Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security Engineer - GRC Controls and Audit

$153k - $214k

1Password

1Password is growing. We've surpassed $400M in ARR and we're continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.

About 1Password

At 1Password, we're building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world's most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.

If you're excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.

Good audits don't start when the auditors arrive - they start the moment a control is designed. 1Password is looking for a Senior Security Engineer - GRC Controls and Audit to serve as the technical and methodological anchor for our compliance audit programs.

You'll partner directly with the Senior Manager of GRC to lead our commercial audit programs - from evidence collection and control testing to deep technical walkthroughs with external auditors and internal SMEs. You'll own the question of what "good evidence" looks like across SOC 2 Type II, ISO 27001/27017/27018, and ISO 27701, and you'll know where to find it in the systems that generate it. Along the way, you'll help build the AI-assisted workflows and automation that make our audit programs more efficient and our compliance posture more continuous.

This is a controls expert role for someone with deep audit experience - ideally from the auditor's side of the table - who also brings a builder's instinct for making GRC more repeatable and scalable. You won't just coordinate evidence; you'll know exactly why each artifact satisfies a control requirement, and you'll be able to explain that to a skeptical Big 4 auditor and a first-time control owner in the same day.

This is a remote opportunity within Canada and the US.

What we're looking for:
  • 5+ years of experience in GRC, compliance, or audit, with a meaningful portion spent as an auditor - public accounting, Big 4, boutique audit firm, or a rigorous internal audit function.
  • Deep hands-on experience with SOC 2 Type II; strong working knowledge of ISO 27001 and related standards (27017, 27018, 27701).
  • Demonstrated experience leading technical audit walkthroughs with external auditors and preparing control owners for those interactions - not just coordinating evidence collection.
  • The ability to define what "good evidence" looks like for each control domain: where it lives in source systems (Drata, Kolide, Trelica/SaaS Manager, HRIS, endpoint tooling, cloud infrastructure), how it maps to trust service criteria, and how it must be formatted to satisfy auditor scrutiny.
  • Proven ability to design and execute control testing - writing test procedures, assessing operating effectiveness, documenting exceptions, and tracking remediation to closure.
  • Ability to work cross-functionally with Engineering, IT, Security, and People teams to understand system architectures, identify control owners, and build durable evidence collection workflows at the source.
  • Strong written and verbal communication skills - you've personally authored control narratives, audit-ready documentation, and compliance reports, and you can run a live auditor walkthrough without notes.
  • Experience with compliance automation platforms (Drata, Vanta, Secureframe, or equivalent) at a level where you can connect automated evidence to specific control requirements, not just use the dashboard.
  • A builder's instinct - you look at manual, repetitive GRC processes and ask whether they can be automated or AI-assisted, and you bring specific proposals, not just observations.
Bonus points for:
  • CPA, CIA, CISA, or CISSP certification.
  • Audit or compliance experience in a cloud-native SaaS product environment, including evidence collection from cloud infrastructure and MDM/endpoint tooling.
  • Experience building or improving continuous control monitoring capabilities.
  • Familiarity with EU AI Act, NIST AI RMF, or AI governance frameworks - increasingly relevant as 1Password governs access for AI agents alongside human users.
  • Experience with vendor risk assessments - reviewing SOC 2 reports, evaluating third-party compliance documentation, and advising on vendor risk posture.
At 1Password, we build with AI:

At 1Password, using AI to do more with less isn't a bonus - it's how we operate. For this role, building with AI is secondary to controls expertise - but it's still a real expectation. We're looking for someone who actively uses AI to accelerate their audit and compliance work and can identify where automation creates leverage for the team.
  • Active and thoughtful AI user: You've used AI tools - not just ChatGPT for writing - to meaningfully speed up audit prep: control narrative drafting, framework cross-mapping, evidence gap identification. You can walk through what you applied, what it produced, and how you validated the output before relying on it.
  • Automation spotter: You identify manual, repetitive GRC processes that can be AI-assisted or automated and bring specific proposals to the team. You don't need to build everything yourself - but you need to see the opportunity and articulate it clearly.
  • AI literacy in a compliance context: You understand the accuracy tradeoffs - when AI-generated control narratives need careful human validation, where framework mapping output requires scrutiny, and why non-determinism is a meaningful risk in audit-facing work.
  • Curiosity and self-direction: You actively track what's happening in AI-assisted compliance tooling, have experimented with more than one approach, and can compare tools with informed opinions rather than general awareness.
What you can expect:
  • Own and lead technical audit walkthroughs across SOC 2 Type II, ISO 27001/27017/27018, and ISO 27701 programs - preparing control owners, surfacing the right evidence, and serving as the primary technical liaison with external auditors.
  • Define and maintain the evidence library - what good evidence looks like for each control domain, where it lives in source systems, and how it maps to trust service criteria.
  • Execute deep-dive control testing and gap analysis across the Unified Control Framework (UCF), identifying design and operating effectiveness gaps before external testing and driving remediation with clear ownership.
  • Drive continuous evidence library maturity - shifting GRC from reactive, point-in-time evidence collection toward proactive, continuously-maintained audit-ready artifacts.
  • Partner cross-functionally with Engineering, IT, Security, and People teams to understand system architectures, identify control owners, and build durable evidence workflows at the source.
  • Contribute to policy, standards, and baseline development with an eye toward auditability and testability - requirements that control owners can implement and auditors can test.
  • Apply AI tools to accelerate control narrative drafting, framework cross-mapping, and audit prep - with clear discipline around validation and when human judgment is required.
  • Mentor A-B level GRC team members on audit methodology, control design, and evidence quality standards.

USA-based roles only: The annual base salary for this role is between $153,000 USD and $214,000 USD, plus immediate participation in 1Password's benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

Canada-based roles only: The annual base salary for this role is between $144,000 CAD and $202,000 CAD, plus immediate participation in 1Password's generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.

At 1Password, we approach each individual's compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.

This posting is for an existing vacancy.

Our culture
At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first.


You'll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone. Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you're looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We're looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results.


How we work with AI
We are committed to leveraging cutting-edge technology-including AI-to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn't just encouraged-it's an essential part of how we will be successful at 1Password.

This approach extends to our hiring process-candidates are welcome to use AI tools responsibly and thoughtfully during the application process.

Our approach to remote work
We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events.

What we offer
We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer:


Health and wellbeing
Maternity and parental leave top-up programs
Competitive health benefits
Generous PTO policy

Growth and future
RSU program for most employees
Retirement matching program
Free 1Password account

Community
Paid volunteer days
Peer-to-peer recognition through Bonusly
Remote-first work environment
*Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.

You belong here.

1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.

Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at View email address on click.appcast.io and we'll work to meet your needs.

Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we're experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you've got questions or concerns about this, your talent partner would be happy to address them with you.

Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.

1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form. For additional information see our Candidate Privacy Notice.
Vacancy posted 17 hours ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer - GRC Controls and Audit in United States vacancy
  •  ...in blockchain scalability and security, we're at the forefront of...  ...The Role As a Security Engineer (GRC) at Offchain Labs, you will play...  ...wide. Ensure the company is audit-ready and responsive to any regulatory...  ...on the status of security controls, ongoing audits, and all... 
    Senior
    Remote job
    Full time
    Work at office
    Home office

    Offchain Labs

    United States
    27 days ago
  • $163.94k - $215.18k

     ...Hi, we're Oscar. We're hiring a Senior Security Engineer 1, GRC to join our Security Team. Oscar is the...  ...managing documentation or preparing for audits, this role engineers the...  ...automation, telemetry, and self-evidencing controls. Operating at the intersection of... 
    Senior
    Full time
    Work at office
    Flexible hours

    Oscar Health

    New York, NY
    2 days ago
  • $110k - $130k

     ...Perform risk and security assessments, design secure infrastructure architectures...  ...immediate remote opening for a Senior Security Engineer(Penetration Testing/GRC Assessments) (must be available...  ...SOX, GDPR, CIS Critical Security Controls, NERC CIP, and ISO 27000.... 
    Senior
    Temporary work
    Work at office
    Immediate start
    Remote work
    Visa sponsorship
    Afternoon shift

    STRUCTURED HOME NETWORKS INC.

    Richmond, VA
    13 hours ago
  •  ...Senior Mainframe Security Engineer role (100% remote) (zSecure audit, with one of these 3 areas: ACF2 / TSS / RACF and JCL and Vulnerability and REXX/IBM SYNC SORT...  ...security standards regarding z/OS hardening, security controls, and vulnerability remediation.... 
    Senior
    Remote work

    Apex Informatics

    United States
    2 days ago
  •  ...PRIMARY FUNCTION: Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for the organization's information security program aligned to the National Institute of Standards and Technology (NIST), the Center for Internet Security... 
    Suggested

    KYOCERA AVX Greenville LLC

    Fountain Inn, SC
    2 days ago
  •  ...Senior Security Engineer Seeking a Senior Security Engineer to support enterprise data protection...  ...threat monitoring, compliance auditing, and Data Loss Prevention (DLP) initiatives...  ...filtering, protocol enforcement, and controlled information exchange between segmented... 
    Senior
    Remote work

    Artech

    United States
    3 days ago
  •  ...Security Engineer You will keep Coder's internal systems secure, reliable...  ...endpoint security, access controls, and application protections...  ...team on SOC2 compliance work, audit preparation, and security...  ...contributors, managers, and senior leaders. AI use during the... 
    Senior
    Local area
    Remote work

    Coder

    United States
    3 days ago
  • $221k - $325k

     ...software, AI, cryptography, mobile engineering, and global operations. Our...  ...will work with our team of security experts to leverage the Ethereum blockchain to record audit events and detect and respond...  ...with programming and version control (esp. GitHub). ~ Willing to... 
    Senior
    Contract work
    Flexible hours

    Tools for Humanity

    San Francisco, CA
    2 days ago
  • RDQ127R265 The Databricks Security Assurance Team enables...  ...confidence in customers. As a Senior Security Assurance Engineer, you will help lead...  ...Databricks ATO packages. Ensure audit readiness and security...  ...understanding of security controls across all domains. A general... 
    Senior

    Neura Market

    San Francisco, CA
    4 days ago
  • $221k - $325k

     ...and financial transactions daily. The Senior Security Engineer, Blockchain Detection role focuses on...  ...blockchain security, intrusion detection, audit event analysis, and incident response...  ...with programming and version control systems including GitHub. Willingness... 
    Senior
    Full time
    Contract work
    Remote work
    Flexible hours

    ArtOfBlockchain

    San Francisco, CA
    1 day ago
  • $124k - $150k

     ...Responsibilities Summary: As an L5 Sr Security Engineer in IT GRC at Frontdoor, you will serve as an advanced...  ...PCI‑DSS, CIS, and SOX. Own end‑to‑end control domains or sub‑programs, driving...  ...exceptions, vendor risk reviews, and audit responses. Implement secure engineering... 
    Senior
    Full time
    For contractors

    Frontdoor, Inc.

    New York, NY
    2 days ago
  • Bright Vision Technologies is seeking an experienced SAP Security Engineer (GRC - Technical) to design and implement security frameworks for...  ...Security and extensive hands-on experience with GRC Access Control. This is a full-time remote position within the continental... 
    Remote job
    Full time

    Bright Vision Technologies

    Edison, NJ
    2 days ago
  • Sage Integration Holdings, LLC is seeking a Systems Engineer to install, service, and maintain enterprise-level security systems including CCTV and access control. This role requires strong technical skills and the ability to work independently. The ideal candidate will... 
    Senior

    Energy Jobline ZR

    Marietta, GA
    2 days ago
  • WiredHive, Inc. in Claremore, Oklahoma seeks a seasoned professional to provide control design guidance and conduct cybersecurity assessments. This role emphasizes risk management and technical security across both Cloud and on-prem environments. The ideal candidate has 5-7... 
    Senior

    WiredHive, Inc.

    Claremore, OK
    4 days ago
  • $130k - $160k

    Decisive Point is looking for a Security Risk and Compliance Analyst in San Francisco...  ...certifications. You will enhance control frameworks and manage audit cycles while collaborating closely...  ...various teams. A minimum of 3 years in GRC is required along with foundational... 

    Decisive Point

    San Francisco, CA
    1 day ago
  •  ...Senior Security Data Engineer Lead the architecture, design, and implementation of scalable, modular...  ...enforcing robust governance and security controls (SSL/TLS, client authentication,...  ...and change tracking for forensic and audit readiness. Collaborate with observability... 
    Senior

    United IT

    United States
    1 day ago
  • $95.3k - $158.8k

     ...Carolina is seeking an experienced Audit & Compliance Program Owner....  ..., and partnering with engineering teams. Candidates should have extensive experience in security, compliance, or audit roles along...  ...with hands-on experience with GRC platforms. The position offers... 
    Senior

    LexisNexis Risk Solutions

    Raleigh, NC
    13 hours ago
  •  ...Senior Security Tools Engineer Ashburn Consulting, LLC, based in the Washington, DC metropolitan area...  ...dashboarding, automation, API development, audit support, and CDM-aligned reporting...  ..., compliance reporting, and version-controlled audit artifacts. Use CI/CD,... 
    Senior
    Work at office

    Ashburn Consulting

    Suitland, MD
    3 days ago
  •  ...Senior Security Analyst – GRC The Senior Security Analyst – GRC (Governance, Risk and Compliance) is...  ...Security Awareness Training, support GRC Audit deliverables and respond to client...  ...and procedures, risk assessment and control evaluation, security awareness and training... 
    Senior

    1872 Consulting

    Chicago, IL
    1 day ago
  •  ...Position Overview The Senior Security Controls Engineer designs, implements, and continuously improves technical security controls that reduce risk...  ...to ensure controls are effective, measurable, and audit‑ready. Key Responsibilities Engineer and maintain... 
    Senior
    Local area

    American Credit Acceptance

    Boise, ID
    1 day ago
  • $11 - $14 per hour

     ...Design and implement role-based access control (RBAC) strategies for SAP...  ...access governance controls Perform security testing, access audits, and remediation activities Review...  ...authorization concepts • Knowledge of GRC Access Control modules including Access... 

    Insight Global

    Atlanta, GA
    3 days ago
  •  ...technically proficient Principal GRC Analyst to join our Information Security team, with a focus on...  ...and testing security controls across the enterprise. This...  ...will serve as the most senior member of a small team focused...  ...of experience in GRC, IT audit, or cybersecurity... 
    Senior

    Programmers.io

    Portland, OR
    13 hours ago
  • $160.23k - $240.45k

     ...launch systems depend on security, compliance, and...  ...the mission. As a GRC Security Architect,...  ...requirements become practical, auditable, and scalable controls across the company....  ..., infrastructure, engineering, manufacturing,...  ...tracking Serve as a senior advisor to technical... 
    Permanent employment
    Full time

    Industrious Ventures

    Kent, WA
    4 days ago
  •  ...Senior Manager, Internal Controls & Sustainability Reporting Legend Biotech is a global biotechnology company...  ...as a key liaison with Internal Audit and external auditors. This role is critical...  ...of governance, risk, and compliance (GRC) tools. Support broader GRC... 
    Senior
    Worldwide

    Legend Biotech

    Bridgewater, NJ
    18 hours ago
  • $124k - $150k

    A leading home repair company is looking for an L5 Sr Security Engineer in Idaho to lead complex security and compliance initiatives. The role requires over 8 years of experience in GRC or cybersecurity and involves executing risk assessments and developing governance artifacts... 
    Senior

    Frontdoor, Inc.

    New York, NY
    5 days ago
  • $102.6k - $179.25k

     ...The Cloud Security Engineer - FAB supports the security, resilience, and compliance of FAB (...  ...role focuses on cloud-native security controls, DevSecOps automation, and operational...  ...engineering, platform operations, and audit teams. Key Responsibilities Cloud... 
    Senior
    Work at office

    Wolters Kluwer N.V.

    New York, NY
    4 days ago
  •  ...Senior Lead Security Engineer Join a team where your engineering expertise directly shapes how Technology/Cyber controls are built, governed, and scaled across a global technology organization...  ...and reporting are consistent and auditable across hybrid environments. Your... 
    Senior

    Chase

    Wilmington, DE
    1 day ago
  •  ...financial customers is seeking a Senior Information Security Analyst with expertise in ServiceNow GRC. As a Senior Information...  ...security policies and security controls as well as ensuring regulatory...  ...security controls and supporting audit. We are a company committed... 
    Senior

    Insight Global

    Minneapolis, MN
    6 days ago
  •  ...Senior Application Security Engineer A new space race has begun. True Anomaly seeks those with the talent and ambition to build innovative...  ...Engineer will be instrumental in implementing and auditing security controls for mission-critical space systems that must meet... 
    Senior
    Shift work

    Navstar

    Denver, CO
    1 day ago
  • $82.6k - $162.8k

     ...SAP Security and GRC Access & Process Control Consultant / Security Engineer II Our Deloitte Cyber team helps organizations address cybersecurity challenges while enabling business growth and resilience. As part of this team, you will support clients in navigating... 
    Visa sponsorship

    Deloitte LLP

    Arizona
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security Engineer - GRC Controls and Audit. Be the first to apply!