SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
SoFi is seeking a Staff Technical Program Manager to lead the Vulnerability Management program and drive maturity across critical cybersecurity initiatives. This high-impact role focuses on building durable program structure, improving remediation outcomes, and enabling cross-functional execution across Security, Engineering, Product, Infrastructure, Enterprise Technology, Risk, and Compliance.
You will own the strategic program management of SoFi's vulnerability management ecosystem, which spans multiple detection layers across code, containers, cloud infrastructure, endpoints, APIs, mobile, data, and secrets. Your primary responsibilities include developing and executing the technical program strategy, establishing scalable operating rhythms for vulnerability intake through closure, and improving risk-based prioritization frameworks that incorporate severity, exploitability, asset criticality, exposure, and business context.
Key deliverables include building governance and reporting mechanisms that make vulnerability management progress visible to technical and non-technical stakeholders, defining and tracking program KPIs and operational health metrics, and driving cross-functional remediation campaigns that reduce mean time to remediate. You will identify process and tooling gaps across the vulnerability detection and remediation workflow, influence technical decisions without direct authority by translating security risk into business impact, and proactively identify opportunities for operational improvement through pattern analysis.
The ideal candidate has 8+ years in technical program management, security program management, security operations, product security, application security, infrastructure security, or DevSecOps. You must have demonstrated ownership of vulnerability management or adjacent security programs at scale and understand how to turn complex security risk into clear priorities and executable plans. While hands-on vulnerability engineering is not expected, you need sufficient technical depth to operate credibly with security engineers, application teams, and infrastructure teams. Strong stakeholder influence, organizational navigation, and the ability to convert ambiguous security data into clear, business-aligned risk reduction outcomes are essential.