Fraud Strategist - Ecosystem

SoFi SoFi · Fintech · Cottonwood Heights, UT · Fraud Ops Strategy

This role focuses on developing and implementing fraud strategy across various SoFi products, using data analysis, rule engines, and cross-product reasoning to mitigate risks like account takeover and scams. It involves building data systems and influencing stakeholders.

What you'd actually do

  1. Owning fraud strategy across the full SoFi product surface, designing decisioning that uses signals from onboarding, login, money movement, and product activity together rather than in isolation.
  2. Leading cross-product perimeter defense covering ATO carryover from compromised credentials, scam interception (authorized push payment, romance, investment, impostor, business email compromise), mule-account detection, and synthetic-identity attacks at funding.
  3. Driving device forensics across product lines: shared device-graph infrastructure, emulator and VM detection, jailbreak and root signals, residential-proxy detection, and entity resolution that links a single bad actor across accounts that look clean in isolation.
  4. Designing risk-tiered money movement decisioning for ACH, FedNow, Wire, Zelle, and P2P flows, replacing fixed dollar caps with dynamic frameworks priced on velocity, recency, counterparty risk, and scam telemetry.
  5. Building the cross-product analytics layer in SQL and Python: shared feature tables, entity-resolution signals, and rule-level attribution that lets every product line see a member’s full risk posture.

Skills

Required

  • Fraud Analytics across multiple product lines
  • ATO and Scam Defense
  • Perimeter Threat Fluency
  • Device Forensics
  • Cross-Product Reasoning
  • Money Movement and Onboarding
  • SQL
  • Python

Nice to have

  • BA/BS in Statistics, Information Systems, Mathematics, Data Science, or related fields, or equivalent work experience
  • IDV vendor stacks (Socure, Persona, Veriff)
  • Rules engines (Oscilar, SAFE, Camunda)

What the JD emphasized

  • Demonstrated track record reducing account takeover and scam losses across more than one product line.
  • Operational understanding of how perimeter threats (credential stuffing, MFA bombing, SIM swap, mule-account farming, synthetic identity at funding, first-party intent fraud) manifest at each entry surface of a multi-product fintech.
  • Hands-on experience with device fingerprinting, emulator and VM detection, jailbreak and root signals, behavioral biometrics, and entity-level device-graph analysis as a tool for linking accounts across products.
  • Demonstrated track record building fraud strategy that spans more than one product line, with explicit framing of where signals transfer, where they do not, and how to govern shared risk infrastructure.
  • Expert-level SQL/Python skills used to build automated, high-volume data architectures and statistical models that serve as the foundation for global risk detection.