 17 to 10 Floor Survey No. 83/1, Serilingampally Mandal, Hyderabad, India
Posted 8 days ago
Inclusive & Diverse
Mission Driven
Rise from Within
Diversity of Opinions
Work/Life Harmony
Empathetic
Feedback Forward
Take Risks
Collaboration over Competition
Medical Insurance
Dental Insurance
Vision Insurance
Mental Health Resources
Life insurance
Disability Insurance
Health Savings Account (HSA)
Flexible Spending Account (FSA)
Conferences Stipend
Paid Time-Off
Maternity Leave
Equity
Photo of the Rise User
Posted yesterday
Photo of the Rise User
Netcompany Remote Brussels, Belgium
Posted 8 days ago
Photo of the Rise User
Third Bridge Remote One World Center 1501, 15th Floor, Tower 2A Senapati Bapat Marg, Lower Parel, Mumbai, Maharashtra, India
Posted 4 days ago
Photo of the Rise User
Posted 4 days ago

1Password is a software technology company that streamlines online navigation by memorizing and auto-filling web forms with passwords, credit card details, and addresses at the click of a button.

201 jobs
MATCH
Calculating your matching score...
BADGES
Badge Diversity ChampionBadge Flexible CultureBadge Future MakerBadge Innovator
BENEFITS & PERKS
Dental Insurance
Flexible Spending Account (FSA)
Vision Insurance
Paid Holidays
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
December 4, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!