SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
SoFi is seeking a Staff Cryptography Engineer to lead enterprise readiness for post-quantum cryptography and long-term cryptographic resilience. This highly cross-functional role sits within the Security Assurance organization and partners with security, engineering, infrastructure, product, and business stakeholders to assess, modernize, and strengthen cryptographic controls across the enterprise.
You will lead efforts to assess and improve SoFi's cryptographic posture with a focus on post-quantum cryptography preparedness and crypto-agility. Key responsibilities include building and maintaining an inventory of cryptographic assets (keys, certificates, algorithms, protocols, libraries, services, and business-critical systems), partnering with product, engineering, infrastructure, cloud, and security teams to identify dependencies and prioritize remediation, and providing deep technical guidance on SSL/TLS, PKI, certificates, key management, encryption, and secure protocol usage.
You will define and document cryptographic standards, design patterns, review gates, and implementation guidance for engineering and product teams. This includes evaluating current and future cryptographic risks such as quantum-resistant key migration, algorithm deprecation, certificate lifecycle management, and insecure implementation patterns. You'll review product and platform architecture designs to identify cryptographic risks and recommend practical, scalable security improvements.
The role requires translating complex cryptographic concepts into clear guidance, roadmaps, and decision points for technical and non-technical stakeholders. You will drive cross-functional execution across teams without direct authority, ensuring ownership, timelines, and risk decisions are clearly documented. You'll support security assurance activities including threat modeling, architecture reviews, control validation, and post-review follow-through, while staying current on post-quantum cryptography developments and industry standards.
Required qualifications include 8+ years in security engineering, product security, applied cryptography, security architecture, or related technical security disciplines. You need deep hands-on expertise in applied cryptography, including cryptographic algorithms, secure protocol design (SSL/TLS, mTLS, M2M), and enterprise-grade solutions such as HSMs, KMS, secrets management, and PKI programs. Experience assessing or designing cryptographic controls in production engineering environments (cloud, distributed systems, services, APIs, enterprise platforms) is essential. Strong understanding of public cloud environments and ability to review technical architecture and identify practical cryptographic risks are required. You should have experience creating or driving security standards, technical guidance, inventories, roadmaps, or enterprise-wide security initiatives, with strong communication skills and demonstrated ability to operate independently in ambiguous problem spaces.