1Password logo
1Password

Productive businesses use 1Password to secure employees at scale.

Senior Security Engineer, GRC Automation

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 501-1,000Since 2009H1B SponsorCompany SiteLinkedIn

Location

California

Posted

6 days ago

Salary

$153K - $214K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishJavaScriptPython

Job Description

Senior Security Engineer, GRC Automation

1Password

• design and implement automation, dashboards, and integrations that power our Governance, Risk, and Compliance (GRC) operations. • partner directly with the Senior Manager of GRC to build automation that scales our security and privacy commitments — from audit readiness and policy enforcement to customer trust workflows. • operationalizing and expanding our GRC platform (Drata), building AI-assisted workflows that automate evidence collection, control monitoring, and vendor risk — and owning the delivery of those projects from scoping through go-live. • be in the room with auditors, owning the technical narrative for what you've built and why. • lead the implementation and integration of our GRC platform, ensuring it is fully operationalized across key systems and workflows. • build out automated workflows for control testing, evidence collection, and audit readiness. • manage project delivery across multiple GRC automation initiatives simultaneously — maintaining clear scope, milestones, and stakeholder visibility without sacrificing quality.

Job Requirements

  • 5+ years of experience in security engineering, DevSecOps, solutions engineering, or GRC automation roles.
  • Proven experience working with GRC, compliance, or audit teams to build automation that supports evidence collection, control testing, or security monitoring.
  • Direct experience implementing and integrating GRC platforms (e.g., Drata, Vanta, Tines, JupiterOne) into production environments.
  • Strong scripting and integration skills using Python, JavaScript, APIs, webhooks, or workflow automation tools.
  • Ability to work cross-functionally with security, compliance, legal, and infrastructure teams to translate policies into scalable technical systems.
  • Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53, and how they map to real-world infrastructure and operations.
  • Project management and delivery ownership — experience managing multi-workstream compliance or security projects end-to-end: scoping, milestones, stakeholder communication, and on-time delivery. You can run a project without a PM holding your hand.
  • Experience building AI-assisted workflows — you've worked with LLMs, agentic tools, or automation pipelines (beyond click-through tools) to solve a GRC or compliance problem and can walk through what you built, why, and how you validated the output.
  • Confident in auditor-facing settings — you have a commanding presence in technical walkthroughs and can represent your automation work clearly to external auditors, senior stakeholders, and executive audiences. You know the difference between what you built and what it proves.

Benefits

  • immediate participation in 1Password's benefits program (health, dental, 401k and many others)
  • utilization of our generous paid time off
  • an equity grant
  • participation in our incentive programs

Related Categories

Related Job Pages

More Security Engineer Jobs

Amazon logo

Security Engineer III

Amazon

Amazon is the largest online retailer in the world. The Fortune 500 company offers traditional and e-books, household items, apparel, electronics, movies, music

Role Description Identify and resolve emerging security threats impacting Amazon's global enterprise, production environments, and customers. - Provide penetration testing. - Provide security engineering solutions and support during customer-facing incidents. - Contribute to development of Amazon.com Services Information Security organization’s policies, processes, and programs. - Identify and troubleshoot recurring issues and escalate appropriately for full resolution. 40 hours / week, 8:00am-5:00pm, Salary Range: $179,234/year to $226,700/year. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, visit: Amazon Benefits . Amazon.com is an Equal Opportunity-Affirmative Action Employer – Minority / Female / Disability / Veteran / Gender Identity / Sexual Orientation. Qualifications - Bachelor's degree or foreign equivalent degree in Computer Science, Engineering, Information Technology, Cybersecurity, Mathematics or a related field. - Five years of experience in the job offered or a related occupation. Requirements - Five years of experience in the following skill(s): - Experience with system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits. - Experience with security engineering practices, including: - Web application security. - Network security. - Authentication and authorization protocols. - Cryptography. - Automation. - Experience with dynamic and manual code auditing to identify security issues. - Programming in Java, C, C++, Perl, Ruby or Python. - Application of threat modeling or other risk identification techniques. - 100% telecommuting permitted, work may be performed from anywhere in the U.S. Preferred Qualifications Please see job description and the position requirements above. Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit Accommodations Information for more information.

United States
$179.2K - $226.7K / year
Mercor logo

Security Labeling Specialist

Mercor

Cincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.

Part TimeRemoteH1B No Sponsor

Role Description Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey. Position: Cybersecurity Labeling Expert Type: Contract Compensation: $100–$150/hour Location: Remote Duration: 2–3 week engagement Commitment: 20+ hours/week Role Responsibilities - Analyze flagged AI conversations to assess intent and harm across domains like scaled data exfiltration, ransomware, worms, and exploits. - Evaluate POC exploit development to determine boundaries between security research and malicious intent. - Provide ground-truth labels to improve classifiers that enhance AI safety. - Work independently and asynchronously to meet deadlines while improving AI model performance. - Collaborate with security experts to ensure accurate threat assessments and labeling. Qualifications - Hands-on offensive security background: red team, malware analysis, pen testing, or exploit research. - Ability to distinguish legitimate security work from genuine attack intent. - Comfort interpreting code-heavy conversations. - Masters or early-career through Senior/Principal experience. Requirements - Hourly contractor. - Paid weekly via Stripe Connect. Application Process - Upload resume. - AI interview based on your resume. - Submit form. Resources & Support - For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome - For any help or support, reach out to: support@mercor.com PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

United States
$100 - $150 / hour
Mercor logo

Cybersecurity Expert - Threat Analysis

Mercor

Cincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.

Part TimeRemoteH1B No Sponsor

Role Description As a Cybersecurity Labeling Expert, you will: - Analyze flagged AI conversations to assess intent and harm across domains like scaled data exfiltration, ransomware, worms, and exploits. - Evaluate POC exploit development to determine boundaries between security research and malicious intent. - Provide ground-truth labels to improve classifiers that enhance AI safety. - Work independently and asynchronously to meet deadlines while improving AI model performance. - Collaborate with security experts to ensure accurate threat assessments and labeling. Qualifications - Hands-on offensive security background: red team, malware analysis, pen testing, or exploit research. - Ability to distinguish legitimate security work from genuine attack intent. - Comfort interpreting code-heavy conversations. - Masters or early-career through Senior/Principal experience. Requirements - Hourly contractor. - Paid weekly via Stripe Connect. Benefits - Remote work opportunity. - Flexible commitment of 20+ hours/week. - 2–3 week engagement. Application Process - Upload resume. - AI interview based on your resume. - Submit form. Resources & Support - For details about the interview process and platform information, please check: Interview Process . - For any help or support, reach out to: support@mercor.com .

United Kingdom
$100 - $150 / hour
Barracuda Networks Inc. logo

Cybersecurity Engineer

Barracuda Networks Inc.

Barracuda is a leading cybersecurity company providing complete protection against complex threats. Our platform protects email, data, applications, and networks with innovative solutions, and a managed XDR service, to strengthen cyber resilience. Hundreds of thousands of IT professionals and managed service providers worldwide trust us to protect and support them with solutions that are easy to buy, deploy, and use.

Full TimeRemoteTeam 1,001-5,000

Role Description Barracuda XDR is seeking a passionate and seasoned Cybersecurity Engineer to help us deliver excellent threat research, detection capabilities, and incident response guidance to our customers. You must possess a strong background in security and data engineering, automation, use-case development, threat hunting, and attack simulation. This is a unique opportunity to work with over 40 different cloud, endpoint, and network data sources blending security knowledge with data engineering. Our global 24x7 SOC team is innovative, competitive, and committed to continuous improvement. We are looking for candidates with strong communication, support, and leadership skills. This role requires flexibility and an eagerness to learn new technologies. What you’ll be working on: - Detection engineering and use-case development. - ETL, normalization, SQL, python notebooks, anomaly detection. - Emerging threat research and threat intelligence gathering. - SOC tier 3 escalation support. - Security orchestration, automation, and response (SOAR). - Adversarial emulation and ethical hacking. - Incident response and report writing. - Fun cutting-edge security projects. Qualifications - Strong foundation in security operations, which provides the context for advanced engineering projects within the Barracuda XDR SOC. - At least 4-6 years of experience working for a SOC or CIRT is required. - Comfortable and confident leading complex security investigations. - Strong threat hunting abilities in SIEM solutions such as Elastic or Splunk. - Basic hands-on experience with Kali Linux and other offensive security tools. - Experience working with API-based integrations or SOAR applications. - Basic familiarity with cloud services such as AWS and Azure and network technologies like the TCP/IP stack, firewall management, IDS/IPS, and log collection techniques. - At least 2 years of experience with CICD, Python and SQL is required. - Deep understanding of end-to-end detection engineering: research, development, automation, testing (Attack-and-Defend), and documentation. - Familiarity with platforms such as Elastic and Databricks is preferred. Requirements - Strong verbal and written communication skills. - Willingness to work across time zones when required – we have team members in US East and Ireland also. - Experience with publishing blogs, Github projects, and speaking engagements. - A college degree in Computer Science, Data Science, Cybersecurity, or a related domain. - Relevant security industry certifications such as CySA+, PNPT, or eJPT are preferred. Benefits - A team where you can voice your opinion, make an impact, and where you and your experience are valued. - Internal mobility – there are opportunities for cross training and the ability to attain your next career step within Barracuda. - Equity, in the form of non-qualifying options. - High-quality health benefits. - Retirement Plan with employer match. - Career-growth opportunities. - Flexible Time Off and Paid Time Off benefits. - Volunteer opportunities. The anticipated salary range for this role is 105,000 to 140,000. Actual compensation offered will be dependent upon the individual's skills, experience, and qualifications as they directly relate to the requirements of the position, the budget for the position, and applicable employment laws. At Barracuda, we believe in fair and equitable compensation practices that reflect both market realities and the unique circumstances of each geographical location. We recognize that cost-of-living disparities, market conditions, and other factors can significantly impact compensation expectations in different regions. The compensation range provided in this job description is for illustrative purposes only and may not reflect the actual compensation offers for the position in your location. Final compensation will be determined based on a variety of factors including the candidates’ qualifications and experience.

United States
$105K - $140K / year