SOC Lead
ID.me · McLean, Virginia
About this role
**Company Overview** ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. With ID.me, consumers can verify their identity once and seamlessly log in across websites without re-verifying. ID.me supports 152M+ users across 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600 consumer brands use ID.me to verify communities and user segments. ID.me’s technology meets federal standards for consumer authentication and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider. **Role Overview (SOC Lead)** ID.me is seeking a highly experienced SOC Lead to safeguard our digital identity ecosystem. You’ll lead incident response, threat hunting, and forensic analysis, while refining SOC processes and tools. This role is ideal for a cybersecurity professional with deep SOC experience who wants greater responsibility, mentoring opportunities, and strategic impact. **Key Responsibilities** - Lead cyber security incident response for cloud-native infrastructure (investigate compromised containers, Kubernetes clusters, and CI/CD pipelines; coordinate isolation, remediation, and root-cause analysis). - Lead advanced host and network-based forensic collection and analysis to support containment, eradication, recovery, and post-incident evaluation. - Oversee detection, analysis, and mitigation of complex insider threats and incidents using tools such as DLP, SIEM (e.g., Chronicle, Splunk), IDS/IPS, EDR, and firewalls. - Conduct proactive threat hunting by identifying/responding to IOCs and APT TTPs, including cloud- and container-specific attack patterns. - Lead projects to improve security monitoring, incident response, and SOC processes. - Mentor and provide technical guidance to junior SOC analysts; foster urgency and continuous improvement. - Collaborate with Tier 2/3 and cross-functional teams to ensure seamless detection, classification, and reporting—while adhering to and enhancing SOC SOPs. - Maintain hands-on awareness of security risks in cloud-native environments (GCP, Kubernetes orchestration, CI/CD pipelines) and the mechanisms for rapid detection/response. - Leverage AI/ML tools and automation to augment incident response, accelerate triage, and streamline operations. - Stay current on cybersecurity trends, tools, and technologies to strengthen incident response capabilities. **Required Qualifications** - Working knowledge of container security fundamentals (image scanning, runtime protection, container escape scenarios) and CI/CD pipeline security (secrets exposure, build/deploy compromise, supply chain risks). - 8+ years of information security experience with extensive hands-on incident response, threat hunting, and forensic analysis. - 2+ years leading a SOC role and responding to sophisticated threats. - 2+ years hands-on incident response in cloud environments (preferably GCP), including Kubernetes/container workload and CI/CD pipeline investigations/remediation. - 4+ years experience detecting, analyzing, and mitigating complex threats using advanced security tools (DLP, SIEM, IDS/IPS, EDR, firewalls). **Preferred Qualifications** - Strong background in cloud (preferably GCP), Kubernetes orchestration, CI/CD pipelines, and DevOps principles. - Deep expertise in container security (runtime protection, image scanning, service mesh security policies). - Expertise securing Infrastructure as Code (IaC) and G
Listing freshness
CronJobs last confirmed this listing 23h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.