JobBobsReal-time global job discoveryLive

Staff Cloud Detection & Response Engineer

Idme · McLean, Virginia · 2026-09-30

executive
Apply on the employer's site

About this role

Company Overview

ID.me is the next-generation digital identity wallet that simplifies how individuals securely prove their identity online. Consumers can verify their identity with ID.me once and seamlessly login across websites without having to create a new login and verify their identity again. Over 152 million users experience streamlined login and identity verification with ID.me at 20 federal agencies, 45 state government agencies, and 70+ healthcare organizations. More than 600+ consumer brands use ID.me to verify communities and user segments to honor service and build more authentic relationships. ID.me’s technology meets the federal standards for consumer authentication set by the Commerce Department and is approved as a NIST 800-63-3 IAL2 / AAL2 credential service provider by the Kantara Initiative. ID.me is committed to “No Identity Left Behind” to enable all people to have a secure digital identity. To learn more, visit https://network.id.me/.

ID.me is a full-time, in-office culture. Unless a specific job description explicitly states otherwise, all roles are on-site five days per week at one of our offices in McLean, VA; Mountain View, CA; New York City, NY; or Tampa, FL. Certain roles — such as field-based sales or other remote-by-design positions — may have different work arrangements as noted in their individual postings.

At ID.me, we embrace the thoughtful use of AI tools in our daily work and there are even occasions where we leverage AI in our hiring process. However, during the interview process, we want to understand your individual skills and experiences. Therefore, we have guidelines on how AI can be appropriately used during your application and interviews which can be found here.

Role Overview:
ID.me is seeking a Staff Cloud Detection & Response Engineer to serve as our senior technical authority on threat detection and incident response across our cloud environments. This is a defender-first role, not an engineering or SRE role; when a high-severity cloud incident happens, you have the technical authority to lead it end to end. Your primary mission is detecting, investigating, and eliminating threats across our cloud infrastructure, Kubernetes workloads, and CI/CD surface.

You bring deep, hands-on fluency in AWS and/or GCP cloud security architecture, and you use it to make faster, more decisive calls during an incident and to advise engineering and platform teams on secure-by-design practices. You are a highly technical consultant to the teams who own the infrastructure; you influence how it's built through review, threat modeling, and architectural guidance, not by writing and owning the Terraform or CI/CD pipelines yourself. Your value is in detection depth, response authority, and the judgment to know exactly where an attacker would go next in a modern cloud environment.

Key Responsibilities:

• Lead high-severity cloud security incidents with full technical authority from initial detection through containment, eradication, and recovery across cloud infrastructure, Kubernetes (EKS/GKE), and CI/CD-deployed workloads.

• Engineer immutable cloud forensics pipelines, including automated disk and memory snapshot capture at the moment of containment, so evidence from ephemeral compute and Kubernetes pods survives autoscaling and termination.

• Advise engineering and platform teams on secure-by-design cloud architecture, IAM least-privilege structures, network security perimeters (e.g., AWS Organizations SCPs / VPC Service Controls), and workload identity, serving as a technical reviewer and consultant rather than the engineer implementing the change.

• Drive visibility into CI/CD pipelines for security signals (such as dependency/SBOM findings, secret-scanning alerts, and admission-control violations) surfaced to your team for detection and response, rather than owning the pipeline configuration itself.

• Conduct deep Kubernetes runtime security investigations, including cluster and node compromise, container escape scenarios, malicious admission-controller bypass, and workload identity abuse at the pod, node, and API-server level.

• Perform proactive threat hunting for IOCs and APT TTPs specific to cloud and container environments, translating cloud-native telemetry (CloudTrail/Cloud Audit Logs, VPC/network flow logs, Kubernetes audit logs) into concrete detections.

• Own incident command during major cloud incidents by directing cross-functional responders, making real-time containment decisions, and communicating status to executive leadership without needing to escalate the decision upward.

• Lead root-cause and post-incident review for cloud incidents, translating findings into concrete architectural recommendations that platform/engineering teams own and implement.

• Mentor SOC and IR analysts on cloud- and container-native investigation techniques, raising the team's overall fluency in cloud threat detection.

• Stay current on cloud-native security services and emerging cloud attack techniques, and drive their adoption into detection content and incident playbooks.

Required Qualifications:

• 8+ years of experience in information security, with extensive hands-on experience in incident response, threat hunting, and forensic analysis.

• 3+ years leading incident response in cloud environments (AWS and/or GCP required).

• Scripting/automation proficiency (Python, Go, bash) for detection engineering and forensic tooling.

• Deep, working knowledge of cloud IAM least-privilege design, including custom/managed roles, service account or role impersonation risk, workload identity federation, and organization-level policy constraints.

• Deep, hands-on knowledge of Kubernetes (EKS/GKE) and container runtime security, covering container escape scenarios, runtime protection, admission control, and image scanning/provenance.

• Demonstrated experience building or specifying immutable cloud forensics workflows, including automated snapshotting of…

Skills asked for

Apply on the employer's site

Your next role is already in here.

Search live openings from thousands of employers, save the ones worth a second look, and let JobBob keep watch for the rest.