SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
SoFi is seeking a Senior Vulnerability Management Engineer to independently identify, assess, prioritize, and drive remediation of vulnerabilities across applications, infrastructure, containers, Kubernetes environments, and third-party dependencies.
In this role, you will understand how vulnerable dependencies enter applications, determine whether they are direct or transitive, identify appropriate remediation options, and work with engineering teams to implement and validate fixes. You will own and enhance internal vulnerability-management tools, including repositories, scheduled jobs, APIs, and reporting applications used to process and display vulnerability findings.
Key responsibilities include:
- Perform vulnerability assessments across applications, operating systems, containers, Kubernetes clusters, and third-party dependencies
- Investigate vulnerable dependencies and determine their origin and type
- Recommend safe dependency upgrades, configuration changes, patches, or compensating controls
- Own and maintain source-code repositories for internal vulnerability-management tools and reporting applications
- Integrate security tools with ticketing systems, repositories, dashboards, and reporting platforms via APIs and webhooks
- Identify false positives, duplicate findings, and findings lacking sufficient context
- Partner with engineering and infrastructure teams to prioritize vulnerabilities based on exploitability, exposure, asset criticality, and business impact
- Develop dashboards and reports communicating vulnerability risk, remediation progress, and program effectiveness
- Lead remediation initiatives and provide technical guidance to engineers and security team members
- Use approved AI-assisted development tools to support coding, debugging, vulnerability research, and documentation
Required qualifications include a Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent practical experience, plus 4+ years in information security, vulnerability management, application security, or related disciplines. You must have strong understanding of CVE, CVSS, CWE, CISA KEV, EPSS, OWASP, and risk-based vulnerability prioritization. Experience with vulnerability-management platforms (Qualys or similar), SAST/DAST/SCA tools, container security, and infrastructure scanning is essential. Proficiency in Python, Java, Go, or Bash is required, along with familiarity with containers, Kubernetes, CI/CD pipelines, and configuration management. You should be able to independently manage technical initiatives involving multiple engineering teams.