Senior Security Engineer, Detection and Response
Listed on 2026-02-27
-
IT/Tech
Cybersecurity, Security Manager
1
Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth.
About 1
Password
At 1
Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today.
As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1
Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.
If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.
At 1
Password, security isn’t just a feature – it’s our foundation. The Security Operations team’s mission is to protect the business by securing the systems, tools, and processes that power how we work. Our mission is to keep 1
Password productive, resilient, and safe through proactive monitoring, rapid response, and continuous improvement of preventative and detective controls.
As a Senior Security Engineer on the Detection & Response team, you will play a key role in detecting, investigating, and responding to security threats across 1
Password. You will help mature detection capabilities, respond to complex security incidents, and improve the systems and processes that enable effective security operations. This is a high-impact role with meaningful ownership and the opportunity to shape how detection and response scale together.
This role reports to the Manager of Detection & Response.
What to expectDesign, build, and continuously improve threat detections across 1
Password’s infrastructure, products, internal tools, and corporate environments.Lead and support security incident response activities, including investigation, containment, remediation, and post-incident learning.
Apply threat intelligence and knowledge of attacker TTPs to detection development, threat hunting, alert triage, and response prioritization.
Collaborate with Security, Infrastructure, and IT teams to improve security visibility, logging quality, and response readiness.
Use automation, scripting, and Detection-as-Code practices to scale detection and response workflows and improve reliability.
Own end-to-end security projects aligned with Detection & Response initiatives and broader security strategy.
Participate in a shared on‑call rotation and support high‑severity incidents as needed.
Contribute to operational maturity through playbooks, mentoring, tabletop exercises, audits, and cross‑functional initiatives.
Calm and effective under pressure, with a blameless, data‑informed approach to incident response.
Operationally minded, with strong judgment and a bias toward action and continuous improvement.
Comfortable working across both detection engineering and incident response responsibilities.
A collaborative teammate who values clear communication, shared ownership, and psychological safety.
Motivated by protecting customers, employees, and the business through practical, high‑impact security work.
5+ years of experience in security technical engineering roles, with 3+ years focused on security operations, detection engineering or incident response.
Hands‑on experience with detection engineering and automation, including SIEMs, SOAR platforms, behavior analytics, and Detection-as-Code workflows.
Strong understanding of modern attacker techniques and how they apply to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).