Staff Vulnerability Management Engineer
Core
Lead the most complex technical work in SoFi's Vulnerability Management program, designing scalable systems to identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud, infrastructure, containers, and supply chains.
Role type
Staff Vulnerability Management Engineer (hands-on IC with broad technical influence)
Builds
Scalable triage and prioritization automation, risk-based prioritization models, and AI-assisted remediation workflows
Domain
Cybersecurity / Vulnerability Management / Cloud-Native Infrastructure
Deliverable
production ML models | product features | infrastructure
Required skills
Vulnerability management expertise, modern infrastructure knowledge (cloud, containers, distributed systems), programming/scripting (Python, Go, Java), vulnerability management standards (CVSS, EPSS, CISA KEV), security tooling (Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable), end-to-end workflow design, cloud-native environments (AWS, GCP, Azure, Kubernetes), software supply chain knowledge (SBOM, SLSA, SAST, SCA), cross-functional leadership, mentoring
Preferred skills
Security orchestration platforms (Tines), serverless frameworks (AWS Lambda, Google Cloud Functions), regulated environment experience (FedRAMP, PCI DSS, SOC 2, ISO 27001, NIST), hardware vendor security partnerships
Technologies
Python, Go, Java, Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx, AWS, GCP, Azure, Kubernetes, SBOM, SLSA, Tines
Responsibilities
Lead high-complexity vulnerability management initiatives and make architecture decisions; Design, build, and productionize scalable triage and prioritization automation; Develop risk-based prioritization models combining threat intelligence and asset criticality; Engineer and improve vulnerability workflows across app security, cloud, containers, and supply chain; Act as senior technical responder for critical vulnerabilities and zero-day events; Partner with dev teams to define remediation paths and review secure code changes; Define technical standards for severity, SLAs, and audit-ready reporting; Produce actionable metrics, dashboards, and risk insights; Lead root-cause analysis for high-impact incidents; Evaluate and apply AI/ML techniques to security triage and remediation workflows
Seniority
Staff, hands-on IC with mentorship and broad influence