SoFi
Cybersecurity Incident Commander
WA - Seattle; CA - San Francisco
Sponsorship not specified$61k-$800kDetected 7 days ago
AWSGCPAzureCybersecuritySIEMIncident ResponseComplianceNetwork MonitoringResearchLeadershipCommunicationCollaborationOrganizational SkillsCISSP
About the role
- This role will serve as a central driver for security incident response, ensuring effective management of day-to-day incidents as well as large-scale, high-impact cybersecurity events.
- The SOC team is responsible for monitoring, analyzing, and responding to security events across SoFi's infrastructure and applications.
Responsibilities
- Lead and manage the end-to-end lifecycle of security incidents, including triage validation, containment, eradication, recovery, and closure.
- Establish and maintain incident command during high-severity or large-scale incidents.
- Drive cross-functional collaboration and decision making across technical and business teams to ensure timely and effective response.
- Facilitate incident communication, coordinate response resources, and maintain clear situational awareness for all engaged.
- Develop and maintain incident severity classifications and escalation criteria that are aligned with organizational and business needs and expectations.
- Partner with SOC leadership to enhance incident metrics, reporting, and operational maturity.
Requirements
- 3-7+ years of experience in cybersecurity operations, incident response, or SOC environments.
- Strong understanding of the incident response lifecycle and frameworks (e.g., NIST 800-61).
- Experience handling high-severity incidents such as ransomware, business email compromise, insider threats, cloud compromise, or data exfiltration events.
- Ability to interpret technical findings and translate them into clear, actionable updates for both technical and non-technical stakeholders.
- Experience facilitating cross-functional communication across various media channels and driving accountability during live incidents.
- Ability to operate independently while collaborating effectively across distributed teams.
Nice to have
- Experience in a formal CSIRT or Incident Commander role.
- Working knowledge of security technologies such as SIEM, EDR, email security, IAM, cloud security controls, and network monitoring tools.
- Knowledge of regulatory and compliance considerations (e.g., financial services, PCI, SOX, GLBA).
- Experience directing or conducting digital forensics or deep technical investigations.
- Familiarity with cloud-native security incident response (AWS, GCP, or Azure).
- Exposure to MITRE ATT&CK framework and threat intelligence integration.
- Relevant certifications such as GCIA, GCIH, GCED, CISSP, CISM, or similar.
- The Company hires the best qualified candidate for the job, without regard to protected characteristics.
Compensation
- The base pay range for this role is listed below.
- Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location.
Benefits
- To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!
Company info
- Shape a brighter financial future with us.
- Together with our members, we're changing the way people think about and interact with personal finance.
- We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals.
- The industry is going through an unprecedented transformation, and we're at the forefront.
- We're proud to come to work every day knowing that what we do has a direct impact on people's lives, with our core values guiding us every step of the way.
- Join us to invest in yourself, your career, and the financial world.
- We are seeking a Cybersecurity Incident Commander to join SoFi's Cyber Defense program and lead incident command efforts across the organization.
- As a dedicated incident response resource within Cyber Defense, you will coordinate cross-functional response efforts, maintain incident command structure during active events, and ensure consistent communication, documentation, and resolution tracking.
- This is a highly visible role that partners closely with SOC Analysts, Threat Research, Offensive Security, Tools Automation & Operations (TAO), Engineering, IT, Legal, Risk, Executive team, and other stakeholders to drive timely containment, eradication, and recovery.
- The ideal candidate thrives in fast-paced environments, brings structure to ambiguity, has exceptional communication skills, and can effectively drive complex incidents from detection through post-incident review.
- Serve as the primary Security Incident Commander for security incidents identified by the SOC.
This listing is sourced directly from SoFi's careers page and normalized into a canonical job model.