SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Vulnerability Management Engineer

SoFi - Seattle, WA, United States - Hybrid - posted 2026-07-30

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

SoFi is seeking a Staff Vulnerability Management Engineer to lead complex technical work in their vulnerability management program. This is a hands-on engineering role with broad technical influence across the organization. You will design and build scalable systems that identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud infrastructure, containers, software supply chains, and specialized hardware/firmware surfaces. Key responsibilities include: • Lead high-complexity vulnerability management initiatives and make architecture decisions for detection, assessment, ticket routing, remediation, and closure validation • Design and productionize scalable triage and prioritization automation, including scanner integrations, enrichment pipelines, deduplication, and observability • Develop risk-based prioritization models combining CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, and compliance obligations • Engineer vulnerability workflows across application security, cloud/infrastructure, containers/Kubernetes, open-source dependencies, secrets, software supply chain, and hardware surfaces (GPU, DPU, BMC, firmware) • Own software supply chain capabilities including SBOM inventory, dependency visibility, SLSA-aligned controls, and CI/CD integration of SAST, SCA, secret scanning, and container scanning • Serve as senior technical responder for critical vulnerabilities, embargoed disclosures, and zero-day events • Partner with development and platform teams to define remediation paths and contribute secure code in Python, Go, JavaScript/TypeScript, or infrastructure code • Define technical standards for severity, remediation SLAs, exceptions, and closure criteria with audit-ready reporting • Produce actionable metrics, dashboards, and risk insights for technical and executive audiences • Lead root-cause analysis for high-impact incidents and drive durable improvements • Evaluate and apply AI/ML and LLM-assisted techniques to security triage with human-in-the-loop validation • Build AI-assisted remediation workflows that partner with engineering teams on proactive patch identification and deployment • Communicate complex security tradeoffs to stakeholders across Engineering, Product, Operations, Legal, Compliance, and leadership You will mentor engineers and work cross-functionally with Engineering, Infrastructure, SRE, Compliance, Legal, and business stakeholders to accelerate remediation while protecting engineering velocity and customer trust.

Similar roles