Logo
ID.me

Product Security Engineer

ID.me, Mountain View, California, us, 94039

Save Job

Company Overview

ID.me is the next‑generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800‑63‑3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/. Role Overview

ID.me is looking for a Product Security Engineer to join our Product Security organization as an execution‑focused individual contributor. If you love deep technical work, building security solutions, and solving complex security challenges, here's your chance to make a career of it by advancing the digital identity ecosystem while protecting millions of users. As one of the most targeted identity platforms in the country, ID.me safeguards a massive volume of sensitive PII—making Product Security the tip of the spear in defending against sophisticated adversaries and ensuring our products remain resilient at scale. We are seeking a highly skilled security engineer who excels at implementing and fixing security issues across software and cloud, building automation, and executing complex technical projects. As a Product Security Engineer, you will be a technical expert who delivers production‑ready technology solutions, solves the hardest problems, and performs deep technical security assessments that directly strengthen the security of our products. Your work will shape the defensive foundation of a platform relied upon nationwide, giving you the opportunity to make a meaningful, visible impact on the safety and trust of millions of users. This role is based out of our Mountain View, CA or McLean, VA offices and requires full‑time in‑office attendance. What You’ll Do

Implement complex security solutions, including Cloud and SaaS security, and service account protections, and Application Security. Build production‑ready security automation using Python or Java to scale security operations and reduce manual toil Execute security projects from requirements through deployment with minimal guidance, delivering high‑quality results on time Trouble‑shoot complex security issues in production environments, conducting deep technical analysis and implementing fixes quickly Implement GKE security controls Build and maintain cloud security infrastructure using Terraform Configure GCP security services such as VPC Service Controls, Private Service Connect, Cloud Armor policies, IAM roles, and Secret Manager Execute API security assessments by conducting security reviews, identifying vulnerabilities, and implementing remediation Execute vulnerability remediation workflows for application, container, Cloud, and SaaS vulnerabilities within defined SLAs Build security dashboards and reporting to track vulnerability MTTR, security control effectiveness, and false positive rates

Basic Qualifications

5+ years in security and/or software engineering, with focus on implementation and execution 5+ years of hands‑on programming in Python or Java with demonstrated ability to build production‑quality security tooling and automation 3+ years of hands‑on GCP experience including GKE, Cloud Run, IAM, Secret Manager, and security services Container / mesh networks (GKE, Docker, Kubernetes security, image scanning, Binary Authorization, SBOM) Infrastructure‑as‑code proficiency (Terraform preferred) for deploying and maintaining security infrastructure Troubleshooting expertise with ability to debug complex issues in production cloud environments Preferred Qualifications

GCP Professional Cloud Architect or Professional Cloud Security Engineer certification OSCP or comparable hands‑on offensive‑security certifications (e.g., OSEP, GXPN, PNPT) demonstrating strong adversarial reasoning and exploit‑focused problem‑solving capability. Experience with offensive‑security methodologies (e.g., understanding attack chains, exploitation fundamentals, or red‑team tooling) applied to defensive engineering contexts Interest in applied security research—such as vulnerability discovery, protocol analysis, or emerging‑threat investigation ID.me offers comprehensive medical, dental, vision, health savings account, flexible spending accounts (medical, limited purpose, dependent care, commuter benefit accounts), basic and voluntary life and AD&D insurance, 401(k) with company match, parental leave, ability to participate in unlimited paid time off subject to the terms and conditions of the PTO policy, including 8 company wide holidays, short and long‑term disability insurance, accident and critical illness insurance, referral bonus policy, employee assistance program, pet insurance, travel assistant program, wellbeing and childcare discounts, benefit advocates, and a learning and development benefit. The above represents the anticipated total rewards package for this job requisition. Final offers may vary from the amount listed based on qualifications, skills, education, relevant training, geographic location and role. U.S. Pay Range $127,500 - $149,939 USD Mountain View, CA Pay Range $134,716 - $167,637 USD ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations. ID.me participates in E-Verify.

#J-18808-Ljbffr