--- title: 'Staff Vulnerability Management Engineer at SoFi' canonical: 'https://feeny.ai/job/staff-vulnerability-management-engineer-sofi-seattle-89803np9qxbc' type: 'job' last_seen: '2026-09-10' --- # Staff Vulnerability Management Engineer at SoFi - **Company:** SoFi - **Location:** Seattle, WA / San Francisco, CA - **Posted:** 2026-07-30 - **Last confirmed live:** 2026-09-10 - **Apply:** https://sofi.com/careers/job/7818426003?gh_jid=7818426003 ## Job description [Employee Applicant Privacy Notice](https://www.sofi.com/sofi-employee-applicant-privacy-notice/) Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. ## The role We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi’s Vulnerability Management program. You will design and build scalable systems that identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud and infrastructure, containers, software supply chains, and specialized hardware or firmware surfaces. This is a hands-on engineering role with broad technical influence: you will write production code, make architecture decisions, establish vulnerability management standards, and improve how teams understand and reduce vulnerability risk. You will partner with Engineering, Infrastructure, SRE, Compliance, Legal, and business stakeholders to accelerate remediation while protecting engineering velocity and customer trust. You will also serve as a senior technical responder for embargoed disclosures and zero-day events, lead root-cause analysis for high-impact vulnerability incidents, and mentor engineers. The ideal candidate combines deep vulnerability management expertise with strong software engineering judgment, systems thinking, and a bias for durable, measurable outcomes. ## What you’ll do - Lead high-complexity vulnerability management initiatives and make architecture decisions for assigned program areas, from detection and assessment through ticket routing, remediation, exception handling, and closure validation. - Design, build, and productionize scalable triage and prioritization automation, including scanner and asset integrations, enrichment pipelines, decision logic, deduplication, ownership resolution, service-level tracking, observability, and failure recovery. - Develop risk-based prioritization models that combine CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations. - Engineer and improve vulnerability workflows across application security, cloud and infrastructure, containers and Kubernetes, open-source dependencies, secrets, software supply chain, and hardware-adjacent surfaces such as GPU, DPU/BlueField, BMC, and firmware. - Own or materially advance software supply chain capabilities, including SBOM inventory, dependency visibility, SLSA-aligned controls, and integration of SAST, SCA, secret scanning, and container scanning into CI/CD. - Act as a senior technical responder for critical vulnerabilities, embargoed disclosures, and zero-day events; coordinate technical assessment, containment, mitigation, patch deployment, validation, and executive communication with service owners and incident response teams. - Partner directly with development and platform teams to define practical remediation paths and, when appropriate, review or contribute secure changes in Python, Go, JavaScript/TypeScript, or infrastructure code. - Define technical standards for vulnerability severity, remediation service levels, exceptions, evidence, and closure criteria; ensure workflows support audit-ready reporting for applicable regulatory and compliance frameworks. - Produce actionable metrics, dashboards, and risk insights for technical and executive audiences, with clear accountability, trend analysis, compliance posture, and execution risks. - Lead root-cause analysis for high-impact vulnerability incidents and convert lessons learned into durable improvements to tooling, architecture, controls, and operating practices. - Evaluate and responsibly apply AI/ML and LLM-assisted techniques to security triage and decision support, with human-in-the-loop validation, measurable quality controls, and safe failure modes. - Build AI-assisted remediation workflows that partner with engineering teams to proactively identify, validate, and apply security patches, with appropriate testing, human oversight, rollback mechanisms, and measurable risk reduction. - Communicate complex security tradeoffs and program risks clearly to stakeholders across Engineering, Product, Operations, Legal, Compliance, and executive leadership. ## What you’ll need - Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience. - Deep expertise in vulnerability management, security engineering, and modern infrastructure, including cloud, containers, and distributed systems. - Strong programming or scripting skills in Python, Go, Java, or similar languages, with experience building automation at scale. - Deep knowledge of vulnerability management methods and standards, including CVSS, EPSS, CISA KEV, threat intelligence integration, asset and exposure context, remediation SLAs, exception governance, and risk-based prioritization. - Hands-on experience with modern vulnerability and application security tooling such as Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx, or equivalent platforms, plus experience tuning SAST, SCA, secret scanning, container, or cloud findings. - Experience designing end-to-end workflows that integrate scanners, asset inventories or CMDBs, ticketing systems, CI/CD platforms, data stores, dashboards, and alerting systems. - Working knowledge of cloud-native and software supply chain environments, including AWS, GCP, or Azure; Kubernetes and containers; build systems and package managers; SBOMs; and Infrastructure as Code. - Demonstrated ability to lead cross-functional technical initiatives, influence without direct authority, make sound decisions amid ambiguity, and drive work from concept through production operation and measurable outcomes. - Experience mentoring senior and developing engineers and raising engineering quality through design reviews, code reviews, standards, and incident leadership. - Strong written and verbal communication, business judgment, and the ability to explain how security choices affect engineering velocity, regulatory obligations, customer trust, and business risk. ## Nice to have - Experience managing security partnerships with hardware or software vendors, including embargoed disclosures, coordinated vulnerability disclosure, and pre-release remediation collaboration. - Production experience with security orchestration platforms such as Tines and serverless frameworks such as AWS Lambda or Google Cloud Functions. - Experience scaling vulnerability management in a high-growth, cloud-native environment or operating within FedRAMP, PCI DSS, SOC 2, ISO 27001, NIST, or comparable regulated environments. ## Compensation and Benefits The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location. To view all of our comprehensive and competitive benefits, visit our [Benefits at SoFi](https://sofietyinfo.sofi.com/sofi-benefits) page! SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law. The Company hires the best qualified candidate for the job, without regard to protected characteristics. Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records. [New York applicants: Notice of Employee Rights](https://dol.ny.gov/system/files/documents/2022/02/ls740_1.pdf) SoFi is committed to an inclusive culture. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com. We are unable to accommodate remote work from Hawaii, Alaska or Puerto Rico at this time. Internal Employees If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles. ## About SoFi ## Company Overview - **One-liner**: SoFi is a next-generation fintech company using innovative, mobile-first technology to help 14.7 million members reach financial independence and “get their money right.” - **Entity Type**: Public (Ticker: SOFI on Nasdaq) - **Headquarters**: San Francisco, California, USA (with offices in Seattle, New York, Frisco, Cottonwood Heights, Helena, Murray, Greenville, Claymont, and more) - **Founded**: 2011 - **Founders**: Founded by Stanford business school students (originally as Social Finance, Inc.) — specific names not listed in the provided sources. ## Core Business - **Primary industry/industries**: Personal finance / financial services (banking, lending, investment, credit, insurance) - **Target customers**: B2C (individual members seeking loans, banking, investing, credit cards, mortgages, travel rewards) and B2B (employer‑facing “SoFi at Work” benefits and financial wellness programs) - **Mission**: “To help people reach financial independence to realize their ambitions.” ## Products & Services - **[SoFi Checking & Savings](https://www.sofi.com/)**: FDIC‑insured checking and savings accounts with no fees, competitive APY, and early direct deposit. - **[SoFi Invest](https://www.sofi.com/invest/)**: Commission‑free stock trading, crypto trading, automated investing, and IPO access. - **[SoFi Personal Loans](https://www.sofi.com/personal-loans/)**: Unsecured personal loans for debt consolidation, home improvement, etc. (up to $100K). - **[SoFi Student Loan Refinancing](https://www.sofi.com/student-loans/)**: Refinancing for federal and private student loans (the first company to offer this). - **[SoFi Mortgages](https://www.sofi.com/mortgage/)**: Home purchase and refinance loans. - **[SoFi Credit Card](https://www.sofi.com/credit-card/)**: 2% unlimited cash back rewards on all eligible purchases. - **[SoFi Travel](https://www.sofi.com/travel/)**: Booking portal powered by Expedia, allowing members to save and earn rewards. - **[SoFi Insurance](https://www.sofi.com/insurance/)**: Comparison and access to auto, home, renters, pet, and life insurance. - **[SoFi at Work](https://www.sofi.com/at-work/)**: Employer‑sponsored financial wellness benefits, including student loan contributions and refinancing. - **[Galileo](https://www.sofi.com/our-story/)**: Financial technology platform (API‑based) for card issuing and digital banking, operated as a subsidiary. ## Market Standing - **Valuation/Market Cap**: Publicly traded on Nasdaq (SOFI). Current market cap is not directly provided in the sources; refer to SoFi’s latest SEC filings or financial data platforms. - **Key Metrics**: - **14.7 million members** (as of 2025‑2026) — [sofi.com](https://www.sofi.com/) - **$117 billion+ in funded loans** — [sofi.com](https://www.sofi.com/) - **$34 billion+ in debt paid off by members** — [sofi.com/our-story](https://www.sofi.com/our-story/) - **$12.5 billion+ in rewards earned** — [sofi.com](https://www.sofi.com/) - **Annual Revenue**: See SoFi Technologies 2025 Annual Report (SEC filing) for latest financial results — [sec.gov](https://www.sec.gov/Archives/edgar/data/1818874/000181887426000034/sofitech2025ars.pdf) - **Notable Investors/Partners**: Not detailed in provided sources; historically received a $1 billion funding round in 2016 (the first U.S. fintech to do so) — [sofi.com/our-story](https://www.sofi.com/our-story/) - **Growth Signals**: - Received federal approval to become a national bank (2023) — [sofi.com/our-story](https://www.sofi.com/our-story/) - Reached 10 million members in 2022 and 14.7 million by early 2026 — [sofi.com](https://www.sofi.com/) - 121 open roles listed across 16 locations as of mid‑2026 — [sofi.com/careers](https://www.sofi.com/careers/) - Continuous product expansion (travel, credit card, bank, etc.) ## Competitive Advantages - **All‑in‑one fintech ecosystem**: Banking, lending, investing, insurance, and travel in a single mobile‑first app — hard for single‑product fintechs to replicate. - **SoFi National Bank**: FDIC‑insured checking and savings, giving SoFi a direct banking charter that reduces reliance on third‑party partners. - **Galileo Platform**: Powers card issuing and digital banking for many fintechs, creating a network effect and deeper technology moat. - **Member‑centric rewards**: SoFi Plus membership program bundles benefits (higher APY, bonus rewards, career coaching). - **Student loan repayment as employee benefit**: Unique perk for attracting talent (as well as offering SoFi at Work to other employers). ## Strategic Focus - **Deepen member engagement**: Cross‑sell more products within the single app to increase lifetime value. - **Grow the bank**: Expand deposits, lending, and banking services under the national bank charter. - **SoFi at Work**: Scale B2B benefits offering to acquire members through employers. - **International/vertical expansion**: Potential for new product lines (e.g., SoFi Travel, insurance marketplace). - **Maintain cost discipline**: Leverage technology to keep customer acquisition costs low while improving unit economics. ## Why Work Here - **Culture**: Defined by “The SoFi Way” — act as a founder, relentless problem solver, and partner to members and colleagues. Emphasis on transparency, trust, and cross‑collaboration. - **Flexible Work**: Some teams offer remote, hybrid, or full‑time in‑office based on role; managers help decide the best setting. SoFridays (no meetings after 2 p.m. local time) protect focus time. - **Benefits**: - **$200/month student loan contribution** to help employees pay down debt — [sofi.com/careers](https://www.sofi.com/careers/) - Comprehensive health, vision, dental, life, disability; fertility & family planning options; flexible time off - Tuition reimbursement up to $5,250/year + regular training and leadership programs - **SoFi Gives**: 16 hours of paid volunteer time off per year - **SoFi Circles**: 8 Employee Resource Groups fostering inclusion and belonging — [sofietyinfo.sofi.com/why-sofi](https://sofietyinfo.sofi.com/why-sofi) - **Learning & Development**: Career pathways, manager excellence framework, and mentorship programs. - **Monthly All‑Hands with CEO** for direct transparency. - **Locations**: Major hubs include San Francisco, Seattle, New York, and Frisco (Texas); remote work is not available from Hawaii or Alaska due to insurance coverage — [sofi.com/careers](https://www.sofi.com/careers/) ## Sources 1. [SoFi Careers Page](https://www.sofi.com/careers/) — benefits, culture, job openings, locations 2. [SoFi Homepage](https://www.sofi.com/) — member count, funded loans, key metrics 3. [SoFi Our Story / About](https://www.sofi.com/our-story/) — founding history, milestones, mission 4. [SoFi 2025 Annual Report (SEC)](https://www.sec.gov/Archives/edgar/data/1818874/000181887426000034/sofitech2025ars.pdf) — financials 5. [SoFi Candidate Resource Website (Why SoFi)](https://sofietyinfo.sofi.com/why-sofi) — flexible work, culture, SoFi Gives, learning programs, SoFridays ## Other roles at SoFi - [Lead Product Tax Advisor](https://feeny.ai/job/lead-product-tax-advisor-sofi-united-states-9rgzasx0zjc1) — United States - [Vulnerability Management Engineer](https://feeny.ai/job/vulnerability-management-engineer-sofi-san-francisco-y41wdmqewmwv) — San Francisco, CA - [Senior Vulnerability Management Engineer](https://feeny.ai/job/senior-vulnerability-management-engineer-sofi-seattle-f7y0a5rtcajr) — Seattle, WA / San Francisco, CA - [Offensive Security Lead](https://feeny.ai/job/offensive-security-lead-sofi-san-francisco-vdwsssftz6af) — San Francisco, CA / Seattle, WA / New York, NY / UT / Cottonwood Heights / TX / Frisco / MT / Helena - [Partnership Success Manager, At Work](https://feeny.ai/job/partnership-success-manager-at-work-sofi-united-states-g3dnwwnx0hrq) — United States - [Senior Manager, Enterprise Learning & Development](https://feeny.ai/job/senior-manager-enterprise-learning-development-sofi-san-francisco-3ges7wvzr994) — San Francisco, CA - [Investment Specialist II](https://feeny.ai/job/investment-specialist-ii-sofi-jacksonville-49ms913fzktr) — Jacksonville, FL - [Home Equity Underwriter](https://feeny.ai/job/home-equity-underwriter-sofi-frisco-xqg46xtgw5g3) — Frisco, TX - [AI Workflow & Design Systems Specialist (Contract)](https://feeny.ai/job/ai-workflow-design-systems-specialist-contract-sofi-san-francisco-08ry1h2k04kd) — San Francisco, CA - [Manager, Strategic Finance](https://feeny.ai/job/manager-strategic-finance-sofi-united-states-xdgv258pqk26) — United States