Jobs and Careers
ID

Senior Application & Product Security Architect (Remote)

ID.me
United States (U.S.), United StatesRemotefull_timeVerifiedPosted 30 Jun 2023

About the role

Company Overview

ID.me simplifies how people securely prove and share their identity online. The company empowers people to control their data through a portable and trusted login, which means they don’t need to create a new password when visiting sites that have the ID.me button.

The COVID-19 pandemic accelerated digital migration for many critical services. Those services require a trusted identity to safeguard against fraud and help ensure people are who they claim to be. With ID.me, login and identity credentials move with people, which can reduce the time and frustration of having to verify at multiple sites and set up multiple passwords.

ID.me is a credential service provider compliant with federal standards for digital identity verification. 

In addition to helping people control their credentials and data, the company’s “No Identity Left Behind” initiative strives to expand access and inclusion for all people. The company offers multiple pathways to verification – online self-serve, live video chat agents, and in person. ID.me is passionate about building a robust identity network that does not compromise access for traditionally underserved groups.

Role Overview

ID.me is looking for a Senior Application and Product Security Architect to add to our growing security team. As ID.me continues to expand at a rapid pace, we need strong security professionals to help build highly scalable and secure products. Our Senior Application Security Architect will have the opportunity to provide thought leadership in the areas of secure software development, deployment pipelines, testing practices, and product vulnerability management. 

Responsibilities

  • Assist in the development and maintenance of secure software development lifecycle methodologies and pipelines to ensure security is part of every phase of development and deployment
  • Support the creation and deployment of a rigorous threat modeling methodology to be used as a foundation for risk management, development priorities, and testing schedules
  • Brainstorm opportunities to improve time to market by improving the efficiency and effectiveness of the product and application security process
  • Influence and participate in activities to support theIntegration of security controls throughout the SDLC
  • Perform design reviews of new applications and products
  • Provide developer education and awareness about secure coding principles
  • Participate in the security testing efforts against our applications, including code reviews, black/white box testing of applications, and maintaining a continuous testing methodology

Desired Qualifications

The qualifications below are ideal, but not all are required.  We encourage candidates to apply if they satisfy some, but not all of the qualifications.

  • 7+ years of experience in information security or equivalent experience
  • 5+ years of experience in hands-on application and product security disciplines or equivalent experience
  • Experience with threat modeling, systems analysis, and/or security design reviews
  • Excellent written and verbal communication skills
  • Understanding of application and product architectures, scripting based programming languages, web application stacks, and general approaches to implementation of an SDLC
  • Demonstrate excellent judgement in prioritizing security efforts to mitigate the appropriate risks
  • Ability to identify, analyze, and explain the present or future needs for proposed security initiatives to senior management
  • Ability to influence with empathy and compassion

Ideal candidate will thrive in our culture if they have a passion for:

  • Building quality products with a mindset on safety and security
  • Operating in a fast-moving and high-growth environment
  • Working as a team player with an entrepreneurial work ethic
  • Security, learning and continuous improvement

Note that candidates must be located in the continental U.S.

ID.me Covid Vaccination Requirement

ID.me has a mandatory vaccination requirement where not prohibited by applicable federal or state law.

All current and future employees are required to receive their COVID-19 vaccinations, unless a reasonable accommodation is approved. Employees not in compliance with this policy will be placed on leave and will be terminated if no valid reason for not getting the COVID-19 vaccine is provided.  

Purpose: In accordance with ID.me's duty to provide and maintain a workplace that is free of known hazards, we are adopting this policy to safeguard the health of our employees and their families; our customers and visitors; and the community at large from COVID-

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ID.me

View company profile →