SoFi
Staff Vulnerability Management Engineer
WA - Seattle; CA - San Francisco · Staff+
Sponsorship not specifiedDetected 1 day ago
JavaScriptTypeScriptPythonJavaGoCode ReviewAWSGCPAzureKubernetesCI/CDSite Reliability EngineeringMachine LearningLLMsCybersecurityIncident ResponseComplianceSupply ChainCommunicationMentoring
> stay_score
odds of building a lasting career here
16Unrated
Cap-exempt (no lottery)0
Sponsors this role0
Entry-level history0
PERM / green-card track0
Lottery odds40
Fits your clock70
No strong sponsorship signal in the public record yet. In the full product we resolve the exact legal entity and show its filing history with a confidence score — treat as unverified until then.
Lottery odds assume a STEM candidate.
Personalize to your clock →> community_outcomes
No reports yet — be the first to help the next applicant.
About the role
- This is a hands-on engineering role with broad technical influence: you will write production code, make architecture decisions, establish vulnerability management standards, and improve how teams understand and reduce vulnerability risk.
- The ideal candidate combines deep vulnerability management expertise with strong software engineering judgment, systems thinking, and a bias for durable, measurable outcomes.
Responsibilities
- Lead high-complexity vulnerability management initiatives and make architecture decisions for assigned program areas, from detection and assessment through ticket routing, remediation, exception handling, and closure validation.
- Design, build, and productionize scalable triage and prioritization automation, including scanner and asset integrations, enrichment pipelines, decision logic, deduplication, ownership resolution, service-level tracking, observability, and failure recovery.
- Develop risk-based prioritization models that combine CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations.
- Own or materially advance software supply chain capabilities, including SBOM inventory, dependency visibility, SLSA-aligned controls, and integration of SAST, SCA, secret scanning, and container scanning into CI/CD.
- Partner directly with development and platform teams to define practical remediation paths and, when appropriate, review or contribute secure changes in Python, Go, JavaScript/TypeScript, or infrastructure code.
- ensure workflows support audit-ready reporting for applicable regulatory and compliance frameworks.
- Lead root-cause analysis for high-impact vulnerability incidents and convert lessons learned into durable improvements to tooling, architecture, controls, and operating practices.
- Evaluate and responsibly apply AI/ML and LLM-assisted techniques to security triage and decision support, with human-in-the-loop validation, measurable quality controls, and safe failure modes.
- Build AI-assisted remediation workflows that partner with engineering teams to proactively identify, validate, and apply security patches, with appropriate testing, human oversight, rollback mechanisms, and measurable risk reduction.
Requirements
- Bachelor's degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
- Deep expertise in vulnerability management, security engineering, and modern infrastructure, including cloud, containers, and distributed systems.
- Experience designing end-to-end workflows that integrate scanners, asset inventories or CMDBs, ticketing systems, CI/CD platforms, data stores, dashboards, and alerting systems.
- Working knowledge of cloud-native and software supply chain environments, including AWS, GCP, or Azure
- Strong written and verbal communication, business judgment, and the ability to explain how security choices affect engineering velocity, regulatory obligations, customer trust, and business risk.
Nice to have
- Experience managing security partnerships with hardware or software vendors, including embargoed disclosures, coordinated vulnerability disclosure, and pre-release remediation collaboration.
- Production experience with security orchestration platforms such as Tines and serverless frameworks such as AWS Lambda or Google Cloud Functions.
- Experience scaling vulnerability management in a high-growth, cloud-native environment or operating within FedRAMP, PCI DSS, SOC 2, ISO 27001, NIST, or comparable regulated environments.
- The Company hires the best qualified candidate for the job, without regard to protected characteristics.
- Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
- New York applicants: Notice of Employee Rights
- SoFi is committed to an inclusive culture.
- Internal Employees
Skills
- Shape a brighter financial future with us.
- Join us to invest in yourself, your career, and the financial world.
Compensation
- The base pay range for this role is listed below.
- Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location.
Benefits
- To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!
Company info
- Together with our members, we're changing the way people think about and interact with personal finance.
- We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals.
- The industry is going through an unprecedented transformation, and we're at the forefront.
- We're proud to come to work every day knowing that what we do has a direct impact on people's lives, with our core values guiding us every step of the way.
- We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi's Vulnerability Management program.
- You will design and build scalable systems that identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud and infrastructure, containers, software supply chains, and specialized hardware or firmware surfaces.
- You will partner with Engineering, Infrastructure, SRE, Compliance, Legal, and business stakeholders to accelerate remediation while protecting engineering velocity and customer trust.
- You will also serve as a senior technical responder for embargoed disclosures and zero-day events, lead root-cause analysis for high-impact vulnerability incidents, and mentor engineers.
This listing is sourced directly from SoFi's careers page and normalized into a canonical job model.