Remote Manager, Security Incident Response
$192k - $278k1Password
- Remote job
1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.
About 1Password
At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.
If you’re excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.
As our Manager, Security Incident Response, you are at the center of how 1Password handles the moments that matter most. You will build and lead a team of builders: responders who don’t just work incidents, but engineer the automation, tooling, and systems that make response faster and more scalable over time. You will guide program maturity, scale the team’s capabilities through AI-assisted tooling, reinforce operational excellence, and step in as incident manager during complex, high-severity events. Success in this role blends strong people leadership with technical depth and sound judgment. As part of the Security leadership team, you will shape response strategy, build effective cross-functional partnerships, and help protect a product trusted by millions.
This role reports to the Senior Manager, Threat Operations.
How we’re using AI today
Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers.
This is a remote opportunity within Canada and the US.
What we’re looking for:
• 5+ years in security incident response, with 2+ years as a people manager or technical leader supporting career development and performance management.
• Experience building or scaling incident response automation, tooling, or AI-assisted workflows (triage, enrichment, investigation), with sound judgment about where automation should and shouldn’t make decisions.
• Experience setting clear expectations, defining ownership, delegating work, and measuring outcomes.
• Experience managing high-pressure security incidents with clarity, structure, and calm.
• Strong understanding of cloud-native, SaaS, and identity-driven attack techniques and how to respond to them.
• Strong communication skills, including the ability to explain complex findings, tradeoffs, and recommendations to technical and non-technical audiences.
• Experience breaking down strategic initiatives into projects, coordinating team sprints, and managing work across competing priorities.
• Passion for fostering psychological safety and stability in stressful environments.
Who you are:
• A people-first leader who prioritizes team development, psychological safety, and performance.
• A builder at heart, someone who thinks in systems and automation, not just case queues, and hires and develops engineers with that same instinct.
• Proactive in identifying gaps, inefficiencies, or operational risks and bringing forward actionable solutions, including where AI or automation can close them.
• Effective at driving alignment across teams with differing priorities and perspectives.
• Calm and decisive during high-pressure situations, with the judgment to prioritize effectively and make difficult tradeoffs.
• A clear and transparent communicator who can align teams with differing priorities, surface tradeoffs, and advocate for sound security decisions.
• Motivated by protecting people, data, and the business.
What you can expect:
• Build, lead, and develop a team of incident responders and security builders, setting clear expectations, creating meaningful ownership, and supporting growth.
• Delegate effectively based on team strengths, development goals, capacity, and operational needs while maintaining accountability for outcomes.
• Define and drive the security incident response roadmap and strategic priorities, including maturing agentic incident response, structured threat hunting, and insider risk investigations as sustained, scaled capabilities rather than one-time builds.
• Balance competing priorities across incident response, strategic initiatives, and team development; make tradeoffs clear and push back when timelines, approaches, or requests create unnecessary risk or unsustainable workload.
• Scale team capacity through AI-assisted tooling and automation, maintaining appropriate controls around human judgment, approval, auditability, and rollback.
• Oversee detection, triage, containment, remediation, and post-incident learning, serving as an escalation point and incident manager for complex or high-severity events.
• Partner with Detection Engineering, Cyber Threat Intelligence, Red Team and other teams to improve cross-functional processes and close detection or response gaps identified through investigations.
• Evolve playbooks, training, tabletop exercises, metrics, and reporting to strengthen operational readiness and program maturity.
• Participate in the on-call rotation, serving as the leadership escalation or incident manager during major or complex incidents.
• Track and report on incident trends, operational metrics, and program maturity, including the impact of automation and AI tooling on response time and coverage.
USA-based roles only: The annual base salary for this role is between $192,000 USD and $278,000 USD, plus immediate participation in 1Password’s benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.
Canada-based roles only: The annual base salary for this role is between $171,000 CAD and $248,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.
At 1Password, we approach each individual’s compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.
This posting is for an existing vacancy.
Our culture
At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first.
You’ll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone . Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you’re looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We’re looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results.
How we work with AI
We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn’t just encouraged—it’s an essential part of how we will be successful at 1Password.
This approach extends to our hiring process—candidates are welcome to use AI tools responsibly and thoughtfully during the application process. To us, this means we do ask that you join live interviews without using AI tools so we can get to know how you communicate, solve problems, and collaborate with others.
Our approach to remote work
We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events.
What we offer
We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer:
Health and wellbeing
Maternity and parental leave top-up programs
Competitive health benefits
Generous PTO policy
Growth and future
RSU program for most employees
Retirement matching program
Free 1Password account
Community
Paid volunteer days
Peer-to-peer recognition through Bonusly
Remote-first work environment
*Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.
You belong here.
1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.
Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at View email address on jobicy.com and we’ll work to meet your needs.
Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we’re experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you’ve got questions or concerns about this, your talent partner would be happy to address them with you.
Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.
1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form . For additional information see our Candidate Privacy Notice .
Jobicy JobID: 153123- PingWind is actively seeking an Incident Manager to lead incident management for the FSA IAM systems, ensuring rapid detection, response, and resolution to minimize disruption for users, applications, and services. The role follows FSA incident and problem management processes...Remote job
- ...Global Services U.S., a division of Brink's, Incorporated, seeks an experienced Security Operations Center (SOC) Manager to lead monitoring, detection, investigation, and incident response across the organization's locations. You will oversee day-to-day SOC operations,...Suggested
- ...employee productivity without compromising security by ensuring every identity is authentic... ...the market-leading enterprise password manager and pioneered Unified Access Management... ...Role Overview As our Manager, Security Incident Response, you are at the center of how 1Password...SuggestedFull timeImmediate start
$225.4k - $281.8k
...for a startup-minded Engineering Manager to lead our Security Detection & Response team. You’ll build and scale a team... ...This role operates in a fully remote environment and requires excellent... ...team. Security Observability & Incident Response as Outcome Own end...Remote workFull timeWorldwideFlexible hours$175.1k - $236.9k
...looking for an experienced security leader to join the Cloud... ...you will own building and managing a team of incident managers and technical leaders... ...is a must.Key job responsibilities- Build and lead a high-performing... ...- Experience managing remote team members- Experience in...Remote workFlexible hoursShift workNight shift- ...Apply now: Security Response Manager, location is Remote. The start date is ASAP for this 6 month Contract-to-Hire position. Job Title: Security Response... .... Job Description: Lead enterprise security incident response while providing hands-on forensic investigation...Remote workContract workImmediate start
$151k - $208k
...looking for a Principal Consultant in Burbank, California, responsible for leading incident response and digital forensics services. This role... ...technical leader on investigations and guiding clients through security incidents with expertise and precision. Ideal candidates...Remote work- An established industry player in cybersecurity is seeking a skilled professional to join their dynamic incident response team. This role focuses on engaging with clients post-cyber-attack, utilizing advanced forensic methodologies to analyze and remediate threats. The...Remote work
- ...Cybersecurity Incident Response Specialist We're on the hunt for a Cybersecurity Incident Response Specialist with the curiosity of a... ...thrive on turning chaos into clarity. You'll investigate security incidents, perform digital forensics, analyze malware, and help...Remote work
$170k - $210k
A leading security consultancy in the United States is seeking a Security Operations Leader to drive their global operations strategy... ...a high-performing team for 24/7 security monitoring, incident response, and ensuring regulatory compliance. Candidates should have...- ...Phase2 Technology is looking for a Cyber Incident Response Business Development Senior Manager to lead and grow its Incident Response business. This role involves... .... This position supports a hybrid work model that includes both in-office and remote work. #J-18808-Ljbffr...Remote workWork at office
$118.65k - $182.71k
10279- Manager, Security Incident Response Location: Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide...Full timeWork experience placement- TeleTech Holdings, Inc. is seeking an Incident Response Manager to lead our security operations from a remote location in the United States. You will oversee detection, containment, and remediation of cybersecurity threats while guiding a skilled team of analysts. You’ll...Remote work
- TTEC is seeking an Incident Response Manager to lead the cybersecurity incident response team from a fully remote position in the United States. You will manage detection, containment... ...lifecycle management, and continuous security improvement across policies and processes...Remote job
- Noblis is seeking a security professional to advance cyber defense programs for federal missions. You will evaluate capabilities, lead improvements, and design incident response playbooks within an agile framework. The role emphasizes cross‑functional collaboration, data...Remote job
- Pax8 is seeking a Senior Manager to lead Cybersecurity Incident Response and Business Continuity in the United States with remote capabilities. You will unite incident command with Business Continuity, guide a small team, and shape the incident management approach while...Remote job
$125.2k - $187.8k
A major grocery retailer is seeking a Security Engineering Manager to oversee security policies and manage incident response for technology environments. This role requires over ten years of relevant experience and a bachelor's degree in a related field. Key responsibilities...Flexible hours- First Quality is seeking a Cyber Security Analyst to join its remote Information Security team. The role focuses on incident detection, investigation, and response, with emphasis on tuning... ...findings to stakeholders and senior management. A background in SOC operations...Remote job
- ...a Privacy Analyst to own the Privacy Incident Management function, reporting to the Head of Privacy... .... You will partner across Privacy, Security, Product, Engineering, and Communications... ...durable process improvements to raise response #J-18808-Ljbffr Jackalope Digital LLCRemote job
- BlueVoyant is seeking a Senior Director, Digital Forensics & Incident Response to spearhead cyber investigations in a client-facing leadership role. This position requires managing complex security incidents while advising executives and legal teams. The ideal candidate...Remote job
- ...Position Title: Cyber Security Incident Response Lead Location: Texas (Teleworker) Clearance Requirements: Public Trust Clearance Pay... ...incident response (DFIR) roles ~ Demonstrated leadership in managing large-scale incidents affecting cloud environments (AWS...Remote workFor contractors
- First Citizens Bank is seeking a Senior Incident Response Analyst for a remote role that can be hired in multiple U.S. markets. You will join the Cyber Incident Response team, detecting and responding to threats, interacting with business stakeholders, and restoring operations...Remote job
$40 - $80 per hour
...Incident Response Lead, Cyber Security $40-80/hr Remote Freelance CODING About the Role What if your hard-won experience in the SOC trenches could directly... ..., response workflows, and incident lifecycle management Sharp analytical thinking with the ability to translate...Remote workHourly payOngoing contractContract workFreelanceFlexible hoursNight shift- ...routine check-ins, patrols, observe safety concerns, and support incident response for staff, clients, and visitors. This essential, part-time... .... Shifts include evenings, weekends, and some days with no remote work; a valid Texas driver's license and at least three years...Remote workPart timeShift workAfternoon shift
- ...Manager, Security Operations Location: Remote – USA Lead the Future of AI-Driven Cyber Defense We are seeking... ...detection, investigation, and response. This is a hands-on leadership role... ...security strategy, lead major incident response, and build a world-class...Remote work
- To lead incident management efforts for a high-impact engagement, the part-time Incident Response Manager will manage live incidents, conduct training, and enable stakeholders... ...effectively respond to cyber incidents in a fully remote capacity for approximately 12-15 weeks,...Remote workPart time
- ...Manager, Security Operations Forward Financing is a financial technology company based in... ...You will be the point person to lead incident response as senior Incident Commander, drive cybersecurity... ...match. Forward is proud to be a remote-first company, keeping workplace...Remote workWork at officeWork from homeFlexible hours
- ...Incident Response Specialist PH - Fully Remote The Incident Response Specialist will play a key role in supporting... ...Incident Responders and Incident Managers, you will conduct technical... ...some of their most critical cyber security events. The role also supports...Remote work
- ...Manager, Security Operations At Vanta, our mission is to help businesses... ...infrastructure. You'll be responsible for leading the Security Operations... ...team and assisting with incident response, setting our... ...Health & wellness stipend ~ Remote workspace, internet, and cellphone...Remote workWork experience placementWork at officeImmediate startFlexible hours
$175.1k - $236.9k
AWS Security Incident Response is looking for a Security Manager who combines deep technical expertise in security operations with the leadership judgment to drive a team through a fundamental transformation — from human-driven investigation to AI-native security operations...Flexible hoursShift work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Remote Manager, Security Incident Response. Be the first to apply!
- security engineering manager Remote
- security operations manager Remote
- senior security manager Remote
- physical security manager Remote
- security manager Remote
- director global security Remote
- surveillance manager Remote
- senior director information security Remote
- security systems manager Remote
- director information security Remote


