Offensive Security Lead

SoFi

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
San Francisco, CASeattle, WANew York, NYCottonwood Heights, UTFrisco, TXHelena, MT
Salary
$172,800–$297,000 / yr
Posted
8 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Above market

How this pay compares to similar roles

Similar $183k
This role $235k
$115k most similar roles pay here $317k

This role pays more than 85% of similar roles. Most pay $151,700–$214,500 — the shaded band above. At the midpoint, this role pays about $235k versus about $183k for comparable roles.

Based on 240 similar postings.

Employer

About SoFi

SoFi Technologies is a fintech company offering student and personal loans, mortgages, credit cards, investing, banking, and insurance products, positioning itself as a one-stop financial services platform. Industry: Financial Technology & Personal Finance

SoFi currently has 17 open roles on FindRole.

Listed pay typically runs $156,800–$247,500 across 17 roles with salary data.

Most-posted roles

View all roles at SoFi

At a glance

TL;DR · Offensive Security Lead

The Offensive Security Lead joins the Cyber Defense organization to mature and grow the Penetration Testing and Red Team functions into a single, cohesive unit. This hands-on leadership role involves developing the offensive security roadmap, managing team growth, and overseeing program metrics while personally contributing to network, application, cloud, and AI pentests. A primary focus is building and scaling AI-assisted capabilities for reconnaissance, exploit development, and report generation. The ideal candidate possesses over eight years of experience in offensive security and at least two years of leadership within regulated industries like financial services. Required skills include technical fluency in AWS, GCP, Azure, and MITRE ATT&CK frameworks, alongside expertise in C2 tooling. This role addresses the challenge of maintaining high-quality security testing for a complex banking platform while scaling operations through automated tools and innovative workflows.

What you'll do

  • Unify Penetration Testing and Red Team into a single, cohesive Offensive Security function with shared standards and tradecraft.
  • Develop and execute an offensive security roadmap aligned with the company's risk profile and regulatory obligations.
  • Design and implement AI-augmented tools and workflows to accelerate reconnaissance, exploit development, and report generation.
  • Lead and contribute to technical engagements including network, application, cloud, and adversary emulation operations.
  • Hire, coach, and mentor a team of penetration testers and red team operators while establishing clear career paths.
  • Define and report program metrics regarding coverage, finding severity, remediation velocity, and overall ROI to leadership.
  • Collaborate with internal teams like SOC and Engineering to ensure offensive findings result in actionable remediations.
  • Manage third-party vendors for pentesting tools and execution while overseeing budget and quality.

What we're looking for

  • Must have 8+ years of experience in offensive security including both penetration testing and red team/adversary emulation.
  • Must have 2+ years of experience directly managing or leading offensive security teams, preferably in a regulated industry.
  • Must have proven experience designing and implementing AI-led or AI-assisted offensive security programs.
  • Must possess deep technical fluency across network, web, application, cloud (AWS/GCP/Azure), and mobile attack surfaces.
  • Must have a track record of building or maturing offensive security programs including process, tooling, metrics, and team structure.
  • Must possess strong written and verbal communication skills to present findings and strategy to executives and risk teams.
  • Experience operating in highly regulated environments and working with auditors is preferred.
  • Relevant certifications such as OSCP, OSCE, OSEP, GPEN, GXPN, or CRTO are preferred but not required.

More like this

Similar roles

Senior Security Engineer, Offensive Security

Datadog

90 days ago $195,000$240,000
Red Teaming Offensive Security Python Go AWS GCP Azure Kubernetes CI/CD Automation EDR SIEM Linux macOS Vulnerability Analysis Security Engineering
5+ yrs exp Hybrid

Staff Engineer, Offensive Security

Twilio

Remote 65 days ago $155,520$194,400
Penetration Testing Offensive Security Python Bash C++ Burp Suite Nmap Metasploit Wireshark Cobalt Strike Sliver Havoc AWS Azure LangChain TensorFlow PyRIT Promptfoo Garak OWASP Top 10 MITRE ATT&CK Red Teaming SIEM
7+ yrs exp Remote

Senior Offensive Security Engineer, Vulnerability Operations

Nvidia

Remote (Austin, TX) +1 9 days ago $224,000$356,500
LLM Python Red Teaming Penetration Testing Kubernetes Exploit Development Vulnerability Research SAST DAST Fuzzing GitOps OpenShift prompt-injection defense Multi-agent Orchestration Offensive Security
10+ yrs exp Remote

Engineering Manager, Red Team

DoorDash, Inc

Remote 143 days ago $193,800$285,000
Red Teaming Adversary Simulation Penetration Testing TTPs AWS GCP Kubernetes CI/CD C2 Infrastructure Threat Intelligence AppSec DFIR OSCP OSCE GXPN CRTO CRTL
7+ yrs exp Remote

Lead Penetration Test Engineer

S&P Global

Boston, MA +11 22 days ago $135,000$200,000
Penetration Testing Vulnerability Management DAST SAST SCA CI/CD Burp Suite Nessus Metasploit Nmap OWASP Top 10 MITRE ATT&CK Python Go Bash PowerShell JavaScript AWS Azure GCP Java
8+ yrs exp Hybrid