Discussion
Loading...

#Tag

Log in
  • About
  • Code of conduct
  • Privacy
  • Users
  • Instances
  • About Bonfire
Claudius Link boosted
Keith Hoodlet :verified: :donor:
Keith Hoodlet :verified: :donor:
@securingdev@infosec.exchange  路  activity timestamp last week

I'm excited to share three new roles that I'm hiring for on the Security Research team at 1Password! 馃攼

Here are the job descriptions available today:

Senior Security Researcher: https://jobs.ashbyhq.com/1password/a370e4fa-e1fa-49bc-be45-8b04184480da

Staff Security Researcher: https://jobs.ashbyhq.com/1password/980f3aad-cc6b-425f-9f35-a465ab20032a

Principal Security Researcher: https://jobs.ashbyhq.com/1password/2811c7da-7dad-445d-bf96-f6e0e5bb27d8

If you鈥檝e got CVE鈥檚, given conference talks at premier security conferences, published vulnerability write ups, and/or written blogs about vulnerabilities you鈥檝e discovered, then this job is likely for you.

Especially if you鈥檙e into hacking AI-integrated software, Large Language Models, browsers, cryptographically sensitive software, or desktop/mobile applications! 馃槈

#remotework #securityresearch #hacking #ai #llm #appsev

Principal Security Researcher

1Password is growing faster than ever. We鈥檝e surpassed $400M in ARR and we鈥檙e continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we鈥檙e building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world鈥檚 most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work. If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future. We鈥檙e building a world-class security research program to advance both the security of 1Password鈥檚 products and the broader identity security landscape. We鈥檙e looking for a Principal Security Researcher to serve as the most senior individual contributor on this greenfield team, setting the quality bar for all research output. In this role, you will collaborate with the Director of Security Research to define research agendas that address the most critical and complex challenges in identity security. You鈥檒l lead investigations into novel attack surfaces, collaborate with engineers to architect innovative defensive techniques, and produce landmark research that shapes how the industry thinks about identity, authentication, and access security. Your work will have an outsized impact both within 1Password and across the security ecosystem. As a member of the Product Security function, you will operate as a strategic technical leader, partnering with the Director of Security Research, engineering leadership, product teams, and company executives. You鈥檒l serve as a visible ambassador for 1Password through high-impact publications, standards leadership, and deep engagement with the global security research community. This is a remote opportunity within Canada and the US. Key responsibilities: - Deep Vulnerability Research: Lead original research into the most complex and high-impact vulnerability classes affecting 1Password鈥檚 products and the broader identity security ecosystem. Discover novel attack surfaces, develop advanced exploit chains, and pioneer new classes of findings that expand the industry鈥檚 understanding of risk. - Advanced Exploit Development & Attack Research: Design and develop sophisticated threat models, attack chains, and proof-of-concept exploits that demonstrate real-world risk at the highest level of complexity. Provide authoritative technical evidence that drives prioritization and remediation across 1Password鈥檚 product portfolio. - AI & Agentic Security Strategy: Lead research into the security implications of AI in identity systems, including prompt injection, data poisoning, adversarial attacks on AI-driven access decisions, and the systemic risks introduced by agentic architectures interacting with privileged access management (PAM); Your work will help shape 1Password鈥檚 strategic position on AI security. - Technical Publications & Thought Leadership: Author high-quality research publications, white papers, blog posts, and technical advisories. Present findings through podcasts, webinars, and/or major security conferences that contribute to 1Password鈥檚 reputation as a thought leader in identity security. - Standards Leadership: Represent 1Password in standards bodies such as NIST, FIDO, and MCP at a leadership level. Your work will influence the development of identity and security standards, contributing original research and technical expertise to shape the direction of emerging protocols and frameworks. - Research Vision & Agenda: Collaborate with leadership to define and drive the long-term technical research agenda for the Security Research team. Identify the highest-impact research opportunities across application security, cryptography, identity, access governance, and AI security; Your work will set the quality standard for all research output. - Strategic Technical Advising: Serve as a trusted technical advisor to the Director of Security Research, security leadership, and product/engineering executives. Your work will translate deep research insights into strategic recommendations that inform product roadmaps, security architecture, and wide-reaching risk decisions. - Community & Ecosystem Leadership: Build and maintain strong relationships with the global security research community. Lead collaborative research initiatives, mentor fellow researchers through responsible disclosure programs, and represent 1Password as a constructive and trusted voice in the identity ecosystem. - Team Elevation: Elevate the broader Product Security team through technical mentorship, rigorous research review, and knowledge sharing. Your work will reinforce cultural norms around evidence, integrity, and intellectual rigor, as well as attract top research talent. Qualifications: - 8+ years of progressive experience in security research, offensive security, or vulnerability research. - Education: Bachelor鈥檚 degree in Computer Engineering, Computer Science, Information Security, or a related field; or equivalent practical experience. An advanced degree (MS/PhD) in a relevant discipline is highly valued. - Industry-recognized body of work: a portfolio of original vulnerability discoveries, high-impact publications, presentations, and/or widely adopted security research. - Expert-level offensive security experience: extensive experience in vulnerability research, exploit development, reverse engineering, and/or advanced adversarial simulation at scale. - Broad and deep domain expertise across three or more of the following domains: application security, cryptography, access governance, identity protocols (SAML, OAuth, OIDC, SCIM, FIDO/WebAuthn), Linux system internals, Windows system internals, macOS system internals, Web application security, AI/Agentic security, or Mobile security. - Recognized expertise in AI security, including hands-on research into prompt injection, data poisoning, adversarial ML, AI architecture review, or the security of agentic systems. - Proven ability to define and drive research strategy: experience identifying and pursuing long-term research agendas, prioritizing across competing opportunities, and delivering high-impact results with minimal direction. - Expert software engineering proficiency: Proficiency in three or more programming languages such as Go, Rust, Python, Ruby, JavaScript/TypeScript, or equivalent modern languages, with the ability to architect and develop tooling, audit complex codebases, and produce proof-of-concept exploits. - Demonstrated thought leadership: A strong record of impactful publications, conference presentations, vulnerability disclosures, or community contributions that advanced security understanding across the industry. - Integrity and ethical rigor: Consistent history of handling vulnerabilities and disclosures responsibly while engaging constructively with vendors and the research community. - Exceptional written and verbal communication skills, with demonstrated ability to produce landmark technical publications, as well as deliver compelling presentations to both deeply technical and executive audiences. USA-based roles only: The annual base salary for this role is between $246,000 USD and $369,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. Canada-based roles only: The annual base salary for this role is between $228,000 CAD and $342,000 CAD, plus immediate participation in 1Password鈥檚 generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. This posting is for an existing vacancy. Our culture At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first. You鈥檒l be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We鈥檙e looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results. How we work with AI We are committed to leveraging cutting-edge technology鈥攊ncluding AI鈥攖o achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged鈥攊t's an essential part of how we will be successful at 1Password. This approach extends to our hiring process鈥攃andidates are welcome to use AI tools responsibly and thoughtfully during the application process. Our approach to remote work We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events. What we offer We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: Health and wellbeing 馃懚 Maternity and parental leave top-up programs 馃┖ Competitive health benefits 馃彎 Generous PTO policy Growth and future 馃搱 RSU program for most employees 馃捀 Retirement matching program 馃攽 Free 1Password account Community 馃 Paid volunteer days 馃弳 Peer-to-peer recognition through Bonusly 馃寧 Remote-first work environment *Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting. You belong here. 1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love. Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we鈥檒l work to meet your needs. Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you. Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law. 1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form https://jobs.ashbyhq.com/1password/automation-notice. For additional information see our Candidate Privacy Notice https://1password.com/files/candidate-privacy-notice.pdf.

Staff Security Researcher

1Password is growing faster than ever. We鈥檝e surpassed $400M in ARR and we鈥檙e continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we鈥檙e building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world鈥檚 most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work. If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future. Role Overview We鈥檙e building a world-class security research program to advance both the security of 1Password鈥檚 products and the broader identity security landscape. We鈥檙e looking for a Staff Security Researcher to join this greenfield team as a senior individual contributor. In this role, you will conduct deep, original vulnerability research across 1Password鈥檚 product suite and the wider identity ecosystem. You鈥檒l investigate emerging attack vectors, develop proof-of-concept exploits, publish your findings responsibly, and partner with engineering teams to drive mitigation/remediation strategies. Your work will directly shape our product security posture and raise the bar for identity security across the industry. As a member of the Product Security organization, you will partner with engineers, product teams, marketing, and security leaders to protect our customers and contribute to a safer digital future. You will establish deep partnerships with the global security research community through technical publications, responsible disclosure, and collaborative dialogue with the broader security community. This is a Remote opportunity within Canada and the US. KEY RESPONSIBILITIES - Vulnerability Research: Conduct original, hands-on research into application-level, protocol-level, and ecosystem-level vulnerabilities in 1Password鈥檚 products and the broader identity security landscape; You will discover, validate, and document novel vulnerability classes and attack chains. - Demonstrate Exploitability: Develop proof-of-concept exploits and attack demonstrations that validate research findings, illustrate real-world risk, and support engineering teams in understanding and prioritizing remediation efforts. - AI & Agentic Security Research: Investigate security risks at the intersection of AI and identity, including prompt injection, data poisoning, and other AI-based attack vectors; Your work will address the emerging challenges of agentic security at the interaction between privileged access management (PAM) and AI systems. - Technical Publications & Thought Leadership: Author high-quality research publications, white papers, blog posts, and technical advisories; You will have the opportunity to present findings on podcasts, webinars, and at major security conferences that contribute to 1Password鈥檚 reputation as a thought leader in identity security. - Standards Engagement: Contribute to standards bodies such as NIST, FIDO, and MCP. Your work will advance 1Password鈥檚 involvement in shaping identity and security standards that benefit the broader ecosystem. - Community Engagement: Engage actively with the global security research community through responsible disclosure, collaborative research, open-source contributions, and participation in industry forums/events. - Cross-functional Collaboration: Partner with Product, Engineering, and Detection teams to translate research findings into actionable security improvements. Provide evidence-based technical guidance that informs product direction and security strategy. - Mentorship: Mentor junior and mid-level security colleagues. Your work will raise the technical bar across the security organization by sharing knowledge, reviewing research, and fostering a culture of curiosity and rigor. QUALIFICATIONS - 6+ years of progressive experience in security research, offensive security, or vulnerability research. - Education: Bachelor鈥檚 degree in Computer Science, Computer Engineering, Information Security, or a related field; or equivalent practical experience. - Security research expertise: Proven track record of discovering and responsibly disclosing original vulnerabilities, ideally with published CVEs, advisories, or equivalent publicly-recognized findings. - Offensive security experience: Hands-on expertise in vulnerability research, exploit development, or advanced adversarial simulation techniques. - Deep domain expertise across one or more of the following domains: application security, cryptography, access governance, identity protocols (SAML, OAuth, OIDC, SCIM, FIDO/WebAuthn), Linux system internals, Windows system internals, macOS system internals, AI/Agentic security, Web application security, or Mobile application security. - AI security experience: Familiarity with prompt injection,data poisoning, AI design architecture, AI-based attacks, and related vectors. - Software engineering proficiency: Proficiency in one or more programming languages such as Go, Rust, Python, Ruby, JavaScript/TypeScript, or equivalent modern languages, with the ability to read and audit code for vulnerabilities. - Integrity and ethical rigor: Consistent history of handling vulnerabilities and disclosures responsibly while engaging constructively with vendors and the research community. - Demonstrated thought leadership: A record of publications, conference presentations, vulnerability disclosures, or community contributions that advanced security understanding across the industry. - Strong written and verbal communication skills, with demonstrated ability to produce technical publications, blog posts, and/or conference talks that clearly convey complex security topics. USA-based roles only: The annual base salary for this role is between $192,000 USD and $278,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. Canada-based roles only: The annual base salary for this role is between $167,000 CAD and $242,000 CAD, plus immediate participation in 1Password鈥檚 generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. This posting is for an existing vacancy. Our culture At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first. You鈥檒l be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We鈥檙e looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results. How we work with AI We are committed to leveraging cutting-edge technology鈥攊ncluding AI鈥攖o achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged鈥攊t's an essential part of how we will be successful at 1Password. This approach extends to our hiring process鈥攃andidates are welcome to use AI tools responsibly and thoughtfully during the application process. Our approach to remote work We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events. What we offer We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: Health and wellbeing 馃懚 Maternity and parental leave top-up programs 馃┖ Competitive health benefits 馃彎 Generous PTO policy Growth and future 馃搱 RSU program for most employees 馃捀 Retirement matching program 馃攽 Free 1Password account Community 馃 Paid volunteer days 馃弳 Peer-to-peer recognition through Bonusly 馃寧 Remote-first work environment *Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting. You belong here. 1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love. Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we鈥檒l work to meet your needs. Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you. Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law. 1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form https://jobs.ashbyhq.com/1password/automation-notice. For additional information see our Candidate Privacy Notice https://1password.com/files/candidate-privacy-notice.pdf.

Senior Security Researcher

1Password is growing faster than ever. We鈥檝e surpassed $400M in ARR and we鈥檙e continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we鈥檙e building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world鈥檚 most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work. If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future. We鈥檙e building a world-class security research program to advance both the security of 1Password鈥檚 products and the broader identity security landscape. We鈥檙e looking for a Senior Security Researcher to join this greenfield team as an individual contributor. In this role, you will conduct deep, original vulnerability research across 1Password鈥檚 product suite and the wider identity ecosystem. You鈥檒l investigate emerging attack vectors, develop proof-of-concept exploits, publish your findings responsibly, and partner with engineering teams to drive mitigations/remediations. Your work will directly contribute to our product security posture and raise the bar for identity security across the industry. As a member of the Product Security organization, you will partner with engineers, product teams, marketing, and security leaders to protect our customers and contribute to a safer digital future. You will establish partnerships with the global security research community through technical publications, responsible disclosure, and collaborative dialogue with the broader security research community. This is a remote opportunity within Canada and the US. Key responsibilities: - Vulnerability Research: Conduct original, hands-on research into application-level, protocol-level, and ecosystem-level vulnerabilities in 1Password鈥檚 products and the broader identity security landscape; You will discover, validate, and document novel vulnerability classes and attack chains. - Demonstrate Exploitability: Collaborate with peers to develop proof-of-concept exploits and attack demonstrations that validate research findings, illustrate real-world risk, and support engineering teams in understanding and prioritizing remediation efforts. - AI & Agentic Security Research: Investigate security risks at the intersection of AI and identity, including prompt injection, data poisoning, and other AI-based attack vectors; Your work will address the emerging challenges of agentic security at the interaction between privileged access management (PAM) and AI systems. - Technical Publications & Thought Leadership: Author high-quality research publications, white papers, blog posts, and technical advisories; You will have the opportunity to present findings on podcasts, webinars, and at major security conferences that contribute to 1Password鈥檚 reputation as a thought leader in identity security. - Community Engagement: Engage actively with the global security research community through responsible disclosure, collaborative research, open-source contributions, and participation in industry forums/events. - Cross-functional Collaboration: Partner with Product, Engineering, and Detection teams to translate research findings into actionable security improvements. Provide evidence-based technical guidance that informs product direction and security strategy. Qualifications: - 4+ years of progressive experience in security research, offensive security, or vulnerability research. - Education: Bachelor鈥檚 degree in Computer Science, Computer Engineering, Information Security, or a related field; or equivalent practical experience. - Security research experience: Proven track record of discovering and responsibly disclosing original vulnerabilities, ideally with published CVEs, advisories, or equivalent publicly-recognized findings. - Offensive security experience: A track record of hands-on experience in vulnerability research, exploit development, or advanced adversarial simulation techniques. - Sufficient domain experience in two or more of the following domains: application security, Linux system internals, Windows system internals, macOS system internals, AI/Agentic security, Web application security, or Mobile application security. - AI security experience: Familiarity with prompt injection, data poisoning, AI design architecture, AI-based attacks, and related vectors. - Software engineering proficiency: Proficiency in one or more programming languages such as Go, Rust, Python, Ruby, JavaScript/TypeScript, or equivalent modern languages, with the ability to read and audit code for vulnerabilities. - Integrity and ethical rigor: Consistent history of handling vulnerabilities and disclosures responsibly while engaging constructively with vendors and the research community. - Demonstrable written and verbal communication skills, with a track record of producing technical publications, blog posts, and/or conference talks that clearly convey complex security topics. USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD, plus immediate participation in 1Password鈥檚 generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. This posting is for an existing vacancy. Our culture At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first. You鈥檒l be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We鈥檙e looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results. How we work with AI We are committed to leveraging cutting-edge technology鈥攊ncluding AI鈥攖o achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged鈥攊t's an essential part of how we will be successful at 1Password. This approach extends to our hiring process鈥攃andidates are welcome to use AI tools responsibly and thoughtfully during the application process. Our approach to remote work We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events. What we offer We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: Health and wellbeing 馃懚 Maternity and parental leave top-up programs 馃┖ Competitive health benefits 馃彎 Generous PTO policy Growth and future 馃搱 RSU program for most employees 馃捀 Retirement matching program 馃攽 Free 1Password account Community 馃 Paid volunteer days 馃弳 Peer-to-peer recognition through Bonusly 馃寧 Remote-first work environment *Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting. You belong here. 1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love. Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we鈥檒l work to meet your needs. Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you. Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law. 1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form https://jobs.ashbyhq.com/1password/automation-notice. For additional information see our Candidate Privacy Notice https://1password.com/files/candidate-privacy-notice.pdf.
  • Copy link
  • Flag this post
  • Block
Keith Hoodlet :verified: :donor:
Keith Hoodlet :verified: :donor:
@securingdev@infosec.exchange  路  activity timestamp last week

I'm excited to share three new roles that I'm hiring for on the Security Research team at 1Password! 馃攼

Here are the job descriptions available today:

Senior Security Researcher: https://jobs.ashbyhq.com/1password/a370e4fa-e1fa-49bc-be45-8b04184480da

Staff Security Researcher: https://jobs.ashbyhq.com/1password/980f3aad-cc6b-425f-9f35-a465ab20032a

Principal Security Researcher: https://jobs.ashbyhq.com/1password/2811c7da-7dad-445d-bf96-f6e0e5bb27d8

If you鈥檝e got CVE鈥檚, given conference talks at premier security conferences, published vulnerability write ups, and/or written blogs about vulnerabilities you鈥檝e discovered, then this job is likely for you.

Especially if you鈥檙e into hacking AI-integrated software, Large Language Models, browsers, cryptographically sensitive software, or desktop/mobile applications! 馃槈

#remotework #securityresearch #hacking #ai #llm #appsev

Principal Security Researcher

1Password is growing faster than ever. We鈥檝e surpassed $400M in ARR and we鈥檙e continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we鈥檙e building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world鈥檚 most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work. If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future. We鈥檙e building a world-class security research program to advance both the security of 1Password鈥檚 products and the broader identity security landscape. We鈥檙e looking for a Principal Security Researcher to serve as the most senior individual contributor on this greenfield team, setting the quality bar for all research output. In this role, you will collaborate with the Director of Security Research to define research agendas that address the most critical and complex challenges in identity security. You鈥檒l lead investigations into novel attack surfaces, collaborate with engineers to architect innovative defensive techniques, and produce landmark research that shapes how the industry thinks about identity, authentication, and access security. Your work will have an outsized impact both within 1Password and across the security ecosystem. As a member of the Product Security function, you will operate as a strategic technical leader, partnering with the Director of Security Research, engineering leadership, product teams, and company executives. You鈥檒l serve as a visible ambassador for 1Password through high-impact publications, standards leadership, and deep engagement with the global security research community. This is a remote opportunity within Canada and the US. Key responsibilities: - Deep Vulnerability Research: Lead original research into the most complex and high-impact vulnerability classes affecting 1Password鈥檚 products and the broader identity security ecosystem. Discover novel attack surfaces, develop advanced exploit chains, and pioneer new classes of findings that expand the industry鈥檚 understanding of risk. - Advanced Exploit Development & Attack Research: Design and develop sophisticated threat models, attack chains, and proof-of-concept exploits that demonstrate real-world risk at the highest level of complexity. Provide authoritative technical evidence that drives prioritization and remediation across 1Password鈥檚 product portfolio. - AI & Agentic Security Strategy: Lead research into the security implications of AI in identity systems, including prompt injection, data poisoning, adversarial attacks on AI-driven access decisions, and the systemic risks introduced by agentic architectures interacting with privileged access management (PAM); Your work will help shape 1Password鈥檚 strategic position on AI security. - Technical Publications & Thought Leadership: Author high-quality research publications, white papers, blog posts, and technical advisories. Present findings through podcasts, webinars, and/or major security conferences that contribute to 1Password鈥檚 reputation as a thought leader in identity security. - Standards Leadership: Represent 1Password in standards bodies such as NIST, FIDO, and MCP at a leadership level. Your work will influence the development of identity and security standards, contributing original research and technical expertise to shape the direction of emerging protocols and frameworks. - Research Vision & Agenda: Collaborate with leadership to define and drive the long-term technical research agenda for the Security Research team. Identify the highest-impact research opportunities across application security, cryptography, identity, access governance, and AI security; Your work will set the quality standard for all research output. - Strategic Technical Advising: Serve as a trusted technical advisor to the Director of Security Research, security leadership, and product/engineering executives. Your work will translate deep research insights into strategic recommendations that inform product roadmaps, security architecture, and wide-reaching risk decisions. - Community & Ecosystem Leadership: Build and maintain strong relationships with the global security research community. Lead collaborative research initiatives, mentor fellow researchers through responsible disclosure programs, and represent 1Password as a constructive and trusted voice in the identity ecosystem. - Team Elevation: Elevate the broader Product Security team through technical mentorship, rigorous research review, and knowledge sharing. Your work will reinforce cultural norms around evidence, integrity, and intellectual rigor, as well as attract top research talent. Qualifications: - 8+ years of progressive experience in security research, offensive security, or vulnerability research. - Education: Bachelor鈥檚 degree in Computer Engineering, Computer Science, Information Security, or a related field; or equivalent practical experience. An advanced degree (MS/PhD) in a relevant discipline is highly valued. - Industry-recognized body of work: a portfolio of original vulnerability discoveries, high-impact publications, presentations, and/or widely adopted security research. - Expert-level offensive security experience: extensive experience in vulnerability research, exploit development, reverse engineering, and/or advanced adversarial simulation at scale. - Broad and deep domain expertise across three or more of the following domains: application security, cryptography, access governance, identity protocols (SAML, OAuth, OIDC, SCIM, FIDO/WebAuthn), Linux system internals, Windows system internals, macOS system internals, Web application security, AI/Agentic security, or Mobile security. - Recognized expertise in AI security, including hands-on research into prompt injection, data poisoning, adversarial ML, AI architecture review, or the security of agentic systems. - Proven ability to define and drive research strategy: experience identifying and pursuing long-term research agendas, prioritizing across competing opportunities, and delivering high-impact results with minimal direction. - Expert software engineering proficiency: Proficiency in three or more programming languages such as Go, Rust, Python, Ruby, JavaScript/TypeScript, or equivalent modern languages, with the ability to architect and develop tooling, audit complex codebases, and produce proof-of-concept exploits. - Demonstrated thought leadership: A strong record of impactful publications, conference presentations, vulnerability disclosures, or community contributions that advanced security understanding across the industry. - Integrity and ethical rigor: Consistent history of handling vulnerabilities and disclosures responsibly while engaging constructively with vendors and the research community. - Exceptional written and verbal communication skills, with demonstrated ability to produce landmark technical publications, as well as deliver compelling presentations to both deeply technical and executive audiences. USA-based roles only: The annual base salary for this role is between $246,000 USD and $369,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. Canada-based roles only: The annual base salary for this role is between $228,000 CAD and $342,000 CAD, plus immediate participation in 1Password鈥檚 generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. This posting is for an existing vacancy. Our culture At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first. You鈥檒l be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We鈥檙e looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results. How we work with AI We are committed to leveraging cutting-edge technology鈥攊ncluding AI鈥攖o achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged鈥攊t's an essential part of how we will be successful at 1Password. This approach extends to our hiring process鈥攃andidates are welcome to use AI tools responsibly and thoughtfully during the application process. Our approach to remote work We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events. What we offer We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: Health and wellbeing 馃懚 Maternity and parental leave top-up programs 馃┖ Competitive health benefits 馃彎 Generous PTO policy Growth and future 馃搱 RSU program for most employees 馃捀 Retirement matching program 馃攽 Free 1Password account Community 馃 Paid volunteer days 馃弳 Peer-to-peer recognition through Bonusly 馃寧 Remote-first work environment *Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting. You belong here. 1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love. Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we鈥檒l work to meet your needs. Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you. Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law. 1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form https://jobs.ashbyhq.com/1password/automation-notice. For additional information see our Candidate Privacy Notice https://1password.com/files/candidate-privacy-notice.pdf.

Staff Security Researcher

1Password is growing faster than ever. We鈥檝e surpassed $400M in ARR and we鈥檙e continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we鈥檙e building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world鈥檚 most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work. If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future. Role Overview We鈥檙e building a world-class security research program to advance both the security of 1Password鈥檚 products and the broader identity security landscape. We鈥檙e looking for a Staff Security Researcher to join this greenfield team as a senior individual contributor. In this role, you will conduct deep, original vulnerability research across 1Password鈥檚 product suite and the wider identity ecosystem. You鈥檒l investigate emerging attack vectors, develop proof-of-concept exploits, publish your findings responsibly, and partner with engineering teams to drive mitigation/remediation strategies. Your work will directly shape our product security posture and raise the bar for identity security across the industry. As a member of the Product Security organization, you will partner with engineers, product teams, marketing, and security leaders to protect our customers and contribute to a safer digital future. You will establish deep partnerships with the global security research community through technical publications, responsible disclosure, and collaborative dialogue with the broader security community. This is a Remote opportunity within Canada and the US. KEY RESPONSIBILITIES - Vulnerability Research: Conduct original, hands-on research into application-level, protocol-level, and ecosystem-level vulnerabilities in 1Password鈥檚 products and the broader identity security landscape; You will discover, validate, and document novel vulnerability classes and attack chains. - Demonstrate Exploitability: Develop proof-of-concept exploits and attack demonstrations that validate research findings, illustrate real-world risk, and support engineering teams in understanding and prioritizing remediation efforts. - AI & Agentic Security Research: Investigate security risks at the intersection of AI and identity, including prompt injection, data poisoning, and other AI-based attack vectors; Your work will address the emerging challenges of agentic security at the interaction between privileged access management (PAM) and AI systems. - Technical Publications & Thought Leadership: Author high-quality research publications, white papers, blog posts, and technical advisories; You will have the opportunity to present findings on podcasts, webinars, and at major security conferences that contribute to 1Password鈥檚 reputation as a thought leader in identity security. - Standards Engagement: Contribute to standards bodies such as NIST, FIDO, and MCP. Your work will advance 1Password鈥檚 involvement in shaping identity and security standards that benefit the broader ecosystem. - Community Engagement: Engage actively with the global security research community through responsible disclosure, collaborative research, open-source contributions, and participation in industry forums/events. - Cross-functional Collaboration: Partner with Product, Engineering, and Detection teams to translate research findings into actionable security improvements. Provide evidence-based technical guidance that informs product direction and security strategy. - Mentorship: Mentor junior and mid-level security colleagues. Your work will raise the technical bar across the security organization by sharing knowledge, reviewing research, and fostering a culture of curiosity and rigor. QUALIFICATIONS - 6+ years of progressive experience in security research, offensive security, or vulnerability research. - Education: Bachelor鈥檚 degree in Computer Science, Computer Engineering, Information Security, or a related field; or equivalent practical experience. - Security research expertise: Proven track record of discovering and responsibly disclosing original vulnerabilities, ideally with published CVEs, advisories, or equivalent publicly-recognized findings. - Offensive security experience: Hands-on expertise in vulnerability research, exploit development, or advanced adversarial simulation techniques. - Deep domain expertise across one or more of the following domains: application security, cryptography, access governance, identity protocols (SAML, OAuth, OIDC, SCIM, FIDO/WebAuthn), Linux system internals, Windows system internals, macOS system internals, AI/Agentic security, Web application security, or Mobile application security. - AI security experience: Familiarity with prompt injection,data poisoning, AI design architecture, AI-based attacks, and related vectors. - Software engineering proficiency: Proficiency in one or more programming languages such as Go, Rust, Python, Ruby, JavaScript/TypeScript, or equivalent modern languages, with the ability to read and audit code for vulnerabilities. - Integrity and ethical rigor: Consistent history of handling vulnerabilities and disclosures responsibly while engaging constructively with vendors and the research community. - Demonstrated thought leadership: A record of publications, conference presentations, vulnerability disclosures, or community contributions that advanced security understanding across the industry. - Strong written and verbal communication skills, with demonstrated ability to produce technical publications, blog posts, and/or conference talks that clearly convey complex security topics. USA-based roles only: The annual base salary for this role is between $192,000 USD and $278,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. Canada-based roles only: The annual base salary for this role is between $167,000 CAD and $242,000 CAD, plus immediate participation in 1Password鈥檚 generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. This posting is for an existing vacancy. Our culture At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first. You鈥檒l be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We鈥檙e looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results. How we work with AI We are committed to leveraging cutting-edge technology鈥攊ncluding AI鈥攖o achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged鈥攊t's an essential part of how we will be successful at 1Password. This approach extends to our hiring process鈥攃andidates are welcome to use AI tools responsibly and thoughtfully during the application process. Our approach to remote work We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events. What we offer We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: Health and wellbeing 馃懚 Maternity and parental leave top-up programs 馃┖ Competitive health benefits 馃彎 Generous PTO policy Growth and future 馃搱 RSU program for most employees 馃捀 Retirement matching program 馃攽 Free 1Password account Community 馃 Paid volunteer days 馃弳 Peer-to-peer recognition through Bonusly 馃寧 Remote-first work environment *Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting. You belong here. 1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love. Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we鈥檒l work to meet your needs. Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you. Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law. 1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form https://jobs.ashbyhq.com/1password/automation-notice. For additional information see our Candidate Privacy Notice https://1password.com/files/candidate-privacy-notice.pdf.

Senior Security Researcher

1Password is growing faster than ever. We鈥檝e surpassed $400M in ARR and we鈥檙e continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we鈥檙e building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Extended Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world鈥檚 most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work. If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future. We鈥檙e building a world-class security research program to advance both the security of 1Password鈥檚 products and the broader identity security landscape. We鈥檙e looking for a Senior Security Researcher to join this greenfield team as an individual contributor. In this role, you will conduct deep, original vulnerability research across 1Password鈥檚 product suite and the wider identity ecosystem. You鈥檒l investigate emerging attack vectors, develop proof-of-concept exploits, publish your findings responsibly, and partner with engineering teams to drive mitigations/remediations. Your work will directly contribute to our product security posture and raise the bar for identity security across the industry. As a member of the Product Security organization, you will partner with engineers, product teams, marketing, and security leaders to protect our customers and contribute to a safer digital future. You will establish partnerships with the global security research community through technical publications, responsible disclosure, and collaborative dialogue with the broader security research community. This is a remote opportunity within Canada and the US. Key responsibilities: - Vulnerability Research: Conduct original, hands-on research into application-level, protocol-level, and ecosystem-level vulnerabilities in 1Password鈥檚 products and the broader identity security landscape; You will discover, validate, and document novel vulnerability classes and attack chains. - Demonstrate Exploitability: Collaborate with peers to develop proof-of-concept exploits and attack demonstrations that validate research findings, illustrate real-world risk, and support engineering teams in understanding and prioritizing remediation efforts. - AI & Agentic Security Research: Investigate security risks at the intersection of AI and identity, including prompt injection, data poisoning, and other AI-based attack vectors; Your work will address the emerging challenges of agentic security at the interaction between privileged access management (PAM) and AI systems. - Technical Publications & Thought Leadership: Author high-quality research publications, white papers, blog posts, and technical advisories; You will have the opportunity to present findings on podcasts, webinars, and at major security conferences that contribute to 1Password鈥檚 reputation as a thought leader in identity security. - Community Engagement: Engage actively with the global security research community through responsible disclosure, collaborative research, open-source contributions, and participation in industry forums/events. - Cross-functional Collaboration: Partner with Product, Engineering, and Detection teams to translate research findings into actionable security improvements. Provide evidence-based technical guidance that informs product direction and security strategy. Qualifications: - 4+ years of progressive experience in security research, offensive security, or vulnerability research. - Education: Bachelor鈥檚 degree in Computer Science, Computer Engineering, Information Security, or a related field; or equivalent practical experience. - Security research experience: Proven track record of discovering and responsibly disclosing original vulnerabilities, ideally with published CVEs, advisories, or equivalent publicly-recognized findings. - Offensive security experience: A track record of hands-on experience in vulnerability research, exploit development, or advanced adversarial simulation techniques. - Sufficient domain experience in two or more of the following domains: application security, Linux system internals, Windows system internals, macOS system internals, AI/Agentic security, Web application security, or Mobile application security. - AI security experience: Familiarity with prompt injection, data poisoning, AI design architecture, AI-based attacks, and related vectors. - Software engineering proficiency: Proficiency in one or more programming languages such as Go, Rust, Python, Ruby, JavaScript/TypeScript, or equivalent modern languages, with the ability to read and audit code for vulnerabilities. - Integrity and ethical rigor: Consistent history of handling vulnerabilities and disclosures responsibly while engaging constructively with vendors and the research community. - Demonstrable written and verbal communication skills, with a track record of producing technical publications, blog posts, and/or conference talks that clearly convey complex security topics. USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD, plus immediate participation in 1Password鈥檚 generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs. At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set. This posting is for an existing vacancy. Our culture At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first. You鈥檒l be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone https://blog.1password.com/inside-the-culture-powering-1passwords-next-chapter/. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We鈥檙e looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results. How we work with AI We are committed to leveraging cutting-edge technology鈥攊ncluding AI鈥攖o achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged鈥攊t's an essential part of how we will be successful at 1Password. This approach extends to our hiring process鈥攃andidates are welcome to use AI tools responsibly and thoughtfully during the application process. Our approach to remote work We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events. What we offer We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer: Health and wellbeing 馃懚 Maternity and parental leave top-up programs 馃┖ Competitive health benefits 馃彎 Generous PTO policy Growth and future 馃搱 RSU program for most employees 馃捀 Retirement matching program 馃攽 Free 1Password account Community 馃 Paid volunteer days 馃弳 Peer-to-peer recognition through Bonusly 馃寧 Remote-first work environment *Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting. You belong here. 1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love. Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at nextbit@agilebits.com and we鈥檒l work to meet your needs. Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you. Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law. 1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here https://www.ashbyhq.com/downloadables/ashby-bias-audit-08-2024.pdf for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form https://jobs.ashbyhq.com/1password/automation-notice. For additional information see our Candidate Privacy Notice https://1password.com/files/candidate-privacy-notice.pdf.
  • Copy link
  • Flag this post
  • Block

bonfire.cafe

A space for Bonfire maintainers and contributors to communicate

bonfire.cafe: About 路 Code of conduct 路 Privacy 路 Users 路 Instances
Bonfire social 路 1.0.2-alpha.34 no JS en
Automatic federation enabled
Log in
Instance logo
  • Explore
  • About
  • Members
  • Code of Conduct