SoFi

Staff Vulnerability Management Engineer

SoFi
Apply
2 months ago
Seattle, WA, USA or San Francisco, CA, USAStaff+
H1B sponsor

Responsibilities

  • Lead high-complexity vulnerability management initiatives and make architecture decisions across detection, assessment, routing, remediation, exception handling, and closure validation.
  • Design and productionize scalable triage and prioritization automation with scanner and asset integrations, enrichment pipelines, deduplication, ownership resolution, observability, and failure recovery.
  • Develop risk-based prioritization models using CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations.
  • Engineer vulnerability workflows across application security, cloud and infrastructure, containers and Kubernetes, open-source dependencies, secrets, software supply chains, and hardware-adjacent surfaces.
  • Advance software supply chain capabilities including SBOM inventory, dependency visibility, SLSA-aligned controls, and SAST, SCA, secret scanning, and container scanning integrations into CI/CD.
  • Respond to critical vulnerabilities, embargoed disclosures, and zero-day events, coordinating assessment, containment, mitigation, patch deployment, validation, and executive communication.
  • Review or contribute secure changes in Python, Go, JavaScript/TypeScript, and infrastructure code when appropriate.
  • Define standards for vulnerability severity, remediation service levels, exceptions, evidence, closure criteria, and audit-ready reporting.
  • Produce dashboards, metrics, and risk insights covering accountability, trends, compliance posture, and execution risks.
  • Lead root-cause analysis for high-impact vulnerability incidents and turn lessons learned into improvements to tooling, architecture, controls, and operating practices.
  • Evaluate AI/ML and LLM-assisted security triage and decision-support techniques with human validation, quality controls, and safe failure modes.
  • Build AI-assisted remediation workflows for identifying, validating, and applying security patches with testing, human oversight, rollback mechanisms, and measurable risk reduction.
  • Communicate security tradeoffs and program risks to Engineering, Product, Operations, Legal, Compliance, and executive stakeholders.

Requirements

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
  • Deep expertise in vulnerability management, security engineering, modern infrastructure, cloud, containers, and distributed systems.
  • Strong programming or scripting skills in Python, Go, Java, or similar languages, with experience building automation at scale.
  • Deep knowledge of CVSS, EPSS, CISA KEV, threat intelligence, remediation SLAs, exception governance, and risk-based prioritization.
  • Hands-on experience with vulnerability and application security tools such as Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, and Checkmarx, or equivalent platforms.
  • Experience designing workflows integrating scanners, asset inventories or CMDBs, ticketing systems, CI/CD platforms, data stores, dashboards, and alerting systems.
  • Working knowledge of AWS, GCP, or Azure; Kubernetes and containers; build systems and package managers; SBOMs; and Infrastructure as Code.
  • Ability to lead cross-functional technical initiatives, influence without direct authority, make decisions amid ambiguity, and drive work through production operation and measurable outcomes.
  • Experience mentoring senior and developing engineers through design reviews, code reviews, standards, and incident leadership.
  • Strong written and verbal communication, business judgment, and ability to explain security impacts on engineering velocity, regulatory obligations, customer trust, and business risk.
  • Experience with hardware or software vendor security partnerships, embargoed disclosures, coordinated vulnerability disclosure, or pre-release remediation is desirable.
  • Production experience with Tines, AWS Lambda, or Google Cloud Functions is desirable.
  • Experience in high-growth cloud-native environments or regulated frameworks such as FedRAMP, PCI DSS, SOC 2, ISO 27001, or NIST is desirable.

Benefits

  • Comprehensive benefits are available through SoFi’s Benefits page.
  • Remote work from Hawaii or Alaska is not accommodated due to insurance coverage issues.
SoFi

About SoFi

5,001-10,000 employees

SoFi provides consumer banking, lending, and investing products, including student-loan refinancing, personal loans, mortgages, checking and savings, a credit card, and brokerage. It earns interest and fee revenue across SoFi Bank, N.A., and related subsidiaries, serving U.S. consumers via a mobile app. Founded in 2011 and headquartered in San Francisco, SoFi Technologies is publicly traded on Nasdaq under the ticker SOFI.

Contact me