Jobs · Information Technology · California

Director of Product Security

ID.me · San Francisco Bay Area · 3 days ago
On-siteInformation Technology$244k–$272k/yrFull-time

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers verify their identity once and seamlessly log in across websites without creating new credentials. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600 consumer brands use ID.me to verify communities and user segments, building authentic relationships. ID.me’s technology meets federal standards for consumer authentication and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative.

About The Role

ID.me runs one of the most heavily scrutinized identity platforms in the world, and our engineers ship fast. Product Security is how we keep that speed safe. We're looking for a leader who believes security is practical and outcome-driven; every control we ask for reduces real risk, and our job isn't done when we file a ticket—it's done when the risk is actually gone. This is a leadership role first. You'll own the Product Security program end-to-end, lead and grow the team, and be the trusted security partner to Engineering, not its gatekeeper.

Responsibilities

  • Own the Product Security (ProdSec) program: threat modeling, secure code and architecture review, SCA, secret scanning, vulnerability management, CSPM, and configuration management; integrated across the SSDLC as scalable, shift-left, developer-aligned controls.
  • Build, grow, and lead a team of security engineers, accountable for their development, growth, and professional well-being—not just their output.
  • Define clear security practices for Engineering, explaining the "why" so teams can self-serve instead of waiting on approvals.
  • Partner with Product and Engineering early in design and architecture to ensure security is built in before code ships, not bolted on after.
  • Develop and maintain security tooling and services that enable engineers to ship secure products at high velocity—adopted because they help, not hinder.
  • Oversee Penetration Testing and Red Team execution, including scope, findings, and remediation.

Requirements

  • Outcome-based leadership: Translate business objectives into clear outcomes, set requirements and constraints, and guide without micromanaging. Focus on the right-sized solution delivered efficiently.
  • Accountability for results: Measure success by whether risk actually decreases and whether engineers can work safely—not by the number of findings. Drive fixes to closure, even when another team owns the code.
  • Partnership with Engineering: Treat Engineering as your customer. Default to "how do we make this work safely?" and explain security requirements in terms they value. Assert security needs without dictating product decisions.
  • Speed and judgment: Turn assessments around in days, not weeks. Right-size rigor to the decision at hand and avoid security theater.
  • Technical depth: Move fluently across threat modeling, code/architecture review, SCA/SAST, secret scanning, vulnerability management, and cloud/CSPM—enough to earn engineers' respect and coach your team.
  • Integrity and trust: Handle privileged access with discretion and foster a team culture where sharing bad news early is safe and rewarded.
  • AI fluency: Leverage AI (Claude, Gemini, custom tooling) as a force multiplier and champion AI-augmented security workflows.

Qualifications

  • Built or matured an Application Security, Security Engineering, or Product Security program in a fast-shipping, cloud-native environment (e.g., GCP, GitHub, Kubernetes/GKE, Apigee, Terraform, modern CI/CD).
  • Hands-on experience with security tooling such as Socket.dev, Sysdig, Trivy, DependencyTrack, or HackerOne.
  • Experience with AI-augmented security workflows (Claude, Gemini, or Vertex AI).
  • Growth-stage experience where you had to build, not just maintain.

About The Environment

  • AI-first: The CISO’s goal is to make it safe for everyone to use AI tools for any task. You’ll help make this a reality.
  • Practical over procedural: Prefer technical enforcement over policy documents and real risk reduction over checkbox compliance.
  • One team: Security operates as a single organization—ProdSec, SecOps, GRC, IT, and Physical Security collaborate daily. Value leaders who build cross-functional trust and operate transparently.

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • Health savings account and flexible spending accounts (medical, limited purpose, dependent care, commuter benefit accounts).
  • Basic and voluntary life and AD&D insurance.
  • 401(k) with company match.
  • Parental leave.
  • Unlimited paid time off (subject to policy terms), including 8 company-wide holidays.
  • Short- and long-term disability insurance, accident and critical illness insurance.
  • Referral bonus policy.
  • Employee assistance program.
  • Pet insurance, travel assistant program, wellbeing and childcare discounts, benefit advocates.
  • Learning and development benefit.

Pay

Mountain View, CA Pay Range: $243,699—$271,644 USD (annual base salary). Final offers may vary based on qualifications, experience, skills, education, relevant training, and geographic location.

Schedule

Full-time, in-office (five days per week) at the Mountain View, CA office. Certain roles may have different arrangements as noted in their individual postings.

Similar jobs

Product Security Director

CrunchyrollLos Angeles, CA· 1 wk ago
Information Technology$249k–$305k/yrapply on boards.greenhouse.io