ID.me is simplifying how individuals securely prove and share their identity online. With their secure digital identity network, ID.me is doing for identity what Visa did for financial transactions. ID.me empowers people to fully control their own data through a portable and trusted login so they don’t need to create a new password at each site they visit.
The COVID-19 pandemic has accelerated a massive digital migration for many critical services. These services require a trusted identity to ensure an individual is who they claim to be while keeping out fraud. Identity verification that serves only one organization is costly and time-intensive. Separate passwords for each application add to consumer frustration. With ID.me, login and identity credentials move with an individual so they only need to verify once.
ID.me is a federally-certified identity provider at the highest standards NIST has set for consumer identity verification and login. ID.me is one of only four companies in the United States of America certified by the federal government to bind a legal identity to a digital login.
In addition to providing individuals with complete control over their credentials and data, the company has a “No Identity Left Behind” initiative to expand access and inclusion for all individuals through a video chat verification process. ID.me is passionate about building a robust identity network that does not compromise access for hard-to-identify groups.
ID.me is looking for a Senior Cybersecurity Vulnerability Engineer to add to our rapidly growing security team. If you love innovation, here's your chance to make a career of it by advancing the digital identity ecosystem. We are seeking a talented cybersecurity professional to execute assessments of systems, applications, and networks. The Senior Cybersecurity Vulnerability Engineer will measure the effectiveness of defense-in-depth architecture against known vulnerabilities and processes that enable the organization to make informed decisions regarding remediation.
- Manage the lifecycle of vulnerabilities: identification, evaluation, remediation, and reporting
- Conduct vulnerability scans of servers, applications, infrastructure, etc
- Configure and manage tools to support vulnerability management
- Partner with threat intelligence and penetration testing teams to share meaningful insights to improve the risk management posture
- Work with cross-functional teams including AppSec, Software Engineering, DevOps, IT, and GRC
- Leverage tools like Splunk to automate vulnerability analysis, metrics and reporting
- Conduct required reviews as appropriate to support security compliance efforts
The qualifications below are ideal, but not all are required. We encourage candidates to apply if they satisfy some, but not all of the qualifications.
- 5+ years of experience in information security
- 5+ years conducting different types of vulnerability assessments
- 5+ years of experience with well known vulnerabilities, exploits, and attacker TTP’s
- 3+ years of experience conducting vulnerability scans in cloud and on-premise environments
- Experience in a Mac enterprise environment
- Bonus: Experience with cloud technologies such as AWS, GCP, and/or Azure
- Bonus: Experience with CI/CD pipelines and containerization
- Bonus: Experience with NIST, FedRAMP, SOC 2, ISO 27001
- Bonus: Experience in scripting (Bash, Python, and/or Ruby)
- Industry security certifications, such as GCIH/ECIH, Security+, or related
Ideal candidate will thrive in the following culture:
- Must have an obsession for security
- Ability to thrive when there are changing priorities and shifting of gears
- Strong oral and written communication skills
- Must be a team player with a strong, self-managing work ethic
- Must be a self-starter with a passion for learning and continuous improvement
Note that candidates must be located in the continental U.S.
ID.me Covid Vaccination Requirement
All current and future employees are required to receive their COVID-19 vaccinations, unless a reasonable accommodation is approved. Employees not in compliance with this policy will be placed on leave and will be terminated if no valid reason for not getting the COVID-19 vaccine is provided.
Purpose: In accordance with ID.me's duty to provide and maintain a workplace that is free of known hazards, we are adopting this policy to safeguard the health of our employees and their families; our customers and visitors; and the community at large from COVID-19 that may be reduced by vaccinations. This policy will comply with all applicable laws and is based on guidance from the Centers for Disease Control and Prevention and local health authorities, as applicable.
Reasonable Accommodation: Current and future employees in need of an exemption from this policy due to a medical reason, or because of a sincerely held religious belief must submit a completed Request for Accommodation form to the human resources department to begin the interactive accommodation process as soon as possible after vaccination deadlines have been announced (September 13th) and an offer of employment has been made. Accommodations will be granted where they do not cause ID.me undue hardship or pose a direct threat to the health and safety of others.
Vision: To be the world's leading digital identity network empowering people to control their own information and to prove their credentials across all channels: online, call center, and in-person.
Mission: To make the world a more trusted place by delivering the highest level of security with the least amount of friction at the lowest possible cost.
People: We have an audacious mission. We aim to fix the identity layer of the internet. Billions of people will live better lives with more trust and convenience thanks to ID.me. We are like Special Forces. We take on the most difficult challenges with amazing teammates.
ID.me Core Values: *Don't be a jerk. *Always compete. *Ask questions like a 5-year old. *Inspire people with your passion. *Make something better every day. *Treat each customer like your favorite family member. *Own your mistakes so you can learn from them. *Details are everything. *Communicate like a scientist. *Be truthful (even when it's hard). *Reflect ID.me's values in your actions. *Act like an owner.
ID.me Career Site & Culture Deck: https://www.id.me/careers