Director of Cybersecurity (Remote)
United States (U.S.)
ID.meID.me simplifies how individuals share and prove their identity online. ID.me's next generation platform facilitates identity proofing, authentication, and group affiliation verification for over 500 organizations.
ID.me is simplifying how individuals securely prove and share their identity online. With their secure digital identity network, ID.me is doing for identity what Visa did for financial transactions. ID.me empowers people to fully control their own data through a portable and trusted login so they don’t need to create a new password at each site they visit.
The COVID-19 pandemic has accelerated a massive digital migration for many critical services. These services require a trusted identity to ensure an individual is who they claim to be while keeping out fraud. Identity verification that serves only one organization is costly and time-intensive. Separate passwords for each application add to consumer frustration. With ID.me, login and identity credentials move with an individual so they only need to verify once.
ID.me is a federally-certified identity provider at the highest standards NIST has set for consumer identity verification and login. ID.me is one of only four companies in the United States of America certified by the federal government to bind a legal identity to a digital login.
In addition to providing individuals with complete control over their credentials and data, the company has a “No Identity Left Behind” initiative to expand access and inclusion for all individuals through a video chat verification process. ID.me is passionate about building a robust identity network that does not compromise access for hard-to-identify groups.
ID.me is looking for a Director, Cybersecurity. This position reports directly to the Chief Information Security Officer. The Director of Cybersecurity will lead the enterprise digital and forensic incident response (DFIR) program, direct enterprise infrastructure vulnerability identification, guide remediation, and own all related information collection, analysis, and security event/incident investigation initiatives. The candidate will also own the operationalization of an enterprise security operations center (SOC), all levels of security incident response, direct the management of the enterprise threat and vulnerability management (TVM) program, and participate in red team and related exercises.
Additionally, the incumbent owns the electronic discovery function and all aspects of the eDiscovery fulfillment strategy, including technology selection, staffing, data identification, collection, preservation, normalization, deduplication and production output to Legal, Regulatory and Audit stakeholders.
- Report to CISO on security monitoring, TVM program, threat mitigations, and response actions.
- Direct and manage enterprise threat and risk intelligence analysis and reporting processes, systems, and personnel.
- Direct and oversee the company's Threat and Vulnerability Management group, Cyber Security group including the Managed Security Services Provider, and eDiscovery group.
- Direct and provide guidance related to protective intelligence, intellectual property protection, PHI/PII threat mitigation, and sensitive investigations.
- Direct and oversee the company's privileged user / trusted insider monitoring program.
- Manage the digital forensics lab, all associated forensic evidence, investigative data, collection procedures, and personnel.
- Provide oversight and contract management to vendor teams providing security monitoring services, information analysis, crisis planning and critical incident response
- Develop and manage training programs and accountability metrics for the team as well as mentor and develop internal junior and senior staff
- Develop and manage controls to ensure compliance with all internal and external security standards
- Other responsibilities include, but are not limited to: participating in special projects, system enhancements, ad hoc analyses, leading threat and vulnerability assessment teams, and/or special event security teams and facing off to external Information Sharing and Analysis Centers (ISACs) and Federal or State law enforcement institutions as appropriate.
- Lead implementation of best practices within the TVM team to scale with and match the pace of business operations
- Work closely with internal partners such as SIU, Privacy, IT and Human Resources
- Ensure compliance with company investigation and reporting standards
- Oversee the E-Discovery process and ensures the preservation, collection and delivery of all facets of electronically stored information requested for litigation, regulatory or audit requests or for international investigations.
- Manage associated capital and expense budget
The qualifications below are ideal, but not all are required. We encourage candidates to apply if they satisfy some, but not all of the qualifications.
- 10+ years experience in a combination of incident and vulnerability management, investigations, and threat intelligence.
- Expert level knowledge of leading incident response and employee investigations within cloud/on-premise environments.
- Understanding of how to effectively communicate with C-suite, Legal Counsel, Human Resources during times of crisis.
- Ability to create a sense of ownership of tasks or projects by providing clear expectations, responsibilities, mentorship, etc.
- Ability to use a range of communications skills and techniques to enable the building of positive and beneficial relationships at all levels of the organization.
- Experience formulating strategic and tactical strategies aligned with the mission, vision, and goals of the organization.
- Experience with non-windows operating systems such as (MacOS, Linux) and their filesystems.
- Expert level experience with well known vulnerabilities, exploits, and attacker TTPs/IOAs.
- Bonus: Experience with cloud technologies such as AWS, GCP, and/or Azure
- Bonus: Experience with CI/CD pipelines and containerization
- Bonus: Experience with Detection Engineering concepts & Mitre Attack
- Bonus: Experience with NIST, FedRAMP, ISA 27001
- Bonus: Experience in scripting (Bash, Python, and/or Ruby)
Ideal candidate will thrive in the following culture:
- Must have an obsession for data driven decision making and automating routine tasks.
- Ability to thrive when there are changing priorities and shifting of gears
- Strong oral and written communication skills
- Must be a team player with a strong, self-managing work ethic
- Must be a self-starter with a passion for learning and continuous improvement
Note that candidates must be located in the continental U.S.
ID.me Covid Vaccination Requirement
All current and future employees are required to receive their COVID-19 vaccinations, unless a reasonable accommodation is approved. Employees not in compliance with this policy will be placed on leave and will be terminated if no valid reason for not getting the COVID-19 vaccine is provided.
Purpose: In accordance with ID.me's duty to provide and maintain a workplace that is free of known hazards, we are adopting this policy to safeguard the health of our employees and their families; our customers and visitors; and the community at large from COVID-19 that may be reduced by vaccinations. This policy will comply with all applicable laws and is based on guidance from the Centers for Disease Control and Prevention and local health authorities, as applicable.
Reasonable Accommodation: Current and future employees in need of an exemption from this policy due to a medical reason, or because of a sincerely held religious belief must submit a completed Request for Accommodation form to the human resources department to begin the interactive accommodation process as soon as possible after vaccination deadlines have been announced (September 13th) and an offer of employment has been made. Accommodations will be granted where they do not cause ID.me undue hardship or pose a direct threat to the health and safety of others.
Vision: To be the world's leading digital identity network empowering people to control their own information and to prove their credentials across all channels: online, call center, and in-person.
Mission: To make the world a more trusted place by delivering the highest level of security with the least amount of friction at the lowest possible cost.
People: We have an audacious mission. We aim to fix the identity layer of the internet. Billions of people will live better lives with more trust and convenience thanks to ID.me. We are like Special Forces. We take on the most difficult challenges with amazing teammates.
ID.me Core Values: *Don't be a jerk. *Always compete. *Ask questions like a 5-year old. *Inspire people with your passion. *Make something better every day. *Treat each customer like your favorite family member. *Own your mistakes so you can learn from them. *Details are everything. *Communicate like a scientist. *Be truthful (even when it's hard). *Reflect ID.me's values in your actions. *Act like an owner.
ID.me Career Site & Culture Deck: https://www.id.me/careers
ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.
ID.me participates in E-Verify.
Other jobs like this
Director of Application and Product Security (Remote)Application security CCPA NIST Penetration testing Privacy Product security Risk management SDLC Strategy Vulnerability management
Career development Flex vacation Health care Medical leave
Head of Security OperationsAutomation EDR Incident response Linux Monitoring SIEM Vulnerability management Windows
Career development Equity Flex hours Flex vacation Salary bonus +2
Explore more Cyber Security career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cybersecurity in general, filtered by job title or popular skill, toolset and products used.
- Open Cyber Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Penetration Tester jobs
- Open Senior DevSecOps Engineer jobs
- Open Application Security Engineer/Architect jobs
- Open Senior Security Operations Engineer jobs
- Open Cyber Threat Intelligence Analyst jobs
- Open Head of Information Security jobs
- Open Senior Information Security Engineer jobs
- Open Lead Security Engineer jobs
- Open Staff Security Engineer jobs
- Open SOC Analyst jobs
- Open Cyber Security Analyst jobs
- Open Information System Security Officer (ISSO) jobs
- Open Cybersecurity Engineer jobs
- Open Senior Penetration Tester jobs
- Open Sr. Security Engineer jobs
- Open Senior Threat Intelligence Analyst jobs
- Open Cloud Security Automation Specialist jobs
- Open Offensive Security Engineer jobs
- Open Information Security Officer jobs
- Open Azure Security Engineer jobs
- Open Senior Information Security Analyst jobs
- Open Cloud Security Operations Lead jobs
- Open Cybersecurity Analyst jobs
- Open DevOps-related jobs
- Open Application security-related jobs
- Open Analytics-related jobs
- Open Audits-related jobs
- Open PCI-related jobs
- Open OWASP-related jobs
- Open Threat intelligence-related jobs
- Open Clearance-related jobs
- Open Security assessments-related jobs
- Open IDS-related jobs
- Open Forensics-related jobs
- Open Splunk-related jobs
- Open Ruby-related jobs
- Open Encryption-related jobs
- Open CEH-related jobs
- Open CISM-related jobs
- Open GDPR-related jobs
- Open Agile-related jobs
- Open Threat detection-related jobs
- Open Open Source-related jobs
- Open OSCP-related jobs
- Open Intrusion detection-related jobs
- Open DevSecOps-related jobs
- Open Machine Learning-related jobs