- Job type
- Full-time
- Work mode
- On-site
- Level
- Director
- Department
- Information Technology
- Experience
- Not listed
- Posted
- Aug 24, 2026
About the role
About the Role
ID.me runs one of the most heavily scrutinized identity platforms in the world, and our engineers ship fast. Product Security is how we keep that speed safe. We're looking for a leader who believes security is practical and outcome-driven; every control we ask for reduces real risk, and our job isn't done when we file a ticket; it's done when the risk is actually gone.
This is a leadership role first. You'll own the Product Security program end-to-end, lead and grow the team, and be the trusted security partner to Engineering and not its gatekeeper.
What You'll Own
- The Product Security (ProdSec) program: threat modeling, secure code and architecture review, SCA, secret scanning, vulnerability management, CSPM and configuration management; integrated across the SSDLC as scalable, shift-left, developer-aligned controls.
- People leadership: build, grow, and lead a team of security engineers. You are accountable for their development, growth, and professional well-being; not just their output.
- The rules of the road: define what is and isn't acceptable security practice for Engineering clearly, with the why, so teams can self-serve instead of waiting on you.
- Secure-by-design consulting: partner with Product and Engineering early at design and architecture time so security is built in before code ships, not bolted on after.
- Security tooling & services: the team builds and maintains tools and services that let engineers ship secure products at high velocity; adopted because they help rather than gate.
- Penetration Testing & Red Team: you're accountable for the execution and outcomes; scope, findings, and remediation.
What We're Looking For
Must Have
Outcome-based leadership. You translate business objectives into clear outcomes and keep the team focused on them. You set the requirements and constraints, guide the how without dictating it, and trust your team to own execution. You know what good looks like and reach it efficiently; the right-sized solution, delivered without micromanagement.
Accountability for results. You measure success by whether risk actually went down and whether engineers can do their jobs safely; not by how many findings you produced. You drive fixes to closure, even when another team owns the code.
Partnership with Engineering. Engineering is your customer. You default to "how do we make this work safely?" and when you must say no, you explain it in terms they value and offer a path. You assert security and compliance requirements; you don't dictate product decisions.
Speed and judgment. Assessments turn around in days, not weeks. You right-size rigor to the decision in front of you and avoid security theater.
Technical depth. You move fluently across threat modeling, code and architecture review, SCA/SAST, secret scanning, vuln management, and cloud/CSPM — enough to earn engineers' respect and coach your team.
Integrity and trust. You handle privileged access with discretion, and you build a team where sharing bad news early is safe and rewarded.
AI fluency. Our security org runs on AI daily (Claude, Gemini, custom tooling). You treat AI as a force multiplier and champion AI-augmented security workflows.
Strong Preference
- Built or matured an Application Security, Security Engineering, or Product Security program in a fast-shipping, cloud-native environment like ours: GCP, GitHub, Kubernetes/GKE, Apigee, Terraform, and modern CI/CD
- Hands-on with security tooling such as Socket.dev, Sysdig, Trivy, DependencyTrack, or HackerOne
- AI-augmented security workflows with Claude, Gemini, or Vertex AI
- Growth-stage experience where you had to build, not just maintain
About the Environment
- AI-first. The CISO's goal: make it safe for everyone to use every feature of any company-provisioned AI tool for any task. You'll help make that real.
- Practical over procedural. We prefer technical enforcement over policy documents, and real risk reduction over checkbox compliance.
- One team. Security at ID.me operates as a single organization — ProdSec, SecOps, GRC, IT, and Physical Security collaborate daily. We value leaders who build cross-functional trust and operate transparently