SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
ID.me is a next-generation digital identity wallet serving 152+ million users across 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. The company operates one of the most heavily scrutinized identity platforms in the world, balancing rapid engineering velocity with security rigor.
As Director of Product Security, you will lead the Product Security program end-to-end, reporting to the Chief Information Security Officer. This is a leadership role first, requiring you to build, grow, and mentor a team of security engineers while owning the complete product security function.
You will own the Product Security program including threat modeling, secure code and architecture review, SCA, secret scanning, vulnerability management, CSPM, and configuration management—integrated across the secure software development lifecycle as scalable, shift-left, developer-aligned controls. You'll define security standards and rules of the road for Engineering, enabling teams to self-serve rather than creating bottlenecks. You'll partner with Product and Engineering early at design and architecture time to embed security before code ships. The team builds and maintains security tooling and services that help engineers ship secure products at high velocity. You're accountable for penetration testing and red team execution, scope, findings, and remediation.
The ideal candidate demonstrates outcome-based leadership, translating business objectives into clear outcomes and keeping teams focused on results. You measure success by whether risk actually decreased and whether engineers can do their jobs safely—not by the number of findings produced. You drive fixes to closure even when other teams own the code. Engineering is your customer; you default to "how do we make this work safely?" and when you must say no, you explain it in terms they value and offer a path. You assess security quickly (days, not weeks), right-size rigor to the decision at hand, and avoid security theater. You have technical depth across threat modeling, code and architecture review, SCA/SAST, secret scanning, and vulnerability management. You've led security teams before and understand how to build high-performing groups. You're comfortable in regulated environments and understand compliance frameworks. The role is on-site five days per week in Mountain View, CA.