
Senior Security Engineer (Governance, Risk, and Compliance)
1PasswordPosted 3/13/2025

Senior Security Engineer (Governance, Risk, and Compliance)
1Password
Job Location
Salary Range
Job Summary
1Password is seeking a Senior Security Engineer (Governance, Risk, and Compliance) to join their remote team. The ideal candidate will have at least 5+ years of combined experience in security, GRC, risk, or a related space with hands-on technical work building automation solutions as they relate to compliance controls, evidence, GRC platforms, etc. The role involves collaborating cross-functionally with teams across the company to establish world-class GRC programs, contributing to GRC initiatives such as audits and security assurance, and building automation using home-grown solutions and off-the-shelf technologies. The position requires sophisticated program/project management abilities, communication skills, and a collaborative approach. 1Password offers a range of benefits, including health and wellbeing programs, growth opportunities, flexibility, and community support. The company is committed to fostering an inclusive, diverse, and equitable workplace.
Job Description
What we're looking for:
- Minimum of 5+ years of combined experience in security, GRC, risk, or a related space with hands-on technical work building automation solutions as they relate to compliance controls, evidence, GRC platforms, etc.
- Experience in effectively analyzing data and programs for security risk, compliance, and maturity.
- Willingness to wear different hats and work on areas where needed.
- Must excel in communication, and demonstrate the ability to explain technical security concepts to a non-technical audience.
- Must have a highly collaborative and teamwork-focused approach, as well as a heart for mentoring and leveling up your teammates.
- Must be able to assess and mitigate corporate risk within the organization.
- Sophisticated program/project management abilities.
- Nice to have: experience with Drata and/or Vanta (integrations, automation, onboarding as a GRC platform).
What you can expect:
- Own, design and manage the continued enhancement of various GRC programs including but not limited to strategy, roadmap, and controls to address regulatory requirements across multiple jurisdictions.
- Communicate our compliance framework and various program requirements to all relevant stakeholders (internal and external).
- Engage cross-functionally (with groups such as Engineering, Finance, Legal, Product, and Sales) to establish a thoughtful, strategic and tactical approach to multiple GRC programs and related processes.
- You will assist with analysis and preparation for internal and external audits.
- Accurately and effectively communicate our compliance position and programs to auditors and customers.
- Partner with other members of the security team to establish security guidelines that enable the organization to move fast in a safe and secure manner.
- To operate as a technical leader by helping define the GRC roadmap and by leveling up junior employees.
- Build strong relationships with partner and stakeholder teams in order to build a scalable GRC program.