SoFi Logo

SoFi

Senior Product Security Engineer

Reposted 12 Days Ago
Easy Apply
Remote or Hybrid
2 Locations
Senior level
Easy Apply
Remote or Hybrid
2 Locations
Senior level
The Senior Product Security Engineer collaborates with engineering to secure products, implements security tools, manages cloud security, and participates in security evaluations and automation for compliance.
The summary above was generated by AI

Employee Applicant Privacy Notice

Who we are:

Shape a brighter financial future with us.

Together with our members, we’re changing the way people think about and interact with personal finance.

We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.

About The Role

The SoFi Product Security team assists and partners with engineering, product, and design organizations. Our mission is to secure the products and services delivered to our members and customers. We deploy best-in-class Product Security practices, compliance frameworks, and design patterns by collaborating with product owners, engineers, and executives. The mission is core to SoFi’s value “Put our member’s interest first.”

As a product security engineer, you will be responsible for the end-to-end tooling of our software security stack, supporting the development of SoFi’s platforms, products, and services. You will work in conjunction with Application security engineers, development, and product teams to bake security controls into the software development lifecycle. This role is pivotal to building security with agility and helping SoFi scale. 

The ideal candidate will be highly collaborative, balancing the right level of security with business objectives, and working to creatively solve complex Product Security related problems in an agile environment. 

What you’ll do:

  • Deploy product security tools like SAST, DAST, IAST, SCA, etc to help uncover security issues early in the software development lifecycle.
  • Build secure integrations following the SDLC process with various internal and external tools to create agile software security solutions.
  • Keep security tools and deployments up to date. Ensure regular patching and upgrades and smooth running of tools.
  • Help review development lifecycle integration with security tools and triage / debug any integration issues.
  • Manage cloud security and WAF solutions to ensure SoFi’s infrastructure is secure.
  • Participate in proof of concept to evaluate security solutions and services to help strengthen SoFi’s products against advanced Cybersecurity attacks.
  • Work closely with security operations and application security engineers to review security gaps and develop mitigation strategies.
  • Help with automation to support compliance with various regulatory and industry standards requirements.

What you’ll need:

  • Proficiency with programming languages, automation tooling, and API integrations
  • Demonstrate deep understanding of Docker, Kubernetes, and CI/CD pipelines
  • Good understanding of cloud services, AWS, and Well-Architected Framework security pillar
  • Proficiency in managing services using Infrastructure as Code (IaC) such as Terraform and Helm/Kustomize/ArgoCD
  • Knowledge of network and web-related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, DNS, routing protocols)
  • Service Mesh/Istio, microsegmentation, and network security
  • Ability to prioritize between and execute on multiple work streams
  • Written and verbal skills for communicating security concepts and solutions
  • Secure software development lifecycle / “Shift Left”

Preferred Qualifications:

  • Bachelor's degree in Computer Science or equivalent from a fully accredited college or university
  • 4+ years experience in DevOps and Cloud/Infrastructure engineering
  • Experience with cloud-native products and an in-depth understanding of microservice topologies and implementations
  • 4+ years of experience with cloud technologies
  • Ability to manage relationships with other business units, external vendors, and stakeholders when IT security risks are present and system or process changes must be made to mitigate risk
  • Familiarity with AWS and at-scale services
  • Knowledge of CI/CD, application development, and testing tools
  • Ability to work in a fast-paced and Agile development environment
  • Work and play well with others; SoFi is a collaborative environment

Nice to have:

  • AWS Certified Security / Solution Architect
  • Any CNCF Cloud Native Certifications
  • Masters or PhD in Computer Science or Engineering
  • Financial services experience
Compensation and Benefits
The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location. 
 
To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!
SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.The Company hires the best qualified candidate for the job, without regard to protected characteristics.Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.New York applicants: Notice of Employee RightsSoFi is committed to embracing diversity. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email [email protected].Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.
Internal Employees
If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.

Top Skills

Argocd
AWS
Ci/Cd
Docker
Helm
Kubernetes
Kustomize
Terraform

Similar Jobs at SoFi

23 Hours Ago
Easy Apply
Remote or Hybrid
4 Locations
Easy Apply
Senior level
Senior level
Fintech • Mobile • Software • Financial Services
The Senior Credit Risk Manager will develop credit strategies, analyze data, collaborate with various teams, and innovate risk management for credit card acquisition.
Top Skills: ExcelPythonSQLTableau
Yesterday
Easy Apply
Remote or Hybrid
United States
Easy Apply
Senior level
Senior level
Fintech • Mobile • Software • Financial Services
The Compliance Specialist will oversee marketing compliance, ensuring adherence to regulations, supporting various departments, and managing compliance documentation and audits.
Top Skills: Google SuiteWorkfront
4 Days Ago
Easy Apply
Remote or Hybrid
2 Locations
Easy Apply
Senior level
Senior level
Fintech • Mobile • Software • Financial Services
The role requires analyzing data to develop credit risk strategies for lending products, focusing initially on personal loans, and ensuring alignment with the company's risk and growth objectives.
Top Skills: ExcelPythonSQL

What you need to know about the Sydney Tech Scene

From opera to comedy shows, the Sydney Opera House hosts more than 1,600 performances a year, yet its entertainment sector isn't the only one taking center stage. The city's tech sector has earned a reputation as one of the fastest-growing in the region. More specifically, its IT sector stands out as the country's third-largest, growing at twice the rate of overall employment in the past decade as businesses continue to digitize their operations to stay competitive.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account