SoFi

SoFi

Cybersecurity Incident Commander

WA - Seattle; CA - San Francisco

Sponsorship not specified$61k-$800kDetected 7 days ago
AWSGCPAzureCybersecuritySIEMIncident ResponseComplianceNetwork MonitoringResearchLeadershipCommunicationCollaborationOrganizational SkillsCISSP

About the role

  • This role will serve as a central driver for security incident response, ensuring effective management of day-to-day incidents as well as large-scale, high-impact cybersecurity events.
  • The SOC team is responsible for monitoring, analyzing, and responding to security events across SoFi's infrastructure and applications.

Responsibilities

  • Lead and manage the end-to-end lifecycle of security incidents, including triage validation, containment, eradication, recovery, and closure.
  • Establish and maintain incident command during high-severity or large-scale incidents.
  • Drive cross-functional collaboration and decision making across technical and business teams to ensure timely and effective response.
  • Facilitate incident communication, coordinate response resources, and maintain clear situational awareness for all engaged.
  • Develop and maintain incident severity classifications and escalation criteria that are aligned with organizational and business needs and expectations.
  • Partner with SOC leadership to enhance incident metrics, reporting, and operational maturity.

Requirements

  • 3-7+ years of experience in cybersecurity operations, incident response, or SOC environments.
  • Strong understanding of the incident response lifecycle and frameworks (e.g., NIST 800-61).
  • Experience handling high-severity incidents such as ransomware, business email compromise, insider threats, cloud compromise, or data exfiltration events.
  • Ability to interpret technical findings and translate them into clear, actionable updates for both technical and non-technical stakeholders.
  • Experience facilitating cross-functional communication across various media channels and driving accountability during live incidents.
  • Ability to operate independently while collaborating effectively across distributed teams.

Nice to have

  • Experience in a formal CSIRT or Incident Commander role.
  • Working knowledge of security technologies such as SIEM, EDR, email security, IAM, cloud security controls, and network monitoring tools.
  • Knowledge of regulatory and compliance considerations (e.g., financial services, PCI, SOX, GLBA).
  • Experience directing or conducting digital forensics or deep technical investigations.
  • Familiarity with cloud-native security incident response (AWS, GCP, or Azure).
  • Exposure to MITRE ATT&CK framework and threat intelligence integration.
  • Relevant certifications such as GCIA, GCIH, GCED, CISSP, CISM, or similar.
  • The Company hires the best qualified candidate for the job, without regard to protected characteristics.

Compensation

  • The base pay range for this role is listed below.
  • Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location.

Benefits

  • To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!

Company info

  • Shape a brighter financial future with us.
  • Together with our members, we're changing the way people think about and interact with personal finance.
  • We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals.
  • The industry is going through an unprecedented transformation, and we're at the forefront.
  • We're proud to come to work every day knowing that what we do has a direct impact on people's lives, with our core values guiding us every step of the way.
  • Join us to invest in yourself, your career, and the financial world.
  • We are seeking a Cybersecurity Incident Commander to join SoFi's Cyber Defense program and lead incident command efforts across the organization.
  • As a dedicated incident response resource within Cyber Defense, you will coordinate cross-functional response efforts, maintain incident command structure during active events, and ensure consistent communication, documentation, and resolution tracking.
  • This is a highly visible role that partners closely with SOC Analysts, Threat Research, Offensive Security, Tools Automation & Operations (TAO), Engineering, IT, Legal, Risk, Executive team, and other stakeholders to drive timely containment, eradication, and recovery.
  • The ideal candidate thrives in fast-paced environments, brings structure to ambiguity, has exceptional communication skills, and can effectively drive complex incidents from detection through post-incident review.
  • Serve as the primary Security Incident Commander for security incidents identified by the SOC.

This listing is sourced directly from SoFi's careers page and normalized into a canonical job model.