CareerPlanSign in

Staff Vulnerability Management Engineer

CA - San Francisco💼 Full-time🗓 2026-07-30 → 2026-09-26

Core

Lead the most complex technical work in SoFi's Vulnerability Management program, designing scalable systems to identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud, infrastructure, containers, and supply chains.

Role type

Staff Vulnerability Management Engineer (hands-on IC with broad technical influence)

Builds

Scalable triage and prioritization automation, risk-based prioritization models, and AI-assisted remediation workflows

Domain

Cybersecurity / Vulnerability Management / Cloud-Native Infrastructure

Deliverable

production ML models | product features | infrastructure

Required skills

Vulnerability management expertise, modern infrastructure knowledge (cloud, containers, distributed systems), programming/scripting (Python, Go, Java), vulnerability management standards (CVSS, EPSS, CISA KEV), security tooling (Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable), end-to-end workflow design, cloud-native environments (AWS, GCP, Azure, Kubernetes), software supply chain knowledge (SBOM, SLSA, SAST, SCA), cross-functional leadership, mentoring

Preferred skills

Security orchestration platforms (Tines), serverless frameworks (AWS Lambda, Google Cloud Functions), regulated environment experience (FedRAMP, PCI DSS, SOC 2, ISO 27001, NIST), hardware vendor security partnerships

Technologies

Python, Go, Java, Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx, AWS, GCP, Azure, Kubernetes, SBOM, SLSA, Tines

Responsibilities

Lead high-complexity vulnerability management initiatives and make architecture decisions; Design, build, and productionize scalable triage and prioritization automation; Develop risk-based prioritization models combining threat intelligence and asset criticality; Engineer and improve vulnerability workflows across app security, cloud, containers, and supply chain; Act as senior technical responder for critical vulnerabilities and zero-day events; Partner with dev teams to define remediation paths and review secure code changes; Define technical standards for severity, SLAs, and audit-ready reporting; Produce actionable metrics, dashboards, and risk insights; Lead root-cause analysis for high-impact incidents; Evaluate and apply AI/ML techniques to security triage and remediation workflows

Seniority

Staff, hands-on IC with mentorship and broad influence

Sourced via greenhouse · Listed on CareerPlan, which tracks 70,000+ jobs from 20+ sources.