Productive businesses use 1Password to secure employees at scale.
Senior Security Engineer, GRC Automation
Location
California
Posted
55 days ago
Salary
$153K - $214K / year
Seniority
Senior
Job Description
Senior Security Engineer, GRC Automation
1Password
• design and implement automation, dashboards, and integrations that power our Governance, Risk, and Compliance (GRC) operations. • partner directly with the Senior Manager of GRC to build automation that scales our security and privacy commitments — from audit readiness and policy enforcement to customer trust workflows. • operationalizing and expanding our GRC platform (Drata), building AI-assisted workflows that automate evidence collection, control monitoring, and vendor risk — and owning the delivery of those projects from scoping through go-live. • be in the room with auditors, owning the technical narrative for what you've built and why. • lead the implementation and integration of our GRC platform, ensuring it is fully operationalized across key systems and workflows. • build out automated workflows for control testing, evidence collection, and audit readiness. • manage project delivery across multiple GRC automation initiatives simultaneously — maintaining clear scope, milestones, and stakeholder visibility without sacrificing quality.
Job Requirements
- 5+ years of experience in security engineering, DevSecOps, solutions engineering, or GRC automation roles.
- Proven experience working with GRC, compliance, or audit teams to build automation that supports evidence collection, control testing, or security monitoring.
- Direct experience implementing and integrating GRC platforms (e.g., Drata, Vanta, Tines, JupiterOne) into production environments.
- Strong scripting and integration skills using Python, JavaScript, APIs, webhooks, or workflow automation tools.
- Ability to work cross-functionally with security, compliance, legal, and infrastructure teams to translate policies into scalable technical systems.
- Familiarity with compliance frameworks such as SOC 2, ISO 27001, or NIST 800-53, and how they map to real-world infrastructure and operations.
- Project management and delivery ownership — experience managing multi-workstream compliance or security projects end-to-end: scoping, milestones, stakeholder communication, and on-time delivery. You can run a project without a PM holding your hand.
- Experience building AI-assisted workflows — you've worked with LLMs, agentic tools, or automation pipelines (beyond click-through tools) to solve a GRC or compliance problem and can walk through what you built, why, and how you validated the output.
- Confident in auditor-facing settings — you have a commanding presence in technical walkthroughs and can represent your automation work clearly to external auditors, senior stakeholders, and executive audiences. You know the difference between what you built and what it proves.
Benefits
- immediate participation in 1Password's benefits program (health, dental, 401k and many others)
- utilization of our generous paid time off
- an equity grant
- participation in our incentive programs
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Set and deliver the security strategy for an AI-native SaaS platform. • Lead a team of Application Security, Infrastructure Security, Detection & Response, and GRC engineers. • Partner closely with executives, Enterprise Governance, GTM, Product, Engineering, Legal, and Risk. • Protect millions of customers from having their API credentials, data, and AI-driven workflows compromised. • Own and evolve the risk management program: identify and quantify enterprise risk. • Lead company-wide security change — standards, golden paths, technical gates, vendor and procurement patterns. • Stay on the bleeding edge of AI, frontier models, and the evolving threat landscape.
Role Description Provide frontline support for all information security related issues, such as: - Penetration testing - Network and service configuration - Advising on security policy compliance - Handling data confidentiality issues - Monitoring and responding to emerging threats Contribute to the development of Information Security policies and processes. Conduct application security reviews and recommend solutions to resolve application security issues. Provide information security support during events impacting tier one customer-facing services. Identify and troubleshoot recurring issues and escalate appropriately for full resolution. 40 hours/week, 8:00am-5:00pm, Salary Range: $159,300/year to $202,400/year. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, visit: Amazon Employee Benefits . Qualifications - Bachelor’s degree or foreign equivalent degree in Computer Science, Engineering, Information Systems or Technology, Mathematics or a related field - One year of experience in the job offered or a related occupation Requirements - One year of experience in the following skill(s): - Application and infrastructure information security - Application of threat modeling or other risk identification techniques - Knowledge of system security vulnerabilities and remediation techniques, including penetration testing, source code review, configuring advanced runtime and static vulnerability testing tools, and the development of exploits - Programming in Java, C, C++, Perl, Ruby or Python - Coordinating responsibility of technical security tasks - 100% telecommuting permitted, work may be performed from anywhere in the U.S. Benefits Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit Amazon Accommodations for more information.
Role Description Identify and resolve emerging security threats impacting Amazon's global enterprise, production environments, and customers. - Provide penetration testing. - Provide security engineering solutions and support during customer-facing incidents. - Contribute to development of Amazon.com Services Information Security organization’s policies, processes, and programs. - Identify and troubleshoot recurring issues and escalate appropriately for full resolution. 40 hours / week, 8:00am-5:00pm, Salary Range: $179,234/year to $226,700/year. Amazon is a total compensation company. Dependent on the position offered, equity, sign-on payments, and other forms of compensation may be provided as part of a total compensation package, in addition to a full range of medical, financial, and/or other benefits. For more information, visit: Amazon Benefits . Amazon.com is an Equal Opportunity-Affirmative Action Employer – Minority / Female / Disability / Veteran / Gender Identity / Sexual Orientation. Qualifications - Bachelor's degree or foreign equivalent degree in Computer Science, Engineering, Information Technology, Cybersecurity, Mathematics or a related field. - Five years of experience in the job offered or a related occupation. Requirements - Five years of experience in the following skill(s): - Experience with system security vulnerabilities and remediation techniques, including penetration testing and the development of exploits. - Experience with security engineering practices, including: - Web application security. - Network security. - Authentication and authorization protocols. - Cryptography. - Automation. - Experience with dynamic and manual code auditing to identify security issues. - Programming in Java, C, C++, Perl, Ruby or Python. - Application of threat modeling or other risk identification techniques. - 100% telecommuting permitted, work may be performed from anywhere in the U.S. Preferred Qualifications Please see job description and the position requirements above. Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit Accommodations Information for more information.
Security Labeling Specialist
MercorCincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.
Role Description Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark, General Catalyst, Peter Thiel, Adam D'Angelo, Larry Summers, and Jack Dorsey. Position: Cybersecurity Labeling Expert Type: Contract Compensation: $100–$150/hour Location: Remote Duration: 2–3 week engagement Commitment: 20+ hours/week Role Responsibilities - Analyze flagged AI conversations to assess intent and harm across domains like scaled data exfiltration, ransomware, worms, and exploits. - Evaluate POC exploit development to determine boundaries between security research and malicious intent. - Provide ground-truth labels to improve classifiers that enhance AI safety. - Work independently and asynchronously to meet deadlines while improving AI model performance. - Collaborate with security experts to ensure accurate threat assessments and labeling. Qualifications - Hands-on offensive security background: red team, malware analysis, pen testing, or exploit research. - Ability to distinguish legitimate security work from genuine attack intent. - Comfort interpreting code-heavy conversations. - Masters or early-career through Senior/Principal experience. Requirements - Hourly contractor. - Paid weekly via Stripe Connect. Application Process - Upload resume. - AI interview based on your resume. - Submit form. Resources & Support - For details about the interview process and platform information, please check: https://talent.docs.mercor.com/welcome - For any help or support, reach out to: support@mercor.com PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.


