Staff Vulnerability Management Engineer

SoFi Technologies
Seattle, San Francisco
Workplace: OnsiteFull timeUSD 144,000 - 247,500 annuallyFunction: Data Analytics & Business IntelligenceEducation: bachelorsSkills: ["Systems thinking","Cross-functional leadership","Influence without direct authority","Mentoring","Communication"]

Design and build scalable vulnerability management systems that identify, enrich, prioritize, route, remediate, and validate findings across applications, cloud/infrastructure, containers, software supply chains, and hardware-adjacent surfaces. Lead triage and prioritization automation, develop risk-based models using CVSS/EPSS/CISA KEV and threat intelligence, and integrate security controls into CI/CD. Serve as a senior responder for zero-day and embargoed disclosures, lead incident root-cause analysis, mentor engineers, and drive measurable risk reduction.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
SoFi Technologies
SoFi Technologies
1 month ago

Staff Vulnerability Management Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 19 hours agoStatus: Live

Job Summary

Design and build scalable vulnerability management systems that identify, enrich, prioritize, route, remediate, and validate findings across applications, cloud/infrastructure, containers, software supply chains, and hardware-adjacent surfaces. Lead triage and prioritization automation, develop risk-based models using CVSS/EPSS/CISA KEV and threat intelligence, and integrate security controls into CI/CD. Serve as a senior responder for zero-day and embargoed disclosures, lead incident root-cause analysis, mentor engineers, and drive measurable risk reduction.
Location: Seattle, San Francisco
Workplace: Onsite
Employment Type: Full time
Job Function: Data Analytics & Business Intelligence
Seniority: Sr. Manager level

Key Responsibilities

  • •Lead high-complexity vulnerability management initiatives and make architecture decisions across detection, assessment, ticket routing, remediation, exception handling, and closure validation.
  • •Design and productionize scalable triage and prioritization automation, including scanner/asset integrations, enrichment pipelines, decision logic, deduplication, ownership resolution, tracking, observability, and failure recovery.
  • •Develop risk-based prioritization models using CVSS, EPSS, CISA KEV, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations.
  • •Engineer vulnerability workflows across application security, cloud/infrastructure, containers and Kubernetes, open-source dependencies, secrets, software supply chain, and hardware-adjacent surfaces.
  • •Serve as a senior responder for critical vulnerabilities, embargoed disclosures, and zero-day events; coordinate assessment/containment/mitigation and communicate outcomes; lead root-cause analysis and implement durable improvements.

Pay and Benefits

Salary: USD 144,000 - 247,500 annually

Key Requirements

  • •Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related field, or equivalent practical experience.
  • •Deep expertise in vulnerability management, security engineering, and modern infrastructure (cloud, containers, distributed systems).
  • •Strong programming/scripting skills in Python, Go, Java (or similar) and experience building automation at scale.
  • •Working knowledge of vulnerability management standards and methods including CVSS, EPSS, CISA KEV, threat intelligence integration, and risk-based prioritization.
  • •Hands-on experience with vulnerability/app security tooling such as Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx, plus tuning SAST/SCA/secret scanning/container or cloud findings.
Education:Bachelor's
Skills:Systems thinkingCross-functional leadershipInfluence without direct authorityMentoringCommunication
Languages:En
Tech Stack:PythonGoJavaJavaScript/TypeScriptAWSGCPAzureKubernetesCI/CDSASTSCASecret scanningContainer scanningSBOMSLSAInfrastructure as CodeCMDBCVSSEPSSCISA Known Exploited Vulnerabilities

Company Brief

SoFi Technologies
Provides digital financial services including lending, banking, investing, and credit products through a consumer-focused online platform. SoFi serves individuals looking to manage money, borrow, save, invest, and protect their finances in one place.
Industry: Neobanking
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: San Francisco, United States
Founded: 2011
WebsiteLinkedIn