Skip to Main Content

Job Title


Senior Security Engineer, Detection and Response


Company : 1Password


Location : Toronto, Ontario


Created : 2026-01-22


Job Type : Full Time


Job Description

Senior Security Engineer, Detection and Response About 1Password: 1Password is building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application signin is secure, and every device is trusted. We innovate the marketleading enterprise password manager and pioneer Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. The Security Operations teams mission is to protect the business by securing the systems, tools, and processes that power how we work. We keep 1Password productive, resilient, and safe through proactive monitoring, rapid response, and continuous improvement of preventative and detective controls. Responsibilities Design, build, and continuously improve threat detections across 1Passwords infrastructure, products, internal tools, and corporate environments. Lead and support security incident response activities, including investigation, containment, remediation, and postincident learning. Apply threat intelligence and knowledge of attacker TTPs to detection development, threat hunting, alert triage, and response prioritization. Collaborate with Security, Infrastructure, and IT teams to improve security visibility, logging quality, and response readiness. Use automation, scripting, and DetectionasCode practices to scale detection and response workflows and improve reliability. Own endtoend security projects aligned with Detection & Response initiatives and broader security strategy. Participate in a shared oncall rotation and support highseverity incidents as needed. Contribute to operational maturity through playbooks, mentoring, tabletop exercises, audits, and crossfunctional initiatives. Who You Are Calm and effective under pressure, with a blameless, datainformed approach to incident response. Operationally minded, with strong judgment and a bias toward action and continuous improvement. Comfortable working across both detection engineering and incident response responsibilities. A collaborative teammate who values clear communication, shared ownership, and psychological safety. Motivated by protecting customers, employees, and the business through practical, highimpact security work. What Were Looking For 5+ years of experience in security technical engineering roles, with 3+ years focused on security operations, detection engineering or incident response. Handson experience with detection engineering and automation, including SIEMs, SOAR platforms, behavior analytics, and DetectionasCode workflows. Strong understanding of modern attacker techniques and how they apply to cloudnative, SaaS, and identitycentric environments. Experience with endpoint, runtime, and forensic tools across multiple operating systems. Knowledge of cloud environments (e.g., AWS, GCP) and security best practices for cloudnative systems. Proficiency with scripting and infrastructure tools (e.g., Python, Bash, Terraform, CI/CD pipelines) to support automation and internal tooling. Strong written and verbal communication skills, with the ability to explain complex security issues to both technical and nontechnical audiences. Salary USAbased roles: $156,000 $210,000 USD plus benefits, equity, and incentive programs. Canadabased roles: CAD143,000 193,000 plus benefits, equity, and incentive programs. Benefits Health and wellbeing: Maternity and parental leave topup programs, competitive health benefits, generous PTO policy. Growth and future: RSU program for most employees, retirement matching program, free 1Password account. Community: Paid volunteer days, peertopeer recognition through Bonusly. Remotefirst work environment. Our Remote Work Policy We are a remotefirst company but require employees to be willing to travel for inperson engagement such as annual offsites, team meetings, and industry events. Equal Opportunity Employer 1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse, and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken, or veteran status. Be yourself, find your people and share the things you love. Accommodation Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at [email protected] and well work to meet your needs. Background Check Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law. AI & Recruitment 1Password uses artificial intelligence (AI) and machine learning (ML) technologies to assist in the initial screening of employment applications and improve our recruitment process. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form. For additional information, see our Candidate Privacy Notice. #J-18808-Ljbffr