1Password is a leading cybersecurity company focused on building a safe and productive digital future. They are seeking a Staff Security Engineer to lead the DevSecOps function within their Corporate Security team, responsible for shaping developer security practices and ensuring secure software development processes.
Responsibilities:
- Own the DevSecOps function: You'll have the latitude and mandate to build a well-run, properly owned developer security program at 1Password. You'll set the technical direction, define the operating model, and drive it with a counterpart in Infrastructure Security. This is a high-ownership, high-impact role, and the decisions you make here will shape how engineering builds securely for years
- Own GitHub and CI/CD security: Lead the program to harden 1Password's GitHub Enterprise environment and CI/CD pipelines. This includes governance frameworks, repository standards, Actions security, audit visibility, and the controls that make secure defaults the easy path for engineering teams
- Define AI-assisted development security: As 1Password's engineering teams adopt AI coding tools and agentic workflows, you'll own the security model for how that happens. You'll build the guardrails, define the governance standards, and ensure that agentic and AI-generated code workflows meet our risk and compliance requirements. This is a genuinely novel problem space and you'll be setting the direction, not following a playbook
- Harden the software supply chain: Drive and work with partner teams on improvements to dependency hygiene, secret management practices, token governance, and secure package consumption across the engineering organization. Design controls that scale and that teams can adopt with minimal friction
- Set standards engineering teams actually use: Build secure templates, baseline configurations, and developer-friendly guardrails that engineering teams adopt because they make their work easier, not just because security requires it. Good DevSecOps is invisible when it works
- Partner with Platform Engineering: Work closely with Platform Engineering as a peer-level security partner, ensuring that developer tooling and platform infrastructure evolve with security embedded in the design rather than added after the fact
- Elevate the team and the org: Mentor engineers across Corporate Security and the broader Security Operations organization. Actively distribute ownership to scale your impact and create growth opportunities for others. Contribute to the hiring process and help develop how we assess candidates
- Support Corporate Security operations: Participate in the Corporate Security on-call rotation. Contribute to investigations involving developer tooling, credential exposure, or workflow misuse when they arise
Requirements:
- Minimum of 8 years of combined experience in security engineering, DevSecOps, platform security, or closely related engineering roles, with deep focus on securing developer environments, CI/CD, or software supply chains
- Deep, hands-on expertise in GitHub Enterprise security and governance, including branch protections, secret scanning, access controls, repository standards, Actions security, and audit logging at scale
- Proven ability to design and implement security controls that integrate into CI/CD pipelines without meaningfully degrading developer velocity. Experience with GitHub Actions and familiarity with how pipeline security scales across a large engineering organization
- Solid understanding of software supply chain security within developer environments, including dependency hygiene (npm, pip, and similar), token and secret management, secure package consumption practices, and SBOM generation
- Practical experience solving security challenges introduced by AI-assisted and agentic development. We are looking for evidence that you've engaged seriously with the problem: you've made real calls about how to govern AI coding tools in a production environment, defined policy and technical controls for tools like Copilot, Cursor, or Claude Code
- Comfortable making architectural decisions that span multiple teams. You set standards and patterns that other engineers adopt; you don't just produce individual deliverables. Experience designing scalable, reusable security controls that prevent entire classes of future problems
- Strong scripting and automation skills in Python, Bash, Terraform, or similar, with demonstrated ability to build tooling that scales security controls without proportional manual effort
- Ability to build alignment with Platform Engineering and other engineering stakeholders, translate security requirements into developer-friendly implementations, and influence engineering-wide standards without direct authority
- A track record of elevating the people around you through mentorship, documentation, and deliberately creating growth opportunities for other engineers. Staff-level impact means the team gets better because you're in it
- Experience participating in on-call rotations and contributing to investigations involving developer tooling, source control, or credential exposure. Familiarity is a must, expertise is a nice to have