ForgeApply
Try it free

ForgeApply · Job listing

Director of Product Security

Idme

Mountain View, CA, USonsite

See all 46 open roles at Idme

Tailor your resume for this Idme job in about a minute.

ForgeApply rewrites your resume for this exact posting, then autofills the application on Idme's site with it. You review everything before it's sent. Free trial, no card required.

About this role

Company Overview

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/ .

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found here .

Director of Product Security

Location: Mountain View, CA (on-site) Reports to: Chief Information Security Officer (CISO) Department: Security - Product Security

About the Role ID.me runs one of the most heavily scrutinized identity platforms in the world, and our engineers ship fast. Product Security is how we keep that speed safe. We're looking for a leader who believes security is practical and outcome-driven; every control we ask for reduces real risk, and our job isn't done when we file a ticket; it's done when the risk is actually gone. This is a leadership role first. You'll own the Product Security program end-to-end, lead and grow the team, and be the trusted security partner to Engineering and not its gatekeeper.

What You'll Own ● The Product Security (ProdSec) program: threat modeling, secure code and architecture review, SCA, secret scanning, vulnerability management, CSPM and configuration management; integrated across the SSDLC as scalable, shift-left, developer-aligned controls. ● People leadership: build, grow, and lead a team of security engineers. You are accountable for their development, growth, and professional well-being; not just their output. ● The rules of the road: define what is and isn't acceptable security practice for Engineering clearly, with the why, so teams can self-serve instead of waiting on you. ● Secure-by-design consulting: partner with Product and Engineering early at design and architecture time so security is built in before code ships, not bolted on after. ● Security tooling & services: the team builds and maintains tools and services that let engineers ship secure products at high velocity; adopted because they help rather than gate. ● Penetration Testing & Red Team: you're accountable for the execution and outcomes; scope, findings, and remediation.

What We're Looking For

Must Have Outcome-based leadership. You translate business objectives into clear outcomes and keep the team focused on them. You set the requirements and constraints, guide the how without dictating it, and trust your team to own execution. You know what good looks like and reach it efficiently; the right-sized solution, delivered without micromanagement. Accountability for results. You measure success by whether risk actually went down and whether engineers can do their jobs safely; not by how many findings you produced. You drive fixes to closure, even when another team owns the code. Partnership with Engineering. Engineering is your customer. You default to "how do we make this work safely?" and when you must say no, you explain it in terms they value and offer a path. You assert security and compliance requirements; you don't dictate product decisions. Speed and judgment. Assessments turn around in days, not weeks. You right-size rigor to the decision in front of you and avoid security theater. Technical depth. You move fluently across threat modeling, code and architecture review, SCA/SAST, secret scanning, vuln management, and cloud/CSPM — enough to earn engineers' respect and coach your team. Integrity and trust. You handle privileged access with discretion, and you build a team where sharing bad news early is safe and rewarded. AI fluency. Our security org runs on AI daily (Claude, Gemini, custom tooling). You treat AI as a force multiplier and champion AI-augmented security workflows.

Strong Preference ● Built or matured an Application Security, Security Engineering, or Product Security program in a fast-shipping, cloud-native environment like ours: GCP, GitHub, Kubernetes/GKE, Apigee, Terraform, and modern CI/CD ● Hands-on with security tooling such as Socket.dev, Sysdig, Trivy, DependencyTrack, or HackerOne ● AI-augmented security workflows with Claude, Gemini, or Vertex AI ● Growth-stage experience where you had to build, not just maintain

About the Environment ● AI-first. The CISO's goal: make it safe for everyone to use every feature of any company-provisioned AI tool for any task. You'll help make that real. ● Practical over procedural. We prefer technical enforcement over policy documents, and real risk reduction over checkbox compliance. ● One team. Security at ID.me operates as a single organization — ProdSec, SecOps, GRC, IT, and Physical Secur

Salary insight

This posting doesn't disclose pay. Across 8,771 San Francisco jobs with disclosed salaries on ForgeApply, the median is $200k.

Based on live postings with disclosed pay on ForgeApply; refreshed daily. Not an estimate of this employer's offer.

Tailor your resume for this Idme role before you apply.

Tailor my resume for this job

Similar jobs

Free ATS checker · How to Autofill Greenhouse Job Applications (Without Sending Junk)