SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
SoFi's Cyber Defense organization seeks an Offensive Security Lead to mature and scale its Penetration Testing and Red Team functions. This is a hands-on leadership role combining deep technical execution with program strategy and team management.
You will own the strategy, staffing, tooling, and execution quality of both penetration testing and red team disciplines, reporting to Cyber Defense leadership and serving as a trusted advisor to engineering, product, and risk partners.
Key responsibilities include:
- Unifying Penetration Testing and Red Team into a cohesive Offensive Security function with shared standards, tradecraft, and reporting
- Setting and executing the offensive security roadmap aligned to SoFi's risk profile, regulatory obligations, and product velocity
- Building and scaling AI-augmented offensive security capabilities—designing workflows for AI-assisted reconnaissance, vulnerability triage, exploit chaining, purple-team simulation, and report generation
- Personally leading engagements (network, application, cloud, AI pentests, adversary emulation, full-scope red team operations) to maintain technical credibility
- Managing and developing the team: hiring, coaching, mentoring, and building career paths between disciplines and into leadership
- Defining and owning program metrics (coverage, finding severity, remediation velocity, engagement quality, ROI) and reporting to senior leadership and risk committees
- Partnering cross-functionally with Vulnerability Management, SOC/Incident Response, Application Security, and engineering teams
- Managing external vendor partnerships for third-party pentesting and red team tooling/execution
- Representing Offensive Security in audits, regulatory exams, and executive briefings
Required qualifications:
- 8+ years in offensive security with demonstrated hands-on experience in both penetration testing and red team/adversary emulation
- 2+ years directly managing or leading offensive security teams, ideally in a regulated industry (financial services, fintech, healthcare)
- Proven experience designing and implementing AI-led or AI-assisted offensive security programs with concrete examples of what scaled
- Deep technical fluency across network, web/application, cloud (AWS/GCP/Azure), and mobile attack surfaces
- Familiarity with adversary emulation frameworks (MITRE ATT&CK) and C2 tooling
- Track record of building programs from the ground up or maturing existing ones—process, tooling, metrics, team structure
- Strong written and verbal communication skills; comfort presenting to engineering leaders and risk teams