CronJobs

security jobs

SOC Lead

ID.me · McLean, Virginia

remotesenior$96,086–$96,086Posted Sep 9, 2026PythonGoBashKubernetesGCPSIEMSplunkChronicle

Apply on the employer site

About this role

**Company Overview** ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. With ID.me, consumers can verify their identity once and seamlessly log in across websites without re-verifying. ID.me supports 152M+ users across 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600 consumer brands use ID.me to verify communities and user segments. ID.me’s technology meets federal standards for consumer authentication and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider. **Role Overview (SOC Lead)** ID.me is seeking a highly experienced SOC Lead to safeguard our digital identity ecosystem. You’ll lead incident response, threat hunting, and forensic analysis, while refining SOC processes and tools. This role is ideal for a cybersecurity professional with deep SOC experience who wants greater responsibility, mentoring opportunities, and strategic impact. **Key Responsibilities** - Lead cyber security incident response for cloud-native infrastructure (investigate compromised containers, Kubernetes clusters, and CI/CD pipelines; coordinate isolation, remediation, and root-cause analysis). - Lead advanced host and network-based forensic collection and analysis to support containment, eradication, recovery, and post-incident evaluation. - Oversee detection, analysis, and mitigation of complex insider threats and incidents using tools such as DLP, SIEM (e.g., Chronicle, Splunk), IDS/IPS, EDR, and firewalls. - Conduct proactive threat hunting by identifying/responding to IOCs and APT TTPs, including cloud- and container-specific attack patterns. - Lead projects to improve security monitoring, incident response, and SOC processes. - Mentor and provide technical guidance to junior SOC analysts; foster urgency and continuous improvement. - Collaborate with Tier 2/3 and cross-functional teams to ensure seamless detection, classification, and reporting—while adhering to and enhancing SOC SOPs. - Maintain hands-on awareness of security risks in cloud-native environments (GCP, Kubernetes orchestration, CI/CD pipelines) and the mechanisms for rapid detection/response. - Leverage AI/ML tools and automation to augment incident response, accelerate triage, and streamline operations. - Stay current on cybersecurity trends, tools, and technologies to strengthen incident response capabilities. **Required Qualifications** - Working knowledge of container security fundamentals (image scanning, runtime protection, container escape scenarios) and CI/CD pipeline security (secrets exposure, build/deploy compromise, supply chain risks). - 8+ years of information security experience with extensive hands-on incident response, threat hunting, and forensic analysis. - 2+ years leading a SOC role and responding to sophisticated threats. - 2+ years hands-on incident response in cloud environments (preferably GCP), including Kubernetes/container workload and CI/CD pipeline investigations/remediation. - 4+ years experience detecting, analyzing, and mitigating complex threats using advanced security tools (DLP, SIEM, IDS/IPS, EDR, firewalls). **Preferred Qualifications** - Strong background in cloud (preferably GCP), Kubernetes orchestration, CI/CD pipelines, and DevOps principles. - Deep expertise in container security (runtime protection, image scanning, service mesh security policies). - Expertise securing Infrastructure as Code (IaC) and G

Listing freshness

CronJobs last confirmed this listing 23h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.

Browse all software engineering jobs →

Follow fresh jobs in Discord