1password - Senior Security Engineer, GRC Automation
Upload My Resume
Drop here or click to browse · Tap to choose · PDF, DOCX, DOC, RTF, TXT
Requirements
• 5+ years of experience in security engineering, DevSecOps, solutions engineering, or GRC automation roles. • Proven experience working with GRC, compliance, or audit teams to build automation that supports evidence collection, control testing, or security monitoring. • Direct experience implementing and integrating GRC platforms (e.g., Drata, Vanta, Tines, JupiterOne) into production environments. • Strong scripting and integration skills using Python, JavaScript, APIs, webhooks, or workflow automation tools. • Ability to work cross-functionally with security, compliance, legal, and infrastructure teams to translate policies into scalable technical systems. • Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53, and how they map to real-world infrastructure and operations. • Project management and delivery ownership — experience managing multi-workstream compliance or security projects end-to-end: scoping, milestones, stakeholder communication, and on-time delivery. You can run a project without a PM holding your hand. • Experience building AI-assisted workflows — you've worked with LLMs, agentic tools, or automation pipelines (beyond click-through tools) to solve a GRC or compliance problem and can walk through what you built, why, and how you validated the output. • Confident in auditor-facing settings — you have a commanding presence in technical walkthroughs and can represent your automation work clearly to external auditors, senior stakeholders, and executive audiences. You know the difference between what you built and what it proves. • Hands-on experience with event-driven automation platforms like Tines and their use in control validation and alerting. • Expertise in building evidence pipelines, tagging telemetry, or creating GRC dashboards in tools like Looker or Metabase. • Strong understanding of cloud-native security architecture and its relationship to compliance controls (e.g., AWS IAM, encryption, logging). • Experience working in customer trust, privacy engineering, or supporting sales/GTM teams with compliance assurance content. • Familiarity with EU AI Act, NIST AI RMF, or emerging AI governance frameworks — increasingly relevant as 1Password governs access for AI agents alongside human users. • CISA, CISSP, or equivalent certification, or actively working toward one. • What you can expect: • Lead the implementation and integration of our GRC platform, ensuring it is fully operationalized across key systems and workflows. • Build out automated workflows for control testing, evidence collection, and audit readiness. • Design and deploy AI-assisted compliance workflows — including agentic evidence collection, LLM-powered vendor questionnaire review, and automated control narrative drafting — with clear validation logic built in. • Develop and maintain integrations between the GRC platform and systems of record (e.g., ticketing systems, IAM, asset inventories, configuration management). • Manage project delivery across multiple GRC automation initiatives simultaneously — maintaining clear scope, milestones, and stakeholder visibility without sacrificing quality. • Design dashboards and reporting to track control health, trust signals, and audit performance. • Collaborate with teams across Security, GRC, and Engineering to embed compliance into operational processes like employee onboarding, change management, and incident response. • Own the roadmap for automated, resilient internal assurance infrastructure — setting priorities, managing delivery across concurrent workstreams, communicating progress to GRC leadership, and making build vs. buy decisions that scale with the business. • At 1Password, we build with AI: • At 1Password, using AI to do more with less isn't a bonus — it's how we operate, and it's especially central to this role. We expect you to come in and actively build compliance infrastructure with AI, not just use off-the-shelf tools. • A proven builder: You've built something — an agentic evidence collection workflow, an AI-assisted vendor questionnaire reviewer, an LLM-powered control narrative pipeline — and you can walk through what you built, the choices you made, what you iterated on, and what the measurable impact was. • Compliance-as-infrastructure mindset: You think in terms of automation coverage. "What percentage of our control evidence is generated automatically vs. collected manually?" is a question you ask and try to move. • AI tradeoff reasoning: You understand where non-deterministic AI is acceptable in compliance workflows (first-pass gap analysis, vendor triage) vs. where deterministic guarantees matter (audit-ready evidence, control conclusions). You build validation steps in — you don't treat AI output as ground truth. • Systems thinking: When you describe an automation you built, you can explain how it changed downstream workflows, not just what it saved on the immediate task. • USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. • Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. • At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. • This posting is for an existing vacancy. • At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first. • You’ll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We’re looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results. • How we work with AI • We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged—it's an essential part of how we will be successful at 1Password. • This approach extends to our hiring process—candidates are welcome to use AI tools responsibly and thoughtfully during the application process. • Our approach to remote work
Benefits
• We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: • Health and wellbeing • 👶 Maternity and parental leave top-up programs • 🏝 Generous PTO policy • Growth and future • 📈 RSU program for most employees • 💸 Retirement matching program • 🔑 Free 1Password account • 🤝 Paid volunteer days • 🏆 Peer-to-peer recognition through Bonusly • 🌎 Remote-first work environment • Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting. • You belong here.
No credit card. Takes 10 seconds.