SlipstreamJobsFresh Startup & VC-Backed Jobs

Vulnerability Management Engineer

SoFi - San Francisco, CA, United States - In-office - posted 2026-09-04

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

SoFi is a next-generation financial services company and national bank using mobile-first technology to serve millions of members. As a Vulnerability Management Engineer, you will support the identification, assessment, prioritization, and remediation of vulnerabilities across applications and infrastructure. Working under the guidance of senior team members, you will assist in understanding how vulnerable dependencies enter applications, identify remediation options, and engage with engineering teams to track fixes. You will perform regular vulnerability assessments using industry-standard tools, assess discovered vulnerabilities and prioritize their scope and impact, and conduct security reviews of products and production infrastructure. You'll contribute to vulnerability management, application security, and potentially offensive/red-team operations. Your responsibilities include engaging in security audit and regulatory exercises with partners and vendors, supporting regulatory compliance monitoring and reporting, and working with system owners on treatment and remediation activities. You will also develop processes and document procedures to enhance team efficiencies and support the maintenance of internal vulnerability-management tools such as scripts, documentation, and reporting. The ideal candidate has a desire to grow their AppSec expertise, is eager to learn about modern security tooling and automation, and is comfortable using AI tools to assist with documentation, investigation, and scripting tasks while following company security requirements. Required qualifications include a Bachelor's degree in Computer Science, Information Systems, or equivalent work experience; strong knowledge of industry standards (CVE, CVSS, OWASP); experience with vulnerability assessment tools (DAST/SAST); outstanding communication skills; hands-on experience with at least one coding language (Bash, Go, Python, Java); and deep application security knowledge. Preferred qualifications include 2+ years in IT/security roles, 2+ years with cloud technologies, AWS and at-scale services experience, familiarity with microservice architecture, and knowledge of CI/CD tools.

Similar roles