Staff Incident Responder / SOC Leader

ID.me · McLean, Virginia · Other

Posted 2026-09-23

Apply for this role →

Role Overview:

ID.me is seeking a Staff Cloud Detection & Response Engineer to serve as our senior technical authority on threat detection and incident response across our cloud environments. This is a defender-first role, not an engineering or SRE role; when a high-severity cloud incident happens, you have the technical authority to lead it end to end. Your primary mission is detecting, investigating, and eliminating threats across our cloud infrastructure, Kubernetes workloads, and CI/CD surface.

You bring deep, hands-on fluency in AWS and/or GCP cloud security architecture, and you use it to make faster, more decisive calls during an incident and to advise engineering and platform teams on secure-by-design practices. You are a highly technical consultant to the teams who own the infrastructure; you influence how it's built through review, threat modeling, and architectural guidance, not by writing and owning the Terraform or CI/CD pipelines yourself. Your value is in detection depth, response authority, and the judgment to know exactly where an attacker would go next in a modern cloud environment.

Key Responsibilities:

Lead high-severity cloud security incidents with full technical authority from initial detection through containment, eradication, and recovery across cloud infrastructure, Kubernetes (EKS/GKE), and CI/CD-deployed workloads.

Engineer immutable cloud forensics pipelines, including automated disk and memory snapshot capture at the moment of containment, so evidence from ephemeral compute and Kubernetes pods survives autoscaling and termination.

Advise engineering and platform teams on secure-by-design cloud architecture, IAM least-privilege structures, network security perimeters (e.g., AWS Organizations SCPs / VPC Service Controls), and workload identity, serving as a technical reviewer and consultant rather than the engineer implementing the change.

Drive visibility into CI/CD pipelines for security signals (such as dependency/SBOM findings, secret-scanning alerts, and admission-control violations) surfaced to your team for detection and response, rather than owning the pipeline configuration itself.

Conduct deep Kubernetes runtime security investigations, including cluster and node compromise, container escape scenarios, malicious admission-controller bypass, and workload identity abuse at the pod, node, and API-server level.

Perform proactive threat hunting for IOCs and APT TTPs specific to cloud and container environments, translating cloud-native telemetry (CloudTrail/Cloud Audit Logs, VPC/network flow logs, Kubernetes audit logs) into concrete detections.

Own incident command during major cloud incidents by directing cross-functional responders, making real-time containment decisions, and communicating status to executive leadership without needing to escalate the decision upward.

Lead root-cause and post-incident review for cloud incidents, translating findings into concrete architectural recommendations that platform/engineering teams own and implement.

Mentor SOC and IR analysts on cloud- and container-native investigation techniques, raising the team's overall fluency in cloud threat detection.

Stay current on cloud-native security services and emerging cloud attack techniques, and drive their adoption into detection content and incident playbooks.

Required Qualifications:

8+ years of experience in information security, with extensive hands-on experience in incident response, threat hunting, and forensic analysis.

3+ years leading incident response in cloud environments (AWS and/or GCP required).

Scripting/automation proficiency (Python, Go, bash) for detection engineering and forensic tooling.

Deep, working knowledge of cloud IAM least-privilege design, including custom/managed roles, service account or role impersonation risk, workload identity federation, and organization-level policy constraints.

Deep, hands-on knowledge of Kubernetes (EKS/GKE) and container runtime security, covering container escape scenarios, runtime protection, admission control, and image scanning/provenance.

Demonstrated experience building or specifying immutable cloud forensics workflows, including automated snapshotting of disks and memory for ephemeral and autoscaled compute.

Experience advising on (not necessarily authoring) CI/CD pipeline security, covering secrets exposure, build/deploy compromise, dependency, and supply-chain risk.

4+ years detecting, analyzing, and mitigating complex threats using SIEM (e.g., Chronicle, Splunk), EDR, DLP, IDS/IPS, and CSPM/CWPP tooling.

Demonstrated ability to run incident command with authority by directing response across teams during a high-severity, high-visibility cloud incident.

Preferred Qualifications:

Experience across both AWS and GCP is a plus, but not required.

Familiarity with Infrastructure as Code (Terraform) and GitOps workflows sufficient to review and advise on security guardrails, even without direct authorship responsibility.

Experience with service mesh security policy (Istio, Linkerd) from an investigative/advisory standpoint.

Advanced certifications: GCIA, GCIH, GCFA, CISSP, CKS (Certified Kubernetes Security Specialist), or a cloud provider security certification (AWS Security – Specialty, GCP Professional Cloud Security Engineer).

Experience with AI/ML-assisted triage and detection engineering, and awareness of securing AI/LLM pipelines.

Proven track record developing insider threat detection strategies and writing detection signatures.

Proficiency leading forensic investigations across Linux, MacOS, and Windows in addition to cloud environments.

Prior experience contributing to SOC/IR process maturity and incident command frameworks.

Ideal Candidate Will Thrive In Our Culture:

Is a defender at heart, energized by hunting down and eliminating threats rather than building the platforms they defend.

Exercises decisive, high-authority judgment in high-pressure, high-severity incidents without waiting for permission to act.

Communicates cloud-native technical findings clearly to both engineering peers and executive stakeholders.

Influences architecture and engineering decisions through credibility and technical depth, not direct implementation authority.

Is highly adaptable, staying ahead of a fast-evolving multi-cloud threat landscape.

The annual base salary listed does not include a company bonus, incentive for sales roles, equity and benefits which will be determined based on experience, skills, education, relevant training, geographic location and role.

ID.me offers comprehensive medical, dental, vision, health savings account, flexible spending accounts (medical, limited purpose, dependent care, commuter benefit accounts), basic and voluntary life and AD&D insurance, 401(k) with company match, parental leave, ability to participate in unlimited paid time off subject to the terms and conditions of the PTO policy, including 8 company wide holidays, short and long-term disability insurance, accident and critical illness insurance, referral bonus policy, employee assistance program, pet insurance, travel assistant program, wellbeing and childcare discounts, benefit advocates, and a learning and development benefit.

Final offers may vary from the amount listed based on qualifications, professional experiences, skills, education, relevant training, geographic location, and other job related factors.

Pay Range

$160,963—$227,360 USD

Apply for this role →

← Back to all jobs