Get more replies from employers
Send a job-specific resume in minutes.
SoFi is seeking a Staff Vulnerability Management Engineer to lead complex vulnerability programs across applications, cloud, and infrastructure. You will design scalable triage, enrichment, and remediation workflows, partnering with Engineering, SRE, Compliance, and Legal to accelerate remediation while preserving velocity and trust.
The role involves mentoring engineers, building AI‑assisted remediation workflows, and defining technical standards for vulnerability management with an audit‑ready
Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi’s Vulnerability Management program. You will design and build scalable systems that identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud and infrastructure, containers, software supply chains, and specialized hardware or firmware surfaces. This is a hands‑on engineering role with broad technical influence: you will write production code, make architecture decisions, establish vulnerability management standards, and improve how teams understand and reduce vulnerability risk. You will partner with Engineering, Infrastructure, SRE, Compliance, Legal, and business stakeholders to accelerate remediation while protecting engineering velocity and customer trust. You will also serve as a senior technical responder for embargoed disclosures and zero‑day events, lead root‑cause analysis for high‑impact vulnerability incidents, and mentor engineers. The ideal candidate combines deep vulnerability management expertise with strong software engineering judgment, systems thinking, and a bias for durable, measurable outcomes.
Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience. Deep expertise in vulnerability management, security engineering, and modern infrastructure, including cloud, containers, and distributed systems. Strong programming or scripting skills in Python, Go, Java, or similar languages, with experience building automation at scale. Deep knowledge of vulnerability management methods and standards, including CVSS, EPSS, CISA KEV, threat intelligence integration, asset and exposure context, remediation SLAs, exception governance, and risk‑based prioritization. Hands‑on experience with modern vulnerability and application security tooling such as Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx, or equivalent platforms, plus experience tuning SAST, SCA, secret scanning, container, or cloud findings. Experience designing end‑to‑end workflows that integrate scanners, asset inventories or CMDBs, ticketing systems, CI/CD platforms, data stores, dashboards, and alerting systems. Working knowledge of cloud‑native and software supply chain environments, including AWS, GCP, or Azure; Kubernetes and containers; build systems and package managers; SBOMs; and Infrastructure as Code. Demonstrated ability to lead cross‑functional technical initiatives, influence without direct authority, make sound decisions amid ambiguity, and drive work from concept through production operation and measurable outcomes. Experience mentoring senior and developing engineers and raising engineering quality through design reviews, code reviews, standards, and incident leadership. Strong written and verbal communication, business judgment, and the ability to explain how security choices affect engineering velocity, regulatory obligations, customer trust, and business risk.
Experience managing security partnerships with hardware or software vendors, including embargoed disclosures, coordinated vulnerability disclosure, and pre-release remediation collaboration. Production experience with security orchestration platforms such as Tines and serverless frameworks such as AWS Lambda or Google Cloud Functions. Experience scaling vulnerability management in a high‑growth, cloud‑native environment or operating within FedRAMP, PCI DSS, SOC 2, ISO 27001, NIST, or comparable regulated environments.
The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location.
SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law. The Company hires the best qualified candidate for the job, without regard to protected characteristics. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. New York applicants: Notice of Employee Rights SoFi is committed to an inclusive culture. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com. Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.