Director of Application and Product Security (Remote)

United States (U.S.)

Applications have closed

ID.me

ID.me Wallet simplifies how individuals discover and access benefits and services through a single login and verified identity.

View company page

Company Overview

ID.me is simplifying how individuals securely prove and share their identity online. With their secure digital identity network, ID.me is doing for identity what Visa did for financial transactions. ID.me empowers people to fully control their own data through a portable and trusted login so they don’t need to create a new password at each site they visit.

The COVID-19 pandemic has accelerated a massive digital migration for many critical services. These services require a trusted identity to ensure an individual is who they claim to be while keeping out fraud. Identity verification that serves only one organization is costly and time-intensive. Separate passwords for each application add to consumer frustration. With ID.me, login and identity credentials move with an individual so they only need to verify once.

ID.me is a federally-certified identity provider at the highest standards NIST has set for consumer identity verification and login. ID.me is one of only four companies in the United States of America certified by the federal government to bind a legal identity to a digital login.

In addition to providing individuals with complete control over their credentials and data, the company has a “No Identity Left Behind” initiative to expand access and inclusion for all individuals through a video chat verification process. ID.me is passionate about building a robust identity network that does not compromise access for hard-to-identify groups.

Role Overview

ID.me is looking for a Director of Application and Product Security to add to our growing security team. As ID.me continues to expand at a rapid pace, we need an application and product security leader to ensure our products and applications are being built in secure and scalable ways.

The Director of Application and Product Security will also have the opportunity to provide thought leadership in the areas of secure software development, deployment pipelines, testing practices, and product vulnerability management. A candidate in this role will need to be able to move quickly to adjust to business needs, and build a strong security culture in software engineering.

Responsibilities

  • Build and maintain secure software development lifecycle methodologies and pipelines to ensure security is part of every phase of development and deployment
  • Build a rigorous threat modeling methodology to be used as a foundation for risk management, development priorities, and testing schedules
  • Provide a data-driven perspective on application and product security risks
  • Identify opportunities to improve time to market by improving the efficiency and effectiveness of the product and application security process
  • Build and manage a team of application and product security professionals
  • Partner closely with engineering and product teams to ensure alignment to long term goals
  • Identify opportunities for innovation and thought leadership in the service of demonstrating ID.me’s commitment to security
  • Build a robust strategy and implementation plan for comprehensive testing of the ID.me application portfolio, from developer IDE through production release. This will include both bug bounty and penetration testing programs.

Ideal Qualifications

The qualifications below are ideal, but not all are required.  We encourage candidates to apply if they satisfy some, but not all of the qualifications.

  • 7+ years of experience in application and product security
  • Ability to lead a small developing team and increase reach and capabilities over time
  • Experience with threat modeling, security design reviews, and security architecture
  • Excellent written and verbal communication skills to enable the translation of security objectives to engineering team
  • Deep understanding of application and product architectures, programming languages, web application stacks, and SDLC pipelines
  • Demonstrate excellent judgment in prioritizing security efforts to mitigate the appropriate risks
  • Ability to identify, analyze, and explain the present or future needs for proposed security initiatives to senior management
  • Track record of innovation and engineering enablement
  • Must be located in the Continental U.S.

Ideal candidate will thrive in the following culture:

  • Must have an obsession for quality and impactful products 
  • Ability to thrive when there are changing priorities and shifting of gears
  • Ability to learn quickly and adapt in a rapidly changing environment
  • Strong oral and written communication skills
  • Must be a team player with a strong, self-managing work ethic
  • Must be a self-starter with a passion for security, learning and continuous improvement

Note that candidates must be located in the continental U.S.

 

ID.me Covid Vaccination Requirement

All current and future employees are required to receive their COVID-19 vaccinations, unless a reasonable accommodation is approved. Employees not in compliance with this policy will be placed on leave and will be terminated if no valid reason for not getting the COVID-19 vaccine is provided.  

Purpose: In accordance with ID.me's duty to provide and maintain a workplace that is free of known hazards, we are adopting this policy to safeguard the health of our employees and their families; our customers and visitors; and the community at large from COVID-19 that may be reduced by vaccinations. This policy will comply with all applicable laws and is based on guidance from the Centers for Disease Control and Prevention and local health authorities, as applicable.

Reasonable Accommodation: Current and future employees in need of an exemption from this policy due to a medical reason, or because of a sincerely held religious belief must submit a completed Request for Accommodation form to the human resources department to begin the interactive accommodation process as soon as possible after vaccination deadlines have been announced (September 13th) and an offer of employment has been made. Accommodations will be granted where they do not cause ID.me undue hardship or pose a direct threat to the health and safety of others.

 

Vision: To be the world's leading digital identity network empowering people to control their own information and to prove their credentials across all channels: online, call center, and in-person.

Mission: To make the world a more trusted place by delivering the highest level of security with the least amount of friction at the lowest possible cost. 

People: We have an audacious mission. We aim to fix the identity layer of the internet. Billions of people will live better lives with more trust and convenience thanks to ID.me. We are like Special Forces. We take on the most difficult challenges with amazing teammates.  

ID.me Core Values: *Don't be a jerk. *Always compete. *Ask questions like a 5-year old. *Inspire people with your passion. *Make something better every day. *Treat each customer like your favorite family member. *Own your mistakes so you can learn from them. *Details are everything. *Communicate like a scientist. *Be truthful (even when it's hard). *Reflect ID.me's values in your actions. *Act like an owner.

ID.me Career Site & Culture Deck: https://www.id.me/careers

ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.

 

Please review our Privacy Policy, including our CCPA policy, at id.me/privacy. If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.

 

ID.me participates in E-Verify.

 

#LI-JS1

#LI-REMOTE

Tags: Application security CCPA Compliance NIST Pentesting Privacy Product security Risk management SDLC Strategy Vulnerability management

Perks/benefits: Career development Flex vacation Health care Medical leave

Regions: Remote/Anywhere North America
Country: United States
Job stats:  4  0  0
Category: Leadership Jobs

More jobs like this

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.