Senior Security Engineer (Remote)
United States (U.S.)
ID.me simplifies how people securely prove and share their identity online. The company empowers people to control their data through a portable and trusted login, which means they don’t need to create a new password when visiting sites that have the ID.me button.
The COVID-19 pandemic accelerated digital migration for many critical services. Those services require a trusted identity to safeguard against fraud and help ensure people are who they claim to be. With ID.me, login and identity credentials move with people, which can reduce the time and frustration of having to verify at multiple sites and set up multiple passwords.
ID.me is a credential service provider compliant with federal standards for digital identity verification.
In addition to helping people control their credentials and data, the company’s “No Identity Left Behind” initiative strives to expand access and inclusion for all people. The company offers multiple pathways to verification – online self-serve, live video chat agents, and in person. ID.me is passionate about building a robust identity network that does not compromise access for traditionally underserved groups.
ID.me is looking for a Senior Security Engineer to add to our growing security team. If you love innovation, here's your chance to make a career of it by advancing the digital identity ecosystem. We are seeking a talented Senior Security Engineer who enjoys the challenges of combining software and systems engineering to design, build, run, and automate distributed, fault-tolerant security solutions at scale. You will ensure that our security infrastructure is high performance, resilient, secure and observable.
- Be an integral part of the team responsible for building and operating highly scalable and resilient security solutions such as a SIEM, IDS/IPS, EDR, firewalls, etc.
- Design and develop automation for maintenance tasks and upgrades of security tools and services
- Build automation solutions to prevent problem recurrence
- Manage end-to-end distributed security solution availability and establish observability to ensure high performance
- Become ID.me’s subject matter expert for security in our AWS and GCP cloud domains
- Plan and lead complicated security projects that interact with a wide variety of teams within the company
- Lead security integration and automation to improve detection, monitoring, and response
- Help define and iterate on processes to increase security engineering capabilities
- Utilize your deep experience and problem solving skills to help prevent and investigate production issues
- Maintain an audit-ready posture, and automate controls for security, compliance, and auditability
- Participate in an on-call rotation and hold retroactive root cause analysis meetings, focusing on identifying remediations and product resiliency opportunities
- Act as an escalation point for security analyst and a resource during incident response
- Contribute to security architecture and operations
- Collaborate with cross-functional groups such as Cloud Engineering, SRE, DevOps, etc.
The qualifications below are ideal, but not all are required. We encourage candidates to apply if they satisfy some, but not all of the qualifications.
- 7+ years of experience in security engineering, systems engineering, software engineering, or SRE roles
- 5+ years experience engineering, running, and automating security solutions
- Strong background with public cloud technologies, preferably GCP and AWS
- Strong understanding cloud-based application and infrastructure security best practices
- Experience with scaled indexed logging or SIEM solutions (e.g. Splunk, ElasticSearch, Exabeam)
- Experience in security orchestration, integration, and automation
- Experience in Linux/Unix administration and solid networking knowledge
- Experience in scripting (ie Bash, Python, and/or Ruby)
- Experience with infrastructure-as-code (e.g. cloud proprietary solutions such as CloudFormation or Terraform)
- Experience with observability tools (New Relic, Prometheus, InfluxDB, Grafana, Splunk etc)
- Experience with end-to-end debugging of infrastructure and application performance & issues
- Experience in supporting a 24/7 infrastructure including on-call rotations
- Solid understanding of cloud-based application architecture and scaling
- The ability to take a systematic approach to analyzing, troubleshooting, and diagnosing system problems to identify, locate, resolve, and repair problems
- Possess a breadth of engineering skills with an interest in service reliability, automation, monitoring, and capacity planning
- Bonus: Experience with CI/CD practices and platform tools (Jenkins, CircleCI, Github etc)
- Bonus: Experience with container computing and container orchestration (e.g. proprietary systems such as Amazon ECS, multi-cloud solutions such as Kubernetes, or Nomad)
- Bonus: Experience with configuration management systems (e.g. Ansible, Puppet, Chef, Saltstack, Consul)
- Bonus: Experience with Information Security Compliance, (SOC, FedRAMP, ISO, etc)
- Bonus: Industry security certifications, such as GCIH/ECIH, Security+, or related
Ideal candidate will thrive in the following culture:
- Must have an obsession for building quality products
- Ability to thrive when there are changing priorities and shifting of gears
- Strong oral and written communication skills
- Must be a team player with a strong, self-managing work ethic
- Must be a self-starter with a passion for security, learning and continuous improvement
Note that candidates must be located in the continental U.S.
ID.me Covid Vaccination Requirement
ID.me has a mandatory vaccination requirement where not prohibited by applicable federal or state law.
All current and future employees are required to receive their COVID-19 vaccinations, unless a reasonable accommodation is approved. Employees not in compliance with this policy will be placed on leave and will be terminated if no valid reason for not getting the COVID-19 vaccine is provided.
Purpose: In accordance with ID.me's duty to provide and maintain a workplace that is free of known hazards, we are adopting this policy to safeguard the health of our employees and their families; our customers and visitors; and the community at large from COVID-19 that may be reduced by vaccinations. This policy will comply with all applicable laws and is based on guidance from the Centers for Disease Control and Prevention and local health authorities, as applicable.
Reasonable Accommodation: Current and future employees in need of an exemption from this policy due to a medical reason, or because of a sincerely held religious belief must submit a completed Request for Accommodation form to the human resources department to begin the interactive accommodation process as soon as possible after vaccination deadlines have been announced (September 13th) and an offer of employment has been made. Accommodations will be granted where they do not cause ID.me undue hardship or pose a direct threat to the health and safety of others.
Vision: To be the world's leading digital identity network empowering people to control their own information and to prove their credentials across all channels: online, call center, and in-person.
Mission: To make the world a more trusted place by delivering the highest level of security with the least amount of friction at the lowest possible cost.
People: We have an audacious mission. We aim to fix the identity layer of the internet. Billions of people will live better lives with more trust and convenience thanks to ID.me. We are like Special Forces. We take on the most difficult challenges with amazing teammates.
ID.me Core Values: *Don't be a jerk. *Always compete. *Ask questions like a 5-year old. *Inspire people with your passion. *Make something better every day. *Treat each customer like your favorite family member. *Own your mistakes so you can learn from them. *Details are everything. *Communicate like a scientist. *Be truthful (even when it's hard). *Reflect ID.me's values in your actions. *Act like an owner.
* Salary range is an estimate based on our salary survey 💰
Tags: Ansible Automation AWS Bash CCPA CI/CD CircleCI Cloud Compliance DevOps EDR Elasticsearch Exabeam FedRAMP Firewalls GCIH GCP GitHub Grafana IDS Incident response IPS Kubernetes Linux Monitoring Privacy Prometheus Puppet Python Ruby Scripting SIEM Splunk Terraform UNIX
Other jobs like this
Senior Security Engineer - Compliance OperationsCI/CD Cloud Compliance Computer Science DevOps FedRAMP GDPR +9
401(k) matching Career development Competitive pay Equity Health care +1
Staff Engineer - Information SecurityAgile Automation Cloud Compliance Monitoring Privacy SaaS
401(k) matching Career development Competitive pay Equity Health care +1
Explore more Cybersecurity career opportunities
Find open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Analysis, Cryptography, Digital Forensics and Cyber Security in general, filtered by job title or popular skill, toolset and products used.
- Open Infrastructure Security Engineer jobs
- Open Information Security Officer jobs
- Open Head of Information Security jobs
- Open IT Security Engineer jobs
- Open Information System Security Officer (ISSO) jobs
- Open Security Consultant jobs
- Open Senior Information Security Analyst jobs
- Open Senior Penetration Tester jobs
- Open SOC Analyst jobs
- Open Lead Security Engineer jobs
- Open Senior Infrastructure Security Engineer jobs
- Open Sr. Security Engineer jobs
- Open Cyber Security Architect jobs
- Open Senior Air Defense/BMD Subject Matter Expert jobs
- Open Senior SOC Analyst jobs
- Open Cyber Security Specialist jobs
- Open Senior Security Analyst jobs
- Open Staff Security Engineer jobs
- Open Staff Application Security Engineer jobs
- Open Information Security Specialist jobs
- Open Application Security Engineer/Architect jobs
- Open Staff Product Security Engineer jobs
- Open Senior Information Security Engineer jobs
- Open Offensive Security Engineer jobs
- Open Security Researcher jobs
- Open Clearance-related jobs
- Open Pentesting-related jobs
- Open Agile-related jobs
- Open GCP-related jobs
- Open SaaS-related jobs
- Open Malware-related jobs
- Open Analytics-related jobs
- Open Java-related jobs
- Open Threat intelligence-related jobs
- Open Vulnerability management-related jobs
- Open ISO 27001-related jobs
- Open Kubernetes-related jobs
- Open Forensics-related jobs
- Open DevOps-related jobs
- Open APIs-related jobs
- Open CISM-related jobs
- Open CISA-related jobs
- Open CI/CD-related jobs
- Open SQL-related jobs
- Open IDS-related jobs
- Open DevSecOps-related jobs
- Open Security assessment-related jobs
- Open Splunk-related jobs
- Open Finance-related jobs
- Open PowerShell-related jobs