Job Closed

This listing is no longer active.

1Password logo
1Password

Productive businesses use 1Password to secure employees at scale.

Principal Security Researcher

Security EngineerSecurity EngineerOtherRemoteLeadTeam 501-1,000Since 2009H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

108 days ago

Salary

$246K - $369K / year

Seniority

Lead

Bachelor Degree8 yrs expEnglishJavaScriptLinuxmacOSPythonRubyRustTypeScript

Job Description

Principal Security Researcher

1Password

• Deep Vulnerability Research: Lead original research into the most complex and high-impact vulnerability classes affecting 1Password’s products and the broader identity security ecosystem. Discover novel attack surfaces, develop advanced exploit chains, and pioneer new classes of findings that expand the industry’s understanding of risk. • Advanced Exploit Development & Attack Research: Design and develop sophisticated threat models, attack chains, and proof-of-concept exploits that demonstrate real-world risk at the highest level of complexity. Provide authoritative technical evidence that drives prioritization and remediation across 1Password’s product portfolio. • AI & Agentic Security Strategy: Lead research into the security implications of AI in identity systems, including prompt injection, data poisoning, adversarial attacks on AI-driven access decisions, and the systemic risks introduced by agentic architectures interacting with privileged access management (PAM); Your work will help shape 1Password’s strategic position on AI security. • Technical Publications & Thought Leadership: Author high-quality research publications, white papers, blog posts, and technical advisories. Present findings through podcasts, webinars, and/or major security conferences that contribute to 1Password’s reputation as a thought leader in identity security. • Standards Leadership: Represent 1Password in standards bodies such as NIST, FIDO, and MCP at a leadership level. Your work will influence the development of identity and security standards, contributing original research and technical expertise to shape the direction of emerging protocols and frameworks. • Research Vision & Agenda: Collaborate with leadership to define and drive the long-term technical research agenda for the Security Research team. Identify the highest-impact research opportunities across application security, cryptography, identity, access governance, and AI security; Your work will set the quality standard for all research output. • Strategic Technical Advising: Serve as a trusted technical advisor to the Director of Security Research, security leadership, and product/engineering executives. Your work will translate deep research insights into strategic recommendations that inform product roadmaps, security architecture, and wide-reaching risk decisions. • Community & Ecosystem Leadership: Build and maintain strong relationships with the global security research community. Lead collaborative research initiatives, mentor fellow researchers through responsible disclosure programs, and represent 1Password as a constructive and trusted voice in the identity ecosystem. • Team Elevation: Elevate the broader Product Security team through technical mentorship, rigorous research review, and knowledge sharing. Your work will reinforce cultural norms around evidence, integrity, and intellectual rigor, as well as attract top research talent.

Job Requirements

  • 8+ years of progressive experience in security research, offensive security, or vulnerability research.
  • Bachelor’s degree in Computer Engineering, Computer Science, Information Security, or a related field; or equivalent practical experience. An advanced degree (MS/PhD) in a relevant discipline is highly valued.
  • a portfolio of original vulnerability discoveries, high-impact publications, presentations, and/or widely adopted security research.
  • extensive experience in vulnerability research, exploit development, reverse engineering, and/or advanced adversarial simulation at scale.
  • Broad and deep domain expertise across three or more of the following domains: application security, cryptography, access governance, identity protocols (SAML, OAuth, OIDC, SCIM, FIDO/WebAuthn), Linux system internals, Windows system internals, macOS system internals, Web application security, AI/Agentic security, or Mobile security.
  • Recognized expertise in AI security, including hands-on research into prompt injection, data poisoning, adversarial ML, AI architecture review, or the security of agentic systems.
  • Proven ability to define and drive research strategy: experience identifying and pursuing long-term research agendas, prioritizing across competing opportunities, and delivering high-impact results with minimal direction.
  • Proficiency in three or more programming languages such as Go, Rust, Python, Ruby, JavaScript/TypeScript, or equivalent modern languages, with the ability to architect and develop tooling, audit complex codebases, and produce proof-of-concept exploits.
  • A strong record of impactful publications, conference presentations, vulnerability disclosures, or community contributions that advanced security understanding across the industry.
  • Consistent history of handling vulnerabilities and disclosures responsibly while engaging constructively with vendors and the research community.
  • Exceptional written and verbal communication skills, with demonstrated ability to produce landmark technical publications, as well as deliver compelling presentations to both deeply technical and executive audiences.

Benefits

  • health, dental, 401k and many others
  • generous paid time off
  • equity grant
  • participation in incentive programs

Related Categories

Related Job Pages

More Security Engineer Jobs

Physical Security Delivery Manager

Stream Data Centers

Stream Data Centers is dedicated to designing, developing, and operating safe, secure, reliable, and sustainable data centers that empower clients, enhance coll

Security Engineer108 days ago

The Physical Security Delivery Manager will provide support for all Stream Data Center Construction and Operations Security Projects.  The PSDM provides design and project management expertise to ensure quality projects are delivered on time and on target in coordination with our Construction, Operations, and Information Technology Teams.   RESPONSIBILITIES: - PSDM supports and manages SDC Construction Data Center and Operations Security Projects to ensure timely delivery for lease commencements and compliance remediations. - PSDM works closely with SDC Design teams during design phase to ensure SDC Security standards are implemented in all phases of design. - PSDM performs Physical Security Design Reviews with Project Architect and Design Team through all project design deliverables to ensure PSBOD standards are implemented. - PSDM reviews Tenant’s Security BOD and ensures requirements are coordinated and captured for Build-to-Suit projects. - PSDM reviews and approves Security Bids with General Contractors. - PSDM reviews and approves Issue for Construction Security drawings and all bulletins. - PSDM reviews RFIs and Submittals associated with the project. - PSDM manages budgets effectively and mitigates unnecessary change orders. - PSDM drives projects to completion and provides updates to all stakeholders during all phases of project. - PSDM plans and coordinates all activities of security technology projects to ensure that all project goals are accomplished, meeting and / or exceeding commitment to internal and external customers. - PSDM will identify and address issues with critical thinking and complex problem solving. - PSDM will host weekly meetings with General Contractors, Security Contractors, and IT teams to effectively manage construction project deliverables and schedules. - PSDM coordinates and perform Security System Commissioning for all new Data Center builds onsite and remotely. - PSDM documents all critical evolutions, lessons learned and find possible efficiency gains in processes. - PSDM ensures a smooth handoff from Construction to Operations with completing internal checklists and hosts a turnover meeting prior to RFS. - PSDM visits job sites to review installation progress of all Security projects. - PSDM develops scopes of work to address TVRA assessment vulnerabilities working closely with Compliance and Security Operations teams. - PSDM also manages physical security remediation projects from engagement to closeout. - PSDM to review and coordinate MOPs with Operations teams to ensure work progress happens efficiently and safely.

Texas
Job Closed

Physical Security Delivery Manager

Stream Data Centers

Stream Data Centers is dedicated to designing, developing, and operating safe, secure, reliable, and sustainable data centers that empower clients, enhance coll

Security Engineer108 days ago

The Physical Security Delivery Manager will provide support for all Stream Data Center Construction and Operations Security Projects.  The PSDM provides design and project management expertise to ensure quality projects are delivered on time and on target in coordination with our Construction, Operations, and Information Technology Teams.   RESPONSIBILITIES: - PSDM supports and manages SDC Construction Data Center and Operations Security Projects to ensure timely delivery for lease commencements and compliance remediations. - PSDM works closely with SDC Design teams during design phase to ensure SDC Security standards are implemented in all phases of design. - PSDM performs Physical Security Design Reviews with Project Architect and Design Team through all project design deliverables to ensure PSBOD standards are implemented. - PSDM reviews Tenant’s Security BOD and ensures requirements are coordinated and captured for Build-to-Suit projects. - PSDM reviews and approves Security Bids with General Contractors. - PSDM reviews and approves Issue for Construction Security drawings and all bulletins. - PSDM reviews RFIs and Submittals associated with the project. - PSDM manages budgets effectively and mitigates unnecessary change orders. - PSDM drives projects to completion and provides updates to all stakeholders during all phases of project. - PSDM plans and coordinates all activities of security technology projects to ensure that all project goals are accomplished, meeting and / or exceeding commitment to internal and external customers. - PSDM will identify and address issues with critical thinking and complex problem solving. - PSDM will host weekly meetings with General Contractors, Security Contractors, and IT teams to effectively manage construction project deliverables and schedules. - PSDM coordinates and perform Security System Commissioning for all new Data Center builds onsite and remotely. - PSDM documents all critical evolutions, lessons learned and find possible efficiency gains in processes. - PSDM ensures a smooth handoff from Construction to Operations with completing internal checklists and hosts a turnover meeting prior to RFS. - PSDM visits job sites to review installation progress of all Security projects. - PSDM develops scopes of work to address TVRA assessment vulnerabilities working closely with Compliance and Security Operations teams. - PSDM also manages physical security remediation projects from engagement to closeout. - PSDM to review and coordinate MOPs with Operations teams to ensure work progress happens efficiently and safely.

Arizona
Job Closed

Physical Security Delivery Manager

Stream Data Centers

Stream Data Centers is dedicated to designing, developing, and operating safe, secure, reliable, and sustainable data centers that empower clients, enhance coll

Security Engineer108 days ago

The Physical Security Delivery Manager will provide support for all Stream Data Center Construction and Operations Security Projects.  The PSDM provides design and project management expertise to ensure quality projects are delivered on time and on target in coordination with our Construction, Operations, and Information Technology Teams.   RESPONSIBILITIES: - PSDM supports and manages SDC Construction Data Center and Operations Security Projects to ensure timely delivery for lease commencements and compliance remediations. - PSDM works closely with SDC Design teams during design phase to ensure SDC Security standards are implemented in all phases of design. - PSDM performs Physical Security Design Reviews with Project Architect and Design Team through all project design deliverables to ensure PSBOD standards are implemented. - PSDM reviews Tenant’s Security BOD and ensures requirements are coordinated and captured for Build-to-Suit projects. - PSDM reviews and approves Security Bids with General Contractors. - PSDM reviews and approves Issue for Construction Security drawings and all bulletins. - PSDM reviews RFIs and Submittals associated with the project. - PSDM manages budgets effectively and mitigates unnecessary change orders. - PSDM drives projects to completion and provides updates to all stakeholders during all phases of project. - PSDM plans and coordinates all activities of security technology projects to ensure that all project goals are accomplished, meeting and / or exceeding commitment to internal and external customers. - PSDM will identify and address issues with critical thinking and complex problem solving. - PSDM will host weekly meetings with General Contractors, Security Contractors, and IT teams to effectively manage construction project deliverables and schedules. - PSDM coordinates and perform Security System Commissioning for all new Data Center builds onsite and remotely. - PSDM documents all critical evolutions, lessons learned and find possible efficiency gains in processes. - PSDM ensures a smooth handoff from Construction to Operations with completing internal checklists and hosts a turnover meeting prior to RFS. - PSDM visits job sites to review installation progress of all Security projects. - PSDM develops scopes of work to address TVRA assessment vulnerabilities working closely with Compliance and Security Operations teams. - PSDM also manages physical security remediation projects from engagement to closeout. - PSDM to review and coordinate MOPs with Operations teams to ensure work progress happens efficiently and safely.

Illinois
Job Closed

Physical Security Delivery Manager

Stream Data Centers

Stream Data Centers is dedicated to designing, developing, and operating safe, secure, reliable, and sustainable data centers that empower clients, enhance coll

Security Engineer108 days ago

The Physical Security Delivery Manager will provide support for all Stream Data Center Construction and Operations Security Projects.  The PSDM provides design and project management expertise to ensure quality projects are delivered on time and on target in coordination with our Construction, Operations, and Information Technology Teams.   RESPONSIBILITIES: - PSDM supports and manages SDC Construction Data Center and Operations Security Projects to ensure timely delivery for lease commencements and compliance remediations. - PSDM works closely with SDC Design teams during design phase to ensure SDC Security standards are implemented in all phases of design. - PSDM performs Physical Security Design Reviews with Project Architect and Design Team through all project design deliverables to ensure PSBOD standards are implemented. - PSDM reviews Tenant’s Security BOD and ensures requirements are coordinated and captured for Build-to-Suit projects. - PSDM reviews and approves Security Bids with General Contractors. - PSDM reviews and approves Issue for Construction Security drawings and all bulletins. - PSDM reviews RFIs and Submittals associated with the project. - PSDM manages budgets effectively and mitigates unnecessary change orders. - PSDM drives projects to completion and provides updates to all stakeholders during all phases of project. - PSDM plans and coordinates all activities of security technology projects to ensure that all project goals are accomplished, meeting and / or exceeding commitment to internal and external customers. - PSDM will identify and address issues with critical thinking and complex problem solving. - PSDM will host weekly meetings with General Contractors, Security Contractors, and IT teams to effectively manage construction project deliverables and schedules. - PSDM coordinates and perform Security System Commissioning for all new Data Center builds onsite and remotely. - PSDM documents all critical evolutions, lessons learned and find possible efficiency gains in processes. - PSDM ensures a smooth handoff from Construction to Operations with completing internal checklists and hosts a turnover meeting prior to RFS. - PSDM visits job sites to review installation progress of all Security projects. - PSDM develops scopes of work to address TVRA assessment vulnerabilities working closely with Compliance and Security Operations teams. - PSDM also manages physical security remediation projects from engagement to closeout. - PSDM to review and coordinate MOPs with Operations teams to ensure work progress happens efficiently and safely.

Texas
Job Closed