2 months ago
Responsibilities
- Lead high-complexity vulnerability management initiatives and make architecture decisions across detection, assessment, routing, remediation, exception handling, and closure validation.
- Design and productionize scalable triage and prioritization automation with scanner and asset integrations, enrichment pipelines, deduplication, ownership resolution, observability, and failure recovery.
- Develop risk-based prioritization models using CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations.
- Engineer vulnerability workflows across application security, cloud and infrastructure, containers and Kubernetes, open-source dependencies, secrets, software supply chains, and hardware-adjacent surfaces.
- Advance software supply chain capabilities including SBOM inventory, dependency visibility, SLSA-aligned controls, and SAST, SCA, secret scanning, and container scanning integrations into CI/CD.
- Respond to critical vulnerabilities, embargoed disclosures, and zero-day events, coordinating assessment, containment, mitigation, patch deployment, validation, and executive communication.
- Review or contribute secure changes in Python, Go, JavaScript/TypeScript, and infrastructure code when appropriate.
- Define standards for vulnerability severity, remediation service levels, exceptions, evidence, closure criteria, and audit-ready reporting.
- Produce dashboards, metrics, and risk insights covering accountability, trends, compliance posture, and execution risks.
- Lead root-cause analysis for high-impact vulnerability incidents and turn lessons learned into improvements to tooling, architecture, controls, and operating practices.
- Evaluate AI/ML and LLM-assisted security triage and decision-support techniques with human validation, quality controls, and safe failure modes.
- Build AI-assisted remediation workflows for identifying, validating, and applying security patches with testing, human oversight, rollback mechanisms, and measurable risk reduction.
- Communicate security tradeoffs and program risks to Engineering, Product, Operations, Legal, Compliance, and executive stakeholders.
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
- Deep expertise in vulnerability management, security engineering, modern infrastructure, cloud, containers, and distributed systems.
- Strong programming or scripting skills in Python, Go, Java, or similar languages, with experience building automation at scale.
- Deep knowledge of CVSS, EPSS, CISA KEV, threat intelligence, remediation SLAs, exception governance, and risk-based prioritization.
- Hands-on experience with vulnerability and application security tools such as Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, and Checkmarx, or equivalent platforms.
- Experience designing workflows integrating scanners, asset inventories or CMDBs, ticketing systems, CI/CD platforms, data stores, dashboards, and alerting systems.
- Working knowledge of AWS, GCP, or Azure; Kubernetes and containers; build systems and package managers; SBOMs; and Infrastructure as Code.
- Ability to lead cross-functional technical initiatives, influence without direct authority, make decisions amid ambiguity, and drive work through production operation and measurable outcomes.
- Experience mentoring senior and developing engineers through design reviews, code reviews, standards, and incident leadership.
- Strong written and verbal communication, business judgment, and ability to explain security impacts on engineering velocity, regulatory obligations, customer trust, and business risk.
- Experience with hardware or software vendor security partnerships, embargoed disclosures, coordinated vulnerability disclosure, or pre-release remediation is desirable.
- Production experience with Tines, AWS Lambda, or Google Cloud Functions is desirable.
- Experience in high-growth cloud-native environments or regulated frameworks such as FedRAMP, PCI DSS, SOC 2, ISO 27001, or NIST is desirable.
Benefits
- Comprehensive benefits are available through SoFi’s Benefits page.
- Remote work from Hawaii or Alaska is not accommodated due to insurance coverage issues.
Categories
About SoFi
SoFi provides consumer banking, lending, and investing products, including student-loan refinancing, personal loans, mortgages, checking and savings, a credit card, and brokerage. It earns interest and fee revenue across SoFi Bank, N.A., and related subsidiaries, serving U.S. consumers via a mobile app. Founded in 2011 and headquartered in San Francisco, SoFi Technologies is publicly traded on Nasdaq under the ticker SOFI.
