Choose your preferred language
Posted 3 weeks ago
1Password — Senior Security Engineer, GRC Automation
We crossed $400M ARR. Four years on the Forbes Cloud 100. Oracle Red Bull Racing uses us. Growth is real and it's not slowing.
But here's the honest part — our GRC function needs to catch up. Not because it's broken, but because we're scaling fast and the manual stuff that worked two years ago doesn't cut it anymore. That's where you come in.
What is 1Password, actually?
We make sure people can sign into things securely without it being a nightmare. Enterprise password management, identity, access — we built the category and we're still leading it. Over 180,000 companies trust us, from big Fortune 100 names to the AI startups you've probably heard of lately.
The mission sounds simple: keep people safe online without making their lives harder. Actually pulling that off at this scale? That's the hard part, and it's what makes the work interesting.
The job
You'd be working side by side with our Senior Manager of GRC to take everything that currently lives in spreadsheets, inboxes, and people's heads — and turn it into something that runs itself.
We use Drata as our GRC platform. Right now it's set up. What it isn't yet is fully plugged in, automated, and driving real decisions. That's the project. You'd own it — from the first scoping conversation to the moment it's live and humming.
You'll build the workflows that collect audit evidence without someone manually chasing it down. You'll connect the integrations that make control monitoring actually work. You'll figure out where AI can genuinely help and where it'd just add noise. And you'll do all of this while being the person who sits in the room with auditors and explains what you built, why it works, and what it proves.
That last part matters. This isn't a heads-down build role where someone else handles the external-facing stuff. You'll own the technical story with auditors and executives. If that sounds like pressure you'd find motivating rather than exhausting, good.
Remote role, US or Canada only.
What you actually need
Five or more years doing real technical work — security engineering, DevSecOps, GRC automation, solutions engineering. Not advising. Building.
You've integrated GRC platforms like Drata, Vanta, or JupiterOne into actual production environments and you know where they fall short, not just what the sales deck says they do.
Python or JavaScript, APIs, webhooks, workflow automation — you use these comfortably and you don't need a ticket system to tell you when something should be automated.
You understand SOC 2, ISO 27001, NIST — not as a list of acronyms but as frameworks that tie to real infrastructure choices. You can look at a control and tell whether it actually works or just looks good on paper.
You've run projects without a dedicated PM babysitting the timeline. You scope it, set milestones, communicate when things shift, and get it across the line.
You've used LLMs or agentic tools to solve an actual compliance problem — not a demo, not a side experiment. A real one. And you can explain what tradeoffs you made and how you knew it was working.
Would be great if you also have
Experience with Tines for event-driven automation and control validation. You've built GRC dashboards in Looker or Metabase. You understand how AWS IAM, encryption, and logging connect to compliance controls at a technical level.
Customer trust or privacy engineering background helps. So does experience supporting sales teams with compliance documentation — we deal with that too.
Any familiarity with EU AI Act or NIST AI RMF is genuinely relevant here, not just a checkbox. AI agents are part of the access picture we manage now.
CISSP or CISA is a plus. Working toward it counts too.
Day to day
Building out the automated control testing and evidence collection workflows that make audit prep a background process instead of a fire drill.
Expanding and integrating Drata across the systems that matter.
Designing AI-assisted compliance workflows — starting with what problem you're actually solving, not what technology sounds cool.
Walking auditors through what you've built. Owning that conversation fully.
To apply for this position:
Click the Apply Now button below.
You will be redirected to the official job page (Jobicy).
Review the full details and submit your application there.