Jobs and Careers
ID

Senior Product Security Engineer

ID.me
Mountain View, United Statesfull_timeVerifiedPosted 1 May 2026
💰 $230,000/yr($189,395/yr$230,000/yr)

About the role

Company Overview

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.

Role Overview

ID.me is looking for a Senior Product Security Engineer to join our Product Security organization as an execution-focused individual contributor. If you love deep technical work, building security solutions, and solving complex security challenges, here's your chance to make a career of it by advancing the digital identity ecosystem while protecting millions of users. As one of the most targeted identity platforms in the country, ID.me safeguards a massive volume of sensitive PII—making Product Security the tip of the spear in defending against sophisticated adversaries and ensuring our products remain resilient at scale.

We are seeking a highly skilled security engineer who excels at implementing and fixing security issues across software and cloud, building automation, and executing complex technical projects. As a Senior Product Security Engineer, you will be a technical expert who delivers production-ready technology solutions, solves the hardest problems, and performs deep technical security assessments that directly strengthen the security of our products. Your work will shape the defensive foundation of a platform relied upon nationwide, giving you the opportunity to make a meaningful, visible impact on the safety and trust of millions of users.

This role is based out of our Mountain View, CA or McLean, VA offices and requires full-time in-office attendance.

 

Responsibilities

  • Lead the design and implementation of secure, scalable cloud security architectures across GCP, Kubernetes, and containerized workloads.
  • Deliver security automation frameworks (Python or Java) that reduce operational risk and increase organizational security maturity.
  • Build production-ready security automation using Python or Java to scale security operations and reduce manual toil
  • Execute security projects from requirements through deployment with minimal guidance, delivering high-quality results on time
  • Troubleshoot complex security issues in production environments, conducting deep technical analysis and implementing fixes quickly
  • Implement GKE security controls 
  • Build and maintain cloud security infrastructure using Terraform
  • Configure GCP security services such as VPC Service Controls, Private Service Connect, Cloud Armor policies, IAM roles, and Secret Manager
  • Execute API security assessments by conducting security reviews, identifying vulnerabilities, and implementing remediation
  • Execute vulnerability remediation workflows for application, container, Cloud, and SaaS vulnerabilities within defined SLAs
  • Build security dashboards and reporting to track vulnerability MTTR, security control effectiveness, and false positive rates
  • Conduct deep technical security assessments—API, application, GKE, and infrastructure layers—and implement durable, production-ready solutions.
  • Serve as a technical escalation point for cloud, IAM, GKE, and Terraform-related security issues; provide expert troubleshooting for high-severity incidents.
  • Implement advanced GCP security controls including VPC Service Controls, Private Service Connect, sensitive service perimeter enforcement, and automated IAM governance.
  • Partner with Infrastructure, Platform, AppSec, and Compliance teams to ensure a unified, secure-by-default cloud architecture.

 

Basic Qualifications

  • 8+ years of experience in security engineering, cloud engineering, or software engineering with a focus on implementation and architecture.
  • 7+ years of hands-on programming experience in Python or Java.
  • 6+ years of GCP experience including GKE, Cloud Run, IAM, Secret Manager, VPC SC, and rela

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

ID.me

View company profile →