ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/ .
ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote‑by‑design positions — may have different work arrangements as noted in their individual postings.
At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found here .
Role Overview:ID.me is seeking a highly experienced SOC Lead to play a pivotal role in our advanced security operations. As a key member of our Security Operations team, you will be instrumental in safeguarding our digital identity ecosystem, bringing your deep expertise in incident response, threat hunting, and forensic analysis to the forefront. In this role, you will not only manage complex security incidents but also lead efforts to refine and optimize our security processes and tools. This position is ideal for a cybersecurity professional with extensive SOC experience who is looking to advance their career by taking on more responsibility, mentoring junior team members, and driving strategic initiatives within our SOC.
Key Responsibilities:
- Lead cyber security incident response for cloud-native infrastructure, including investigating compromised containers, Kubernetes clusters, and CI/CD pipelines, and coordinating rapid isolation, remediation, and root‑cause analysis across cloud workloads.
- Lead the technical initiatives including advanced host and network‑based forensic collection and analysis, to ensure effective containment, eradication, recovery, and post‑incident evaluation.
- Oversee the detection, analysis, and mitigation of complex insider threats and incidents, utilizing advanced security tools such as DLP, SIEM (e.g., Chronicle, Splunk), IDS/IPS, EDR, and firewalls.
- Conduct proactive threat hunting, identifying and responding to Indicators of Compromise (IOC) and Advanced Persistent Threat (APT) tactics, techniques, and procedures (TTPs), including cloud‑ and container‑specific attack patterns.
- Lead projects related to security monitoring, incident response, and SOC process improvement, ensuring alignment with best practices and emerging threats.
- Mentor and provide technical guidance to junior SOC analysts, fostering a culture of urgency and continuous improvement for professional development within the team.
- Collaborate closely with Tier 2 and 3 staff and other cross‑functional teams to ensure seamless detection, classification, and reporting of security incidents, adhering to and enhancing Standard Operating Procedures (SOPs).
- Maintain deep, hands‑on awareness of security risks in cloud‑native environments, including GCP, Kubernetes orchestration, and CI/CD pipelines, along with the mechanisms and processes that enable rapid incident detection and response in these environments.
- Leverage AI/ML tools and automation to augment incident response, accelerate threat triage, and streamline security operations.
- Stay abreast of the latest cybersecurity trends, tools, and technologies, driving the adoption of new solutions and methodologies to strengthen our incident response capabilities.
Required Qualifications:
- Working knowledge of container security fundamentals (image scanning, runtime protection, container escape scenarios) and CI/CD pipeline security (secrets exposure, build/deploy compromise, supply chain risks).
- 8+ years of experience in information security, with extensive hands‑on experience in incident response, threat hunting, and forensic analysis.
- 2+ years of demonstrated experience in a lead SOC role and responding to sophisticated threats.
- 2+ years of hands‑on experience performing incident response in cloud environments (preferably GCP), including investigating and remediating incidents involving Kubernetes/container workloads and CI/CD pipelines.
- 4+ years of experience detecting, analyzing, and mitigating complex threats and incidents, utilizing advanced security tools (DLP, SIEM, IDS/IPS, EDR and firewalls).
Preferred Qualifications:
- Strong background in cloud (preferably GCP) environments, Kubernetes orchestration, CI/CD pipelines, and DevOps principles.
- Deep expertise in container security, including runtime protection, image scanning, and service mesh security policies.
- Expertise in securing Infrastructure as Code (IaC) and GitOps deployment workflows, ensuring security guardrails are integrated into the pipeline.
- Experience leveraging AI/ML as a responder tool to accelerate incident response, threat detection, and SOC automation.
- Familiarity with AI/ML security best practices, including securing LLM deployments and protecting AI pipelines from adversarial attacks.
- Expertise in securing Infrastructure as Code (IaC) and GitOps deployment workflows, ensuring security guardrails are integrated into the pipeline.
- Deep expertise in container security, including runtime protection, image scanning, and service mesh security policies.
- Comprehensive understanding of email security, network monitoring, data loss prevention (DLP), OS forensics, and other key security domains.
- Advanced expertise in using and optimizing SIEM tools (Chronicle, Splunk) and other security technologies for high‑level threat detection and incident response.
- Proven track record in developing