Principal Privacy Engineer at ID.me

McLean, Virginia, United States

ID.me Logo
Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Technology, Identity Verification, Government, HealthcareIndustries

Requirements

  • Deep expertise in Digital Identity
  • Strong technical knowledge of identity protocols, privacy-enhancing technologies, and regulatory frameworks (e.g., GDPR, CCPA, eIDAS, NIST SP 800-63)
  • Ability to design and implement privacy-centric solutions including data retention, anonymization, Privacy Threshold Assessments (PTAs), and Privacy Impact Assessments (PIAs)
  • Technical product and engineering consultation skills
  • Availability for onsite work in Mountain View, CA or McLean, VA

Responsibilities

  • Design and implement privacy-preserving identity solutions including federated identity, decentralized identifiers (DIDs), and verifiable credentials
  • Integrate privacy-by-design into authentication, authorization, and identity federation workflows (e.g., OAuth2, OpenID Connect, SAML)
  • Assist with conducting privacy impact assessments (PIAs) specifically related to identity and access management systems
  • Evaluate and deploy privacy-enhancing technologies (PETs) such as zero-knowledge proofs (ZKPs), secure multi-party computation (SMPC), anonymization, pseudonymization, and data minimization methods
  • Develop and enforce technical standards for identity data minimization, encryption, pseudonymization, and secure storage
  • Collaborate with IAM and security engineering teams to enhance identity governance with strong privacy controls
  • Review architecture and code for identity systems to ensure compliance with privacy regulations (GDPR, CCPA, eIDAS, etc.)
  • Monitor and assess threats to identity-related data and respond to incidents involving identity data exposure
  • Assist in managing privacy risk assessments and reviews for identity systems, including digital onboarding, credential issuance, and account recovery flows
  • Collaborate with security, IAM, DevOps, and compliance teams to build identity solutions that enforce Privacy-by-Design principles
  • Review identity system architecture and source code to ensure privacy and data protection controls are correctly implemented
  • Contribute to tooling for secure and automated DSAR (data subject access request) identity verification and privacy dashboards
  • Participate in incident response planning and investigations for identity-related security or privacy events
  • Map and enforce privacy principles (ISO/IEC 29100) including consent, purpose limitation, data minimization, and transparency in digital identity systems
  • Develop identity data lifecycle controls covering collection, processing, retention, and deletion per ISO/IEC and GDPR guidelines
  • Develop and implement solutions to ensure privacy policies are correctly implemented

Skills

Digital Identity
Federated Identity
Decentralized Identifiers
DIDs
Data Anonymization
Privacy Impact Assessments
Privacy Threshold Assessments
Identity Protocols
Privacy-Enhancing Technologies
NIST SP 800-63
Authentication
Identity Proofing

ID.me

Digital identity verification for secure access

About ID.me

ID.me provides a platform for digital identity verification, allowing individuals to prove and share their identity online. Users create a verified digital identity that can be used to access various services and discounts from partner companies. This process helps businesses ensure that only eligible individuals receive specific offers, which reduces fraud and enhances security. ID.me primarily serves military personnel, first responders, students, teachers, nurses, medical professionals, and government employees, making it particularly valuable in sectors like e-commerce, healthcare, government services, and education. Unlike its competitors, ID.me focuses on building trust between businesses and customers by offering a streamlined verification process that complies with regulatory requirements. The company's goal is to simplify identity verification while providing secure access to services and discounts.

McLean, VirginiaHeadquarters
2010Year Founded
$279.5MTotal Funding
SERIES_DCompany Stage
Government & Public Sector, Cybersecurity, HealthcareIndustries
1,001-5,000Employees

Benefits

Health Insurance
Dental Insurance
Vision Insurance
Life Insurance
Disability Insurance
Health Savings Account/Flexible Spending Account
Unlimited Paid Time Off
Paid Vacation
401(k) Company Match
401(k) Retirement Plan
Parental Leave
Employee Assistance Program
Pet Insurance
Travel Assistance Program
Wellbeing and Childcare Discounts
Referral Bonus
Learning and Development Benefit

Risks

Increased competition from new digital identity startups threatens ID.me's market share.
Privacy concerns and regulatory scrutiny could impact ID.me's data handling practices.
Technical challenges in scaling video chat services may lead to customer dissatisfaction.

Differentiation

ID.me is the only provider offering video chat for identity verification.
The company serves diverse sectors, including government, retail, and healthcare.
ID.me's platform is NIST 800-63-3 IAL2/AAL2 conformant, ensuring high security standards.

Upsides

ID.me's valuation increased to $1.8 billion, showing strong investor confidence.
Partnerships with government agencies enhance ID.me's credibility and market reach.
The growing demand for digital identity verification boosts ID.me's market potential.

Land your dream remote job 3x faster with AI