Staff Vulnerability Management Engineer

SoFi SoFi · Fintech · San Francisco, CA · Information Security

Staff Vulnerability Management Engineer at SoFi, responsible for designing and building scalable systems to identify, enrich, prioritize, route, and track vulnerabilities. The role involves writing production code, making architecture decisions, establishing standards, and improving risk management. A key aspect is evaluating and applying AI/ML and LLM-assisted techniques to security triage and remediation workflows, with a focus on human-in-the-loop validation and measurable outcomes.

What you'd actually do

  1. Lead high-complexity vulnerability management initiatives and make architecture decisions for assigned program areas, from detection and assessment through ticket routing, remediation, exception handling, and closure validation.
  2. Design, build, and productionize scalable triage and prioritization automation, including scanner and asset integrations, enrichment pipelines, decision logic, deduplication, ownership resolution, service-level tracking, observability, and failure recovery.
  3. Develop risk-based prioritization models that combine CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations.
  4. Engineer and improve vulnerability workflows across application security, cloud and infrastructure, containers and Kubernetes, open-source dependencies, secrets, software supply chain, and hardware-adjacent surfaces such as GPU, DPU/BlueField, BMC, and firmware.
  5. Own or materially advance software supply chain capabilities, including SBOM inventory, dependency visibility, SLSA-aligned controls, and integration of SAST, SCA, secret scanning, and container scanning into CI/CD.

Skills

Required

  • Vulnerability management expertise
  • Software engineering judgment
  • Systems thinking
  • Python
  • Go
  • JavaScript/TypeScript
  • Infrastructure as code
  • Modern infrastructure (cloud, containers, distributed systems)
  • Vulnerability management methods and standards (CVSS, EPSS, CISA KEV, threat intelligence, asset criticality, exposure, remediation SLAs, exception governance, risk-based prioritization)
  • Modern vulnerability and application security tooling (Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, Checkmarx)
  • SAST, SCA, secret scanning, container scanning, cloud findings tuning
  • Designing end-to-end workflows (scanners, asset inventories, ticketing systems, CI/CD, data stores, dashboards, alerting)
  • Cloud-native and software supply chain environments

Nice to have

  • AI/ML and LLM-assisted techniques for security triage and decision support
  • AI-assisted remediation workflows

What the JD emphasized

  • production code
  • scalable systems
  • risk-based prioritization
  • software supply chain
  • critical vulnerabilities
  • AI/ML and LLM-assisted techniques
  • AI-assisted remediation workflows

Other signals

  • AI/ML for security triage
  • LLM-assisted techniques
  • AI-assisted remediation workflows