Security Product Lead – Enterprise & Identity Security

SoFi SoFi · Fintech · San Francisco, CA · Information Security

The Security Product Lead will define the strategic direction, roadmap, and measurable outcomes for securing the organization's enterprise infrastructure, critical internal systems, and user identities. This role involves treating Enterprise Security and Identity Security capabilities as internal security products, aligning with enterprise risk priorities, and delivering through structured program governance. Key responsibilities include developing multi-year strategies and roadmaps for Enterprise Security, Identity Security (IAM, PAM, Authentication), and AI Security capabilities, managing product requirements for Data Security, and defining outcome-based metrics for security platforms. The role requires strong cross-functional collaboration, strategic thinking, and influencing skills, with a focus on protecting member trust and corporate assets.

What you'd actually do

  1. Develop and maintain a multi-year strategy and roadmap for Enterprise Security, Identity Security (IAM, PAM, Authentication), and AI Security capabilities.
  2. Define the value proposition and service model for Enterprise Security capabilities (e.g., infrastructure hardening, cloud security posture).
  3. Maintain and prioritize a strategic backlog across all areas aligned to measurable risk reduction outcomes (e.g., reduction in over-privileged accounts, faster access revocation, secure-by-design adoption in AI).
  4. Own the portfolio view of Enterprise, Identity, and AI Security initiatives within the broader security strategy.
  5. Partner closely with the Identity & Access Management, Infrastructure Security, and AI/ML functional leaders to align on priorities and execution sequencing.

Skills

Required

  • 7+ years of experience in cybersecurity, risk management, or technology strategy roles.
  • Demonstrated experience in Identity & Access Management (IAM), Privileged Access Management (PAM), Enterprise Security, Data Security, or AI/ML Security domains.
  • Demonstrated experience building and managing strategic roadmaps tied to measurable outcomes.
  • Strong understanding of security frameworks, identity protocols (e.g., OAuth, SAML, SCIM), and enterprise risk.
  • Understanding of AI/ML concepts and associated security risks, including data provenance, model integrity, and adversarial machine learning.
  • Strong product mindset with ability to translate strategy into execution.
  • Experience working in matrixed organizations with cross-functional stakeholders.
  • Strong analytical, communication, and executive presentation skills.

Nice to have

  • Bachelor’s degree in Computer Science, Cybersecurity, or related discipline.

What the JD emphasized

  • AI Security capabilities
  • AI governance
  • AI model integrity
  • AI/ML Security domains
  • AI-specific threats
  • AI/ML concepts and associated security risks