Prepin
Log in
ID.me

engineering opportunity

Product Security Engineer

Implement complex security solutions and build production-ready security automation. Troubleshoot security issues and execute security projects to strengthen product security.

Mountain View, California, United StatesonsiteFULL_TIME

Posted

About the role

What will you do at ID.me?

COMPANY OVERVIEW

ID.me is the next-generation digital identity wallet that simplifies how

individuals securely prove their identity online. Consumers can verify their

identity with ID.me once and seamlessly login across websites without having to

create a new login and verify their identity again. Over 152 million users

experience streamlined login and identity verification with ID.me at 20 federal

agencies, 45 state government agencies, and 70+ healthcare organizations. More

than 600+ consumer brands use ID.me to verify communities and user segments to

honor service and build more authentic relationships. ID.me’s technology meets

the federal standards for consumer authentication set by the Commerce Department

and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by

the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to

enable all people to have a secure digital identity. To learn more, visit

https://network.id.me/ [https://network.id.me/].

ID.me is a full-time, in-office culture. Unless a specific job description

explicitly states otherwise, all roles are on-site five days per week at one of

our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL.

Certain roles — such as field-based sales or other remote-by-design positions —

may have different work arrangements as noted in their individual postings.

At ID.me, we embrace the thoughtful use of AI tools in our daily work and there

are even occasions where we leverage AI in our hiring process. However, during

the interview process, we want to understand your individual skills and

experiences. Therefore, we have guidelines on how AI can be appropriately used

during your application and interviews which can be found here

[http://At%20ID.me,%20we%20embrace%20the%20thoughtful%20use%20of%20AI%20tools%20in%20our%20daily%20work%20and%20there%20are%20even%20occasions%20where%20we%20leverage%20AI%20in%20our%20hiring%20process. %20However,%20during%20the%20interview%20process,%20we%20want%20to%20understand%20your%20individual%20skills%20and%20experiences. %20Therefore,%20we%20have%20guidelines%20on%20how%20AI%20can%20be%20appropriately%20used%20during%20your%20application%20and%20interviews.].

ROLE OVERVIEW

ID.me is looking for a Product Security Engineer to join our Product Security

organization as an execution-focused individual contributor. If you love deep

technical work, building security solutions, and solving complex security

challenges, here's your chance to make a career of it by advancing the digital

identity ecosystem while protecting millions of users. As one of the most

targeted identity platforms in the country, ID.me safeguards a massive volume of

sensitive PII—making Product Security the tip of the spear in defending against

sophisticated adversaries and ensuring our products remain resilient at scale.

We are seeking a highly skilled security engineer who excels at implementing and

fixing security issues across software and cloud, building automation, and

executing complex technical projects. As a Product Security Engineer, you will

be a technical expert who delivers production-ready technology solutions, solves

the hardest problems, and performs deep technical security assessments that

directly strengthen the security of our products. Your work will shape the

defensive foundation of a platform relied upon nationwide, giving you the

opportunity to make a meaningful, visible impact on the safety and trust of

millions of users.

This role is based out of our Mountain View, CA or McLean, VA offices and

requires full-time in-office attendance.

WHAT YOU'LL DO

* Implement complex security solutions, including Cloud and SaaS security, and

service account protections, and Application Security.

* Build production-ready security automation using Python or Java to scale

security operations and reduce manual toil

* Execute security projects from requirements through deployment with minimal

guidance, delivering high-quality results on time

* Troubleshoot complex security issues in production environments, conducting

deep technical analysis and implementing fixes quickly

* Implement GKE security controls

* Build and maintain cloud security infrastructure using Terraform

* Configure GCP security services such as VPC Service Controls, Private Service

Connect, Cloud Armor policies, IAM roles, and Secret Manager

* Execute API security assessments by conducting security reviews, identifying

vulnerabilities, and implementing remediation

* Execute vulnerability remediation workflows for application, container,

Cloud, and SaaS vulnerabilities within defined SLAs

* Build security dashboards and reporting to track vulnerability MTTR, security

control effectiveness, and false positive rates

BASIC QUALIFICATIONS

* 5+ years in security and/or software engineering, with focus on

implementation and execution

* 5+ years of hands-on programming in Python or Java with demonstrated ability

to build production-quality security tooling and automation

* 3+ years of hands-on GCP experience including GKE, Cloud Run, IAM, Secret

Manager, and security services

* Container / mesh networks (GKE, Docker, Kubernetes security, image scanning,

Binary Authorization, SBOM)

* Infrastructure-as-code proficiency (Terraform preferred) for deploying and

maintaining security infrastructure

* Troubleshooting expertise with ability to debug complex issues in production

cloud environments

PREFERRED QUALIFICATIONS

* GCP Professional Cloud Architect or Professional Cloud Security Engineer

certification

* OSCP or comparable hands-on offensive-security certifications (e.g., OSEP,

GXPN, PNPT) demonstrating strong adversarial reasoning and exploit-focused

problem-solving capability.

* Experience with offensive-security methodologies (e.g., understanding attack

chains, exploitation fundamentals, or red-team tooling) applied to defensive

engineering contexts

* Interest in applied security research—such as vulnerability discovery,

protocol analysis, or emerging-threat investigation

#LI-JS1

The annual base salary listed does not include a company bonus, incentive for

sales roles, equity and benefits which will be determined based on experience,

skills, education, relevant training, geographic location and role.

ID.me offers comprehensive medical, dental, vision, health savings account,

flexible spending accounts (medical, limited purpose, dependent care, commuter

benefit accounts), basic and voluntary life and AD&D insurance, 401(k) with

company match, parental leave, ability to participate in unlimited paid time off

subject to the terms and conditions of the PTO policy, including 8 company wide

holidays, short and long-term disability insurance, accident and critical

illness insurance, referral bonus policy, employee assistance program, pet

insurance, travel assistant program, wellbeing and childcare discounts, benefit

advocates, and a learning and development benefit.

Final offers may vary from the amount listed based on qualifications,

professional experiences, skills, education, relevant training, geographic

location, and other job related factors.

Mountain View, CA Pay Range

$168,472—$200,000 USD

ID.me maintains a work environment free from discrimination, where employees are

treated with dignity and respect. All ID.me employees share in the

responsibility for fulfilling our commitment to equal employment opportunity.

ID.me does not discriminate against any employee or applicant on the basis of

age, ancestry, color, family or medical care leave, gender identity or

expression, genetic information, marital status, medical condition, national

origin, physical or mental disability, political affiliation, protected veteran

status, race, religion, sex (including pregnancy), sexual orientation, or any

other characteristic protected by applicable laws, regulations and ordinances.

ID.me adheres to these principles in all aspects of employment, including

recruitment, hiring, training, compensation, promotion, benefits, social and

recreational programs, and discipline. In addition, ID.me's policy is to provide

reasonable accommodation to qualified employees who have protected disabilities

to the extent required by applicable laws, regulations and ordinances where a

particular employee works. Upon request we will provide you with more

information about such accommodations.

Please review our Privacy Policy, including our CCPA policy, at id.me/privacy

[https://insider.id.me/privacy/]. If you provide ID.me with any personally

identifiable information you confirm that you have read and agree to be bound by

the terms and conditions set out in our Privacy Policy.

ID.me participates in E-Verify.

Which skills does this role require?

Security EngineeringApplication SecurityPythonJavaTerraformVulnerability AssessmentAutomationAPI SecurityInfrastructure-as-CodeContainer SecurityProduction EnvironmentsSecurity DashboardsTechnical AnalysisDigital IdentitySecurity SolutionsSensitive PIISaaS SecurityVulnerability RemediationAPI Security AssessmentsTechnical Security AssessmentsSecurity ControlsCloud ArmorIAM RolesSecret ManagerVPC Service ControlsGKE SecurityKubernetes SecurityBinary AuthorizationDockerKubernetes

Make your next move

Build a shortlist and prepare

Identify the requirements you can demonstrate, then choose examples from your work to discuss with the hiring team.

Review the responsibilities and requirements before adding an opening to your shortlist.

Role information can change. Confirm current details on the original application page.

Product

AI Candidate AgentCompaniesBrowse JobsDeep ProfileSkill AssessmentOpportunity Matching
Prepin.ai

© 2026 Prepin | All rights reserved.