Staff Cloud Detection & Response Engineer

Idme

McLean (VA)

On-site

USD 161,000 - 227,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Medical, dental, vision
401(k) with company match
Unlimited PTO
Wellbeing and childcare discounts

Job summary

ID.me seeks a Staff Cloud Detection & Response Engineer to lead threat detection and incident response across cloud environments. You will act as a defender-first authority, guiding security decisions and advising engineering on secure-by-design practices.

You’ll work with AWS and/or GCP, Kubernetes workloads, and CI/CD surfaces to detect, investigate, and eliminate threats. You bring deep hands-on experience in cloud security, incident response, and forensics, with a focus on detection depth,

Qualifications

  • Eight+ years in information security with hands-on IR, threat hunting, and forensics.
  • Three+ years leading IR in cloud environments (AWS and/or GCP).
  • Proficient in Python/Go/bash for detection tooling.
  • Deep knowledge of IAM least-privilege design and risk controls.
  • Hands-on Kubernetes (EKS/GKE) and container runtime security experience.
  • Experience with immutable cloud forensics workflows and automated evidence capture.
  • Ability to advise on secure-by-design architecture and CI/CD security.

Responsibilities

  • Lead high-severity cloud security incidents with technical authority from detection to recovery.
  • Engineer immutable cloud forensics pipelines to preserve evidence during autoscaling.
  • Advise on secure cloud architecture, IAM, network perimeters, and workload identity.
  • Drive visibility into CI/CD pipelines for security signals without owning pipelines.
  • Conduct deep Kubernetes runtime security investigations across clusters and pods.
  • Perform proactive threat hunting using cloud-native telemetry to detect IOCs and TTPs.
  • Own incident command during major cloud incidents and communicate with leadership.
  • Lead root-cause analyses and convert findings into architectural improvements.
  • Mentor SOC/IR analysts to raise overall cloud threat detection fluency.
  • Stay current on cloud-native security services and advise adoption into playbooks.

Skills

Incident response
Threat hunting
Forensic analysis
Python
Go
Bash
IAM least-privilege design
Kubernetes security
Immutable forensics workflows
CI/CD security
SIEM/EDR/DLP/IDS
Incident command

Tools

Chronicle
Splunk
Terraform
Kubernetes security tooling

Job description

Company Overview

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me's technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to "No Identity Left Behind" to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found here.

Role Overview

ID.me is seeking a Staff Cloud Detection & Response Engineer to serve as our senior technical authority on threat detection and incident response across our cloud environments. This is a defender-first role, not an engineering or SRE role; when a high-severity cloud incident happens, you have the technical authority to lead it end to end. Your primary mission is detecting, investigating, and eliminating threats across our cloud infrastructure, Kubernetes workloads, and CI/CD surface.

You bring deep, hands-on fluency in AWS and/or GCP cloud security architecture, and you use it to make faster, more decisive calls during an incident and to advise engineering and platform teams on secure-by-design practices. You are a highly technical consultant to the teams who own the infrastructure; you influence how it's built through review, threat modeling, and architectural guidance, not by writing and owning the Terraform or CI/CD pipelines yourself. Your value is in detection depth, response authority, and the judgment to know exactly where an attacker would go next in a modern cloud environment.

Key Responsibilities
  • Lead high-severity cloud security incidents with full technical authority from initial detection through containment, eradication, and recovery across cloud infrastructure, Kubernetes (EKS/GKE), and CI/CD-deployed workloads.
  • Engineer immutable cloud forensics pipelines, including automated disk and memory snapshot capture at the moment of containment, so evidence from ephemeral compute and Kubernetes pods survives autoscaling and termination.
  • Advise engineering and platform teams on secure-by-design cloud architecture, IAM least-privilege structures, network security perimeters (e.g., AWS Organizations SCPs / VPC Service Controls), and workload identity, serving as a technical reviewer and consultant rather than the engineer implementing the change.
  • Drive visibility into CI/CD pipelines for security signals (such as dependency/SBOM findings, secret-scanning alerts, and admission-control violations) surfaced to your team for detection and response, rather than owning the pipeline configuration itself.
  • Conduct deep Kubernetes runtime security investigations, including cluster and node compromise, container escape scenarios, malicious admission-controller bypass, and workload identity abuse at the pod, node, and API-server level.
  • Perform proactive threat hunting for IOCs and APT TTPs specific to cloud and container environments, translating cloud-native telemetry (CloudTrail/Cloud Audit Logs, VPC/network flow logs, Kubernetes audit logs) into concrete detections.
  • Own incident command during major cloud incidents by directing cross-functional responders, making real-time containment decisions, and communicating status to executive leadership without needing to elevate the decision upward.
  • Lead root-cause and post-incident review for cloud incidents, translating findings into concrete architectural recommendations that platform/engineering teams own and implement.
  • Mentor SOC and IR analysts on cloud- and container-native investigation techniques, raising the team's overall fluency in cloud threat detection.
  • Stay current on cloud-native security services and emerging cloud attack techniques, and drive their adoption into detection content and incident playbooks.
Required Qualifications
  • 8+ years of experience in information security, with extensive hands-on experience in incident response, threat hunting, and forensic analysis.
  • 3+ years leading incident response in cloud environments (AWS and/or GCP required).
  • Scripting/automation proficiency (Python, Go, bash) for detection engineering and forensic tooling.
  • Deep, working knowledge of cloud IAM least-privilege design, including custom/managed roles, service account or role impersonation risk, workload identity federation, and organization-level policy constraints.
  • Deep, hands-on knowledge of Kubernetes (EKS/GKE) and container runtime security, covering container escape scenarios, runtime protection, admission control, and image scanning/provenance.
  • Demonstrated experience building or specifying immutable cloud forensics workflows, including automated snapshotting of disks and memory for episodic and autoscaled compute.
  • Experience advising on (not necessarily authoring) CI/CD pipeline security, covering secrets exposure, build/deploy compromise, dependency, and supply-chain risk.
  • 4+ years detecting, analyzing, and mitigating complex threats using SIEM (e.g., Chronicle, Splunk), EDR, DLP, IDS/IPS, and CSPM/CWPP tooling.
  • Demonstrated ability to run incident command with authority by directing response across teams during a high-severity, high-visibility cloud incident.
Preferred Qualifications
  • Experience across both AWS and GCP is a plus, but not required.
  • Familiarity with Infrastructure as Code (Terraform) and GitOps workflows sufficient to review and advise on security guardrails, even without direct authorship responsibility.
  • Experience with service mesh security policy (Istio, Linkerd) from an investigative/advisory standpoint.
  • Advanced certifications: GCIA, GCIH, GCFA, CISSP, CKS (Certified Kubernetes Security Specialist), or a cloud provider security certification (AWS Security – Specialty, GCP Professional Cloud Security Engineer).
  • Experience with AI/ML-assisted triage and detection engineering, and awareness of securing AI/LLM pipelines.
  • Proven track record developing insider threat detection strategies and writing detection signatures.
  • Proficiency leading forensic investigations across Linux, MacOS, and Windows in addition to cloud environments.
  • Prior experience contributing to SOC/IR process maturity and incident command frameworks.
Ideal Candidate Will Thrive In Our Culture
  • Is a defender at heart, energized by hunting down and eliminating threats rather than building the platforms they defend.
  • Exercises decisive, high-authority judgment in high-pressure, high-severity incidents without waiting for permission to act.
  • Communicates cloud-native technical findings clearly to both engineering peers and executive stakeholders.
  • Influences architecture and engineering decisions through credibility and technical depth, not direct implementation authority.
  • Is highly adaptable, staying ahead of a fast-evolving multi-cloud threat landscape.
Pay Range

The annual base salary listed does not include a company bonus, incentive for sales roles, equity and benefits which will be determined based on experience, skills, education, relevant training, geographic location and role.

ID.me offers comprehensive medical, dental, vision, health savings account, flexible spending accounts (medical, limited purpose, dependent care, commuter benefit accounts), basic and voluntary life and AD&D insurance, 401(k) with company match, parental leave, ability to participate in unlimited paid time off subject to the terms and conditions of the PTO policy, including 8 company wide holidays, short and long-term disability insurance, accident and critical illness insurance, referral bonus policy, employee assistance program, pet insurance, travel assistant program, wellbeing and childcare discounts, benefit advocates, and a learning and development benefit.

Final offers may vary from the amount listed based on qualifications, professional experiences, skills, education, relevant training, geographic location, and other job related factors.

$160,963 - $227,360 USD

Equal Employment Opportunity Statement

ID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.

Privacy Policy

Please review our Privacy Policy, including our CCPA policy, at id.me/privacy. If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.

Additional Notes

ID.me participates in E-Verify.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

ID.me • Washington, Baltimore (MD)

On-site
USD 140,000 - 200,000
Director of Product Security
Director of Product Security

ID.me • San Francisco (CA)

On-site
USD 244,000 - 272,000
Medical benefits
Dental benefits
Vision benefits
+2
Director of Product Security
Director of Product Security

Idme • Mountain View (CA)

On-site
USD 244,000 - 272,000
Director of Product Security
Director of Product Security

ID.me • Mountain View (CA)

On-site
USD 244,000 - 272,000
Medical benefits
401(k) with company match
Paid time off
Senior Threat Intelligence Analyst
Senior Threat Intelligence Analyst

ID.me • McLean (VA), Mountain View (CA)

On-site
USD 150,000 - 190,000
SOC Analyst
SOC Analyst

ID.me • McLean (VA)

On-site
USD 65,000 - 90,000
401(k) with company match
Unlimited paid time off
Wellbeing and childcare discounts
Staff Software Engineer – AI Enablement
Staff Software Engineer – AI Enablement

ID.me • San Francisco (CA)

On-site
USD 218,000 - 260,000
Comprehensive medical
Dental insurance
Vision insurance
+3
Account Executive, Workforce Identity East
Account Executive, Workforce Identity East

ID.me • New York (NY)

On-site
USD 140,000 - 160,000
Medical insurance
Dental insurance
Vision insurance
+4
Senior Software Development Engineer - Fullstack
Senior Software Development Engineer - Fullstack

ID.me • Maryland

On-site
USD 191,000 - 231,000
Medical insurance
Dental insurance
Vision insurance
+4
Software Engineer II, Developer Portal (New Grad / Early Career)
Software Engineer II, Developer Portal (New Grad / Early Career)

iDme Technologies Corp • San Francisco (CA)

On-site
USD 122,000 - 157,000