
About 1Password
At 1Password, weβre building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. Over 180,000 businesses trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.
The Role
As our Manager, Security Incident Response, you are at the center of how 1Password handles the moments that matter most. You will build and lead a team of responders who don't just work incidents, but engineer the automation, tooling, and systems that make response faster and more scalable over time. You will guide program maturity, scale the team's capabilities through AI-assisted tooling, reinforce operational excellence, and step in as incident manager during complex, high-severity events.
This role reports to the Senior Manager, Threat Operations and is a remote opportunity within Canada and the US.
What You'll Do
- Lead & Develop: Build, lead, and develop a team of incident responders and security builders, setting clear expectations, creating meaningful ownership, and supporting growth.
- Roadmap & Strategy: Define and drive the security incident response roadmap and strategic priorities, including maturing agentic incident response, structured threat hunting, and insider risk investigations as sustained, scaled capabilities.
- Automation & Scaling: Scale team capacity through AI-assisted tooling and automation, maintaining appropriate controls around human judgment, approval, auditability, and rollback.
- Incident Management: Oversee detection, triage, containment, remediation, and post-incident learning, serving as an escalation point and incident manager for complex or high-severity events.
- Cross-Functional Collaboration: Partner with Detection Engineering, Cyber Threat Intelligence, Red Team, and other groups to improve processes and close detection or response gaps.
- Program Maturity: Evolve playbooks, training, tabletop exercises, metrics, and reporting to strengthen operational readiness.
- On-Call Leadership: Participate in the on-call rotation, serving as the leadership escalation or incident manager during major incidents.
What We're Looking For
- 5+ years in security incident response, with 2+ years as a people manager or technical leader supporting career development and performance management.
- Experience building or scaling incident response automation, tooling, or AI-assisted workflows (triage, enrichment, investigation).
- Proven experience managing high-pressure security incidents with clarity, structure, and calm.
- Strong understanding of cloud-native, SaaS, and identity-driven attack techniques and remediation strategies.
- Excellent communication skills to explain complex findings, tradeoffs, and recommendations to both technical and non-technical audiences.
- Experience coordinating team sprints, breaking down strategic initiatives, and managing competing priorities.
- Passion for fostering psychological safety and stability in demanding environments.
Timezone overlap
UTC-8β-4
Open to
NA
Sign in to track applications and earn points.