SoFi

Vulnerability Management Engineer

SoFi$110K — $130K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's Degree in Computer Science, Information Systems, or equivalent experience
  • Strong knowledge of vulnerability management standards like CVE and CVSS
  • Experience with vulnerability assessment tools (DAST/SAST)
  • Excellent communication skills for explaining security concepts
  • Ability to prioritize remediation based on risk assessments
  • Deep application security knowledge and investigative techniques
  • Hands-on coding experience in languages like Bash, Go, or Python

Responsibilities

  • Perform regular vulnerability assessments with various tools
  • Assess and prioritize discovered vulnerabilities based on impact
  • Conduct security reviews of products and infrastructure
  • Contribute to vulnerability management and application security efforts
  • Engage in security audits with partners and vendors
  • Support compliance monitoring and reporting
  • Develop and document processes to improve team efficiency

Benefits

  • Comprehensive and competitive benefits package
  • Opportunities for professional development and growth
  • Collaborative team environment
  • Support for work-life balance
  • Potential for remote work options
Full Job Description
About The role

As a Vulnerability Management Engineer, you will support the identification, assessment, prioritization, and remediation of vulnerabilities across applications and infrastructure. Working under the guidance of senior team members, you will assist in understanding how vulnerable dependencies enter an application, identifying remediation options, and engaging with engineering teams to track fixes.

You will contribute to the maintenance of internal vulnerability-management tools, such as scripts, documentation, and reporting. The ideal candidate will have a desire to grow their AppSec expertise, will be eager to learn about modern security tooling and automation, and will be comfortable using AI tools like Claude to assist with documentation, investigation, and scripting tasks while following company security and data-handling requirements.

What you'll do
  • Perform regular vulnerability assessments using different tools. Regularly drive remediation and reporting of cataloged vulnerabilities.
  • Assess discovered vulnerabilities and properly prioritize their scope, impact and necessary response actions.
  • Conduct security reviews of our products and production infrastructure.
  • Contribute to vulnerability management, application security and/or offensive/red-team operations.
  • Engage in security audit and security regulatory exercises with partners and vendors.
  • Support regulatory compliance monitoring and reporting
  • Support treatment and remediation activities with identified points of contact and system owners
  • Develop processes and document procedures for use by other team members and to enhance efficiencies

What you'll need
  • Bachelor's Degree in Computer Science, Information Systems, or equivalent work-related experience
  • Strong knowledge of industry standards regarding vulnerability management including Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), OWASP, etc.
  • Experience with different types of vulnerability assessment tools or related experience in vulnerability detection DAST/SAST tools
  • Outstanding communication and interpersonal skills, with the capacity to effectively convey intricate security concepts to both technical and non-technical stakeholders.
  • Ability to demonstrate knowledge with prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets
  • Experience judging the vulnerability priority based on risk and impact
  • Deep application security knowledge, with the ability to map an application vulnerability to exploitation indications and relevant investigative techniques.
  • Hands-on experience with at least one coding language (Bash, Go, Python, Java).
  • Experience with Secure Software Development Life Cycles.

Preferred Qualifications
  • 2+ years of experience in an information technology/security role
  • 2+ years of experience with cloud technologies
  • Ability to manage relationships with other business units, external vendors, and stakeholders when IT security risks are present and system or process changes must be made to mitigate risk
  • Familiarity with AWS and at-scale services
  • Experience with micro-service architecture
  • Knowledge of CI/CD, application development and testing tools
  • Ability to work in a fast paced and Agile development environment
  • Work and play well with others; SoFi is a collaborative environment

Nice to have
  • Masters or PhD in Computer Science or Engineering
  • Financial services experience


Compensation and Benefits

The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location.

To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!

Internal Employees

If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.

About SoFi

SoFi is a financial services company that offers a range of products including student loan refinancing, personal loans, and mortgages. The company was founded in 2011 and is headquartered in San Francisco, California. SoFi's mission is to help people achieve financial independence by providing access to affordable credit and financial education. The company has over 1,200 employees and has funded over $50 billion in loans to date. SoFi is a privately held company and has raised over $2 billion in funding from investors including SoftBank, Silver Lake, and Peter Thiel.
Learn more about SoFi
Size
1,200 employees
Industry
Founded
2011

Similar Jobs

More Jobs at SoFi

More Information Technology Jobs

Find similar Vulnerability Management Engineer jobs: