---
title: "Staff Incident Responder / SOC Leader"
company: "Idme"
company_url: "https://www.remjobs.works/companies/idme"
url: "https://www.remjobs.works/job/idme-staff-incident-responder-soc-leader-8d456744-0eec-40a7-9c71-08e16a3f2dff"
apply_url: "https://job-boards.greenhouse.io/idme/jobs/7986926003"
workplace: onsite
location: "McLean, Virginia"
employment_type: unspecified
seniority: staff
role: other
region: united-states
salary: "$160,963–$227,360"
date_posted: 2026-09-09T15:48:20.000Z
first_seen_by_remjobs: 2026-09-09T16:14:25.409Z
---

# Staff Incident Responder / SOC Leader

**Idme** · McLean, Virginia

Salary: $160,963–$227,360

Apply: https://job-boards.greenhouse.io/idme/jobs/7986926003

## About the role

#### Company Overview

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit [https://network.id.me/](https://network.id.me/).

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found [here](https://insider.id.me/candidate-ai-use-in-interviewing/).

**Role Overview:****
** ID.me is seeking a Staff Cloud Detection & Response Engineer to serve as our senior technical authority on threat detection and incident response across our cloud environments. This is a defender-first role, not an engineering or SRE role; when a high-severity cloud incident happens, you have the technical authority to lead it end to end. Your primary mission is detecting, investigating, and eliminating threats across our cloud infrastructure, Kubernetes workloads, and CI/CD surface.

You bring deep, hands-on fluency in AWS and/or GCP cloud security architecture, and you use it to make faster, more decisive calls during an incident and to advise engineering and platform teams on secure-by-design practices. You are a highly technical consultant to the teams who own the infrastructure; you influence how it's built through review, threat modeling, and architectural guidance, not by writing and owning the Terraform or CI/CD pipelines yourself. Your value is in detection depth, response authority, and the judgment to know exactly where an attacker would go next in a modern cloud environment.

**Key Responsibilities:**

- Lead high-severity cloud security incidents with full technical authority from initial detection through containment, eradication, and recovery across cloud infrastructure, Kubernetes (EKS/GKE), and CI/CD-deployed workloads.

- Engineer immutable cloud forensics pipelines, including automated disk and memory snapshot capture at the moment of containment, so evidence from ephemeral compute and Kubernetes pods survives autoscaling and termination.

- Advise engineering and platform teams on secure-by-design cloud architecture, IAM least-privilege structures, network security perimeters (e.g., AWS Organizations SCPs / VPC Service Controls), and workload identity, serving as a technical reviewer and consultant rather than the engineer implementing the change.

- Drive visibility into CI/CD pipelines for security signals (such as dependency/SBOM findings, secret-scanning alerts, and admission-control violations) surfaced to your team for detection and response, rather than owning the pipeline configuration itself.

- Conduct deep Kubernetes runtime security investigations, including cluster and node compromise, container escape scenarios, malicious admission-controller bypass, and workload identity abuse at the pod, node, and API-server level.

- Perform proactive threat hunting for IOCs and APT TTPs specific to cloud and container environments, translating cloud-native telemetry (CloudTrail/Cloud Audit Logs, VPC/network flow logs, Kubernetes audit logs) into concrete detections.

- Own incident command during major cloud incidents by directing cross-functional responders, making real-time containment decisions, and communicating status to executive leadership without needing to escalate the decision upward.

- Lead root-cause and post-incident review for cloud incidents, translating findings into concrete architectural recommendations that platform/engineering teams own and implement.

- Mentor SOC and IR analysts on cloud- and container-native investigation techniques, raising the team's overall fluency in cloud threat detection.

- Stay current on cloud-native security services and emerging cloud attack techniques, and drive their adoption into detection content and incident playbooks.

**Required Qualifications:**

- 8+ years of experience in information security, with extensive hands-on experience in incident response, threat hunting, and forensic analysis.

- 3+ years leading incident response in cloud environments (AWS and/or GCP required).

- Scripting/automation proficiency (Python, Go, bash) for detection engineering and forensic tooling.

- Deep, working knowledge of cloud IAM least-privilege design, including custom/managed roles, service account or role impersonation risk, workload identity federation, and organization-level policy constraints.

- Deep, hands-on knowledge of Kubernetes (EKS/GKE) and container runtime security, covering container escape scenarios, runtime protection, admission control, and image scanning/provenance.

- Demonstrated experience building or specifying immutable cloud forensics workflows, including automated snapshotting of disks and memory for ephemeral and autoscaled compute.

- Experience advising on (not necessarily authoring) CI/CD pipeline security, covering secrets exposure, build/deploy compromise, dependency, and supply-chain risk.

- 4+ years detecting, analyzing, and mitigating complex threats using SIEM (e.g., Chronicle, Splunk), EDR, DLP, IDS/IPS, and CSPM/CWPP tooling.

- Demonstrated ability to run incident command with authority by directing response across teams during a high-severity, high-visibility cloud incident.

**Preferred Qualifications:**

- Experience across both AWS and GCP is a plus, but not required.

- Familiarity with Infrastructure as Code (Terraform) and GitOps workflows sufficient to review and advise on security guardrails, even without direct authorship responsibility.

- Experience with service mesh security policy (Istio, Linkerd) from an investigative/advisory standpoint.

- Advanced certifications: GCIA, GCIH, GCFA, CISSP, CKS (Certified Kubernetes Security Specialist), or a cloud provider security certification (AWS Security – Specialty, GCP Professional Cloud Security Engineer).

- Experience with AI/ML-assisted triage and detection engineering, and awareness of securing AI/LLM pipelines.

- Proven track record developing insider threat detection strategies and writing detection signatures.

- Proficiency leading forensic investigations across Linux, MacOS, and Windows in addition to cloud environments.

- Prior experience contributing to SOC/IR process maturity and incident command frameworks.

**Ideal Candidate Will Thrive In Our Culture:**

- Is a defender at heart, energized by hunting down and eliminating threats rather than building the platforms they defend.

- Exercises decisive, high-authority judgment in high-pressure, high-severity incidents without waiting for permission to act.

- Communicates cloud-native technical findings clearly to both engineering peers and executive stakeholders.

- Influences architecture and engineering decisions through credibility and technical depth, not direct implementation authority.

- Is highly adaptable, staying ahead of a fast-evolving multi-cloud threat landscape.
The annual base salary listed does not include a company bonus, incentive for sales roles, equity and benefits which will be determined based on experience, skills, education, relevant training, geographic location and role.

ID.me offers comprehensive medical, dental, vision, health savings account, flexible spending accounts (medical, limited purpose, dependent care, commuter benefit accounts), basic and voluntary life and AD&D insurance, 401(k) with company match, parental leave, ability to participate in unlimited paid time off subject to the terms and conditions of the PTO policy, including 8 company wide holidays, short and long-term disability insurance, accident and critical illness insurance, referral bonus policy, employee assistance program, pet insurance, travel assistant program, wellbeing and childcare discounts, benefit advocates, and a learning and development benefit.

Final offers may vary from the amount listed based on qualifications, professional experiences, skills, education, relevant training, geographic location, and other job related factors.

Pay Range$160,963—$227,360 USDID.me maintains a work environment free from discrimination, where employees are treated with dignity and respect. All ID.me employees share in the responsibility for fulfilling our commitment to equal employment opportunity. ID.me does not discriminate against any employee or applicant on the basis of age, ancestry, color, family or medical care leave, gender identity or expression, genetic information, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran status, race, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable laws, regulations and ordinances. ID.me adheres to these principles in all aspects of employment, including recruitment, hiring, training, compensation, promotion, benefits, social and recreational programs, and discipline. In addition, ID.me's policy is to provide reasonable accommodation to qualified employees who have protected disabilities to the extent required by applicable laws, regulations and ordinances where a particular employee works. Upon request we will provide you with more information about such accommodations.

Please review our Privacy Policy, including our CCPA policy, at[id.me/privacy](https://insider.id.me/privacy/). If you provide ID.me with any personally identifiable information you confirm that you have read and agree to be bound by the terms and conditions set out in our Privacy Policy.

ID.me participates in E-Verify.

---

Source: Idme's own career page, read by RemJobs. Canonical HTML version: https://www.remjobs.works/job/idme-staff-incident-responder-soc-leader-8d456744-0eec-40a7-9c71-08e16a3f2dff
