Remote Manager, Security Incident Response
$192k - $278k1Password
- Remote job
1Password is growing. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing.
About 1Password
At 1Password, we’re building the foundation for a safe, productive digital future. Our mission is to unleash employee productivity without compromising security by ensuring every identity is authentic, every application sign-in is secure, and every device is trusted. We innovated the market-leading enterprise password manager and pioneered Unified Access Management, a new cybersecurity category built for the way people and AI agents work today. As one of the most loved brands in cybersecurity, we take a human-centric approach in everything from product strategy to user experience. Over 180,000 businesses, from Fortune 100 leaders to the world’s most innovative AI companies, trust 1Password to help their teams securely adopt the SaaS and AI tools they need to do their best work.
If you’re excited about the opportunity to contribute to the digital safety of millions, to work alongside a team of curious, driven individuals, and to solve hard problems in a fast-paced, dynamic environment, then we want to hear from you. Come join us and help shape a safer, simpler digital future.
As our Manager, Security Incident Response, you are at the center of how 1Password handles the moments that matter most. You will build and lead a team of builders: responders who don’t just work incidents, but engineer the automation, tooling, and systems that make response faster and more scalable over time. You will guide program maturity, scale the team’s capabilities through AI-assisted tooling, reinforce operational excellence, and step in as incident manager during complex, high-severity events. Success in this role blends strong people leadership with technical depth and sound judgment. As part of the Security leadership team, you will shape response strategy, build effective cross-functional partnerships, and help protect a product trusted by millions.
This role reports to the Senior Manager, Threat Operations.
How we’re using AI today
Our Engineering, Product, and Design teams are thoughtfully integrating AI across the full software and product development lifecycle to move faster without sacrificing quality or security. In practice, that looks like engineers using AI-assisted coding tools to accelerate reviews and catch bugs earlier, product managers synthesizing user research at scale, and designers rapidly prototyping and iterating with AI-generated mockups. We approach AI the same way we approach security: with clear principles, human accountability at every consequential decision point, and rigorous evaluation before anything ships to customers.
This is a remote opportunity within Canada and the US.
What we’re looking for:
• 5+ years in security incident response, with 2+ years as a people manager or technical leader supporting career development and performance management.
• Experience building or scaling incident response automation, tooling, or AI-assisted workflows (triage, enrichment, investigation), with sound judgment about where automation should and shouldn’t make decisions.
• Experience setting clear expectations, defining ownership, delegating work, and measuring outcomes.
• Experience managing high-pressure security incidents with clarity, structure, and calm.
• Strong understanding of cloud-native, SaaS, and identity-driven attack techniques and how to respond to them.
• Strong communication skills, including the ability to explain complex findings, tradeoffs, and recommendations to technical and non-technical audiences.
• Experience breaking down strategic initiatives into projects, coordinating team sprints, and managing work across competing priorities.
• Passion for fostering psychological safety and stability in stressful environments.
Who you are:
• A people-first leader who prioritizes team development, psychological safety, and performance.
• A builder at heart, someone who thinks in systems and automation, not just case queues, and hires and develops engineers with that same instinct.
• Proactive in identifying gaps, inefficiencies, or operational risks and bringing forward actionable solutions, including where AI or automation can close them.
• Effective at driving alignment across teams with differing priorities and perspectives.
• Calm and decisive during high-pressure situations, with the judgment to prioritize effectively and make difficult tradeoffs.
• A clear and transparent communicator who can align teams with differing priorities, surface tradeoffs, and advocate for sound security decisions.
• Motivated by protecting people, data, and the business.
What you can expect:
• Build, lead, and develop a team of incident responders and security builders, setting clear expectations, creating meaningful ownership, and supporting growth.
• Delegate effectively based on team strengths, development goals, capacity, and operational needs while maintaining accountability for outcomes.
• Define and drive the security incident response roadmap and strategic priorities, including maturing agentic incident response, structured threat hunting, and insider risk investigations as sustained, scaled capabilities rather than one-time builds.
• Balance competing priorities across incident response, strategic initiatives, and team development; make tradeoffs clear and push back when timelines, approaches, or requests create unnecessary risk or unsustainable workload.
• Scale team capacity through AI-assisted tooling and automation, maintaining appropriate controls around human judgment, approval, auditability, and rollback.
• Oversee detection, triage, containment, remediation, and post-incident learning, serving as an escalation point and incident manager for complex or high-severity events.
• Partner with Detection Engineering, Cyber Threat Intelligence, Red Team and other teams to improve cross-functional processes and close detection or response gaps identified through investigations.
• Evolve playbooks, training, tabletop exercises, metrics, and reporting to strengthen operational readiness and program maturity.
• Participate in the on-call rotation, serving as the leadership escalation or incident manager during major or complex incidents.
• Track and report on incident trends, operational metrics, and program maturity, including the impact of automation and AI tooling on response time and coverage.
USA-based roles only: The annual base salary for this role is between $192,000 USD and $278,000 USD, plus immediate participation in 1Password’s benefits program (health, dental, 401k and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.
Canada-based roles only: The annual base salary for this role is between $171,000 CAD and $248,000 CAD, plus immediate participation in 1Password’s generous benefits program (health, dental, RRSP and many others), utilization of our generous paid time off, an equity grant and, where applicable, participation in our incentive programs.
At 1Password, we approach each individual’s compensation with a promise of fair market value and internal equity commensurate with experience and specific skill set.
This posting is for an existing vacancy.
Our culture
At 1Password, we prioritize collaboration, clear and transparent communication, receptiveness to feedback, and alignment with our core values: keep it simple, lead with honesty, and put people first.
You’ll be part of a team that challenges the status quo, and is excited to experiment and iterate in search of the best solution. That said, 1Password is not for everyone . Our work is demanding, we strive for excellence, and the pace is fast. We need people who are keen to take on challenging problems, who seek feedback to grow, and who are driven to make an impact. If you’re looking for a place where you can settle into a comfortable routine, this might not be the right fit for you. We’re looking for individuals who are proven experts in their fields, as well as those who are highly adaptable, can thrive in ambiguity and through change, are curious, and above all deliver results.
How we work with AI
We are committed to leveraging cutting-edge technology—including AI—to achieve our mission. We also understand that thinking critically about AI in its current forms will help us create better solutions for our customers and ourselves with its future forms, which will help us continue to close the gap between security and privacy and achieve our mission. We want team members at all levels to take the approach of actively learning AI best practices, identifying opportunities to apply AI in meaningful ways, and driving innovative solutions in their daily work. Embracing the future of AI isn’t just encouraged—it’s an essential part of how we will be successful at 1Password.
This approach extends to our hiring process—candidates are welcome to use AI tools responsibly and thoughtfully during the application process. To us, this means we do ask that you join live interviews without using AI tools so we can get to know how you communicate, solve problems, and collaborate with others.
Our approach to remote work
We believe in the power of remote work, but recognize that in-person connection is important to help us achieve our mission. While we are a remote-first company, travel for in-person engagement is a part of almost all roles, and we require our employees to be ready and willing to take part. Frequency will depend on role and responsibilities, and may include, but is not limited to: annual department-wide offsites, team meetings, and customer/industry events.
What we offer
We believe in working hard, and rewarding that hard work through our benefits. While not an exhaustive list, here is a glance at what we currently offer:
Health and wellbeing
Maternity and parental leave top-up programs
Competitive health benefits
Generous PTO policy
Growth and future
RSU program for most employees
Retirement matching program
Free 1Password account
Community
Paid volunteer days
Peer-to-peer recognition through Bonusly
Remote-first work environment
*Some roles in our GTM team are currently being hired for in-person hybrid work in Toronto and Austin. These roles will specify on the posting.
You belong here.
1Password is proud to be an equal opportunity employer. We are committed to fostering an inclusive, diverse and equitable workplace that is built on trust, support and respect. We welcome all individuals and do not discriminate on the basis of gender identity and expression, race, ethnicity, disability, sexual orientation, colour, religion, creed, gender, national origin, age, marital status, pregnancy, sex, citizenship, education, languages spoken or veteran status. Be yourself, find your people and share the things you love.
Accommodation is available upon request at any point during our recruitment process. If you require an accommodation, please speak to your talent acquisition partner or email us at View email address on jobicy.com and we’ll work to meet your needs.
Remote work is a part of our DNA. Given that our company was founded remotely in 2005, we can safely say we’re experts at building remote culture. That said, remote work at 1Password does mean working from your home country. If you’ve got questions or concerns about this, your talent partner would be happy to address them with you.
Successful applicants will be required to complete a background check that may consist of prior employment verification, reference checks, education confirmation, criminal background, publicly available social media, credit history, or other information, as permitted by local law.
1Password uses artificial intelligence (AI) and machine learning (ML) technologies, including natural language processing and predictive analytics, to assist in the initial screening of employment applications and improve our recruitment process. See here for the latest third party bias audit information. If you prefer not to have your application assessed using AI/ML features, you may opt out by completing this form . For additional information see our Candidate Privacy Notice .
Jobicy JobID: 153123$175.1k - $236.9k
...looking for an experienced security leader to join the Cloud... ...you will own building and managing a team of incident managers and technical leaders... ...is a must.Key job responsibilities- Build and lead a high-performing... ...- Experience managing remote team members- Experience in...Remote workFlexible hoursShift workNight shift- ...productivity without compromising security by ensuring every identity... ...leading enterprise password manager and pioneered Unified Access... .... As our Manager, Security Incident Response, you are at the center of... ...ships to customers. This is a remote opportunity within Canada...Remote workFull timeImmediate start
- ...Samsara Inc. is seeking aSecurity Incident Response leader to monitor security events, manage incidents end-to-end, and drive forensics investigations across the... ...practical security leadership in a fast-growing, remote-friendly organization. You will work within the Security...Remote work
$170k - $210k
A leading security consultancy in the United States is seeking a Security Operations Leader to drive their global operations strategy... ...a high-performing team for 24/7 security monitoring, incident response, and ensuring regulatory compliance. Candidates should have...Suggested- ...Parts seeks a seasoned Director of Security Operations to lead the security operations... ...program, oversee threat detection, incident response, vulnerability management, and monitoring across the... ...leadership, with 4 days in office and 1 day remote per week at the Raleigh, NC...Remote workWork at office1 day per week
$130k - $150k
...services, personal insurance, retirement, and private wealth management products and services. With over $5 billion in revenue and... ...Job Description In this role, you will manage the Security Incident Response team; for detecting and identifying cyber threats, as well...Full timeImmediate start- ...Incident Ops Team The Incident Ops team is a global 24/7 team responsible for driving incident response and management from detection to resolution. Stripe is proud of its five 9s reliability... ...service outages, critical bugs, security attacks and anything that...Remote work
- ...About the team Abuse Operations is the front-line incident response and remediation function handling active product abuse... ...This multi-disciplinary group, spanning Incident Managers, Investigators, Forward Deployed Security Engineers, and Data Scientists, neutralizes active...Full time
- Everforth ECS seeks a Director of Security Operations to lead SOC analysts, detection engineers... ...cyber threat intelligence teams in a remote, senior leadership role. You will... ...enterprise environments, and coordinate incident response with executive and customer...Remote job
- ...A cybersecurity consulting firm is seeking an Incident Response Analyst to support incident management for federal contracts. The role includes event triage,... ...understanding of federal cybersecurity frameworks. Remote work is permitted with occasional on-site duties in...Remote work
- ...Cybersecurity Incident Response Specialist We're on the hunt for a Cybersecurity Incident Response Specialist with the curiosity of a... ...thrive on turning chaos into clarity. You'll investigate security incidents, perform digital forensics, analyze malware, and help...Remote work
- ...As the Incident Response Lead, this full-time remote position will manage client security incidents, directing response efforts, establishing protocols, and coordinating communications during critical events while building and refining the incident response practice....Remote workFull time
- ...across the globe to create, secure, and run applications that enhance... ...Security Engineer III _ Incident Response F5 Office of the CISO |... ...attack techniques, incident management, technical communications, cross... ...business days per quarter. Remote: Primarily work from designated...Remote workWork at officeLocal areaWork from home
$140k - $170k
...services - economic and management consulting - are... ...investigations space, your responsibilities as an Associate... ...limited to):Leading security and privacy investigations... ..., threat analysis, incident response and malware... ...periods), additional remote work options are offered...Remote workWork at officeLocal areaWork from home3 days per week$118.65k - $182.71k
10279- Manager, Security Incident Response Location: Irvine, HQ Company Overview Hyundai AutoEver America (HAEA) is the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide...Full timeWork experience placementLocal area- ...onsite with Monday and Friday remote. Key Skills:... ...level analyst in the area of incident response with experience working in a... ...understanding of information security concepts, protocols, tools,... ...level request and incident management General firewall knowledge...Remote workMonday to Friday3 days per week
- ...DeepSeas is seeking a Senior SOC Analyst (L2) to drive client‑facing detection and response outcomes. You will lead high‑severity incidents, mentor L1/L2 analysts, and turn findings from threat hunting, malware analysis, and forensics into stronger detections and playbooks...Remote job
- ...Supporting a Defense Logistics Agency program, the fully remote Cybersecurity Incident Response & Threat Detection Analyst will monitor cybersecurity threats, perform incident response actions, and analyze security events to protect the enterprise network environment....Remote work
- ...requires deep technical aptitude, strong communication, and an ability to work with clients in a remote environment across the United States. You will influence incident response across multiple client environments and collaborate with threat intel and #J-18808-Ljbffr...Remote work
- ...Managing Security Information and Event Management (SIEM) systems, the full-time Senior Cybersecurity Incident Response Administrator will deploy, install, and monitor infrastructure while... ...anomalies, with the flexibility to work remotely or onsite in Virginia. Key...Remote workFull time
- ...Owning the end-to-end incident response process, the full-time Senior Incident Response Analyst will manage tier-1 and tier-2 incidents, conduct... ...collection while working remotely. Key responsibilities Lead... ...post-incident reviews for security incidents Conduct...Remote workFull time
$140k - $150k
...DescriptionEverforth ECS is seeking an Incident Response Lead to work in our Washington, DC office / remote. The role is contingent upon... ...Lead to join our advanced security operations team which is a... ...proceduresComfortable interacting with executive management to communicate risk and...Remote workWork at office- Kentro is seeking a Major Incident Management (MIM) Support Specialist to provide technical leadership in VA End User support and operations... ...facilitation, and proactive improvements to incident response metrics. Remote within the United States with EST alignment, offering a...Remote job
$230k
...Manager, Security GRC Salary: Starting at $230k + bonus Location: Remote *We are unable to provide sponsorship for this role*... ...Automation, Orchestration, and Response (SOAR). ~ Proven experience... ...techniques. Partner with Incident Response, Enterprise Architecture...Remote work- ...Leidos in Arlington, VA seeks a Senior Incident Response Analyst to join the DHS CISA SOC program, driving incident detection, response, and threat analysis to protect government networks. You will coordinate investigations, analyze indicators, and develop playbooks...Remote job
- FICO is seeking a Senior/Lead Incident Response Engineer to lead defensive security operations, owning detection, containment, and recovery from incidents. You... ..., including AI/automation integration in IR workflows. Remote options are available. #J-18808-Ljbffr FICORemote job
- ...University of Rochester, operating in Remote Work - New York, is seeking an Incident Response Rep IV to support day-to-day information security operations and triage. You will verify, classify and document events, escalating incidents as required, and provide first- and...Remote job
- ...Switch is seeking an Incident Commander to lead regional response during active data center incidents. You will coordinate Mission Control, Site Operations, Engineering, and customer-facing teams to achieve incident objectives, restoration, and formal closure. Ideal...Remote job
- ...Atlassian is seeking a Senior Incident Response Analyst to lead security incidents across our corporate and cloud environments. You will hunt for signs of compromise, coordinate cross-functional responses, and develop automated playbooks to improve detection and remediation...Remote job
- ...University of Rochester is seeking a security operations professional to support day-to-day information security incident response and triage. You will verify and document events... ...requires on-call rotation and involves managing security tools, analyzing threats, and contributing...Remote job
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Remote Manager, Security Incident Response. Be the first to apply!
- senior director information security Remote
- program manager with security clearance Remote
- security operations manager Remote
- physical security manager Remote
- director information security Remote
- corporate security manager Remote
- security manager Remote
- senior security manager Remote
- surveillance manager Remote
- security engineering manager Remote




