Senior Vulnerability Management Engineer

SoFi

Confirmed live yesterday High trust

Quick summary

Work type
On-site
Location
Seattle, WASan Francisco, CA
Salary
$124,800–$234,000 / yr
Posted
7 days ago
Freshness
Confirmed live yesterday

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $186k
This role $179k
$112k most similar roles pay here $247k

This role pays less than 53% of similar roles. Most pay $156,312–$216,062 — the shaded band above. At the midpoint, this role pays about $179k versus about $186k for comparable roles.

Based on 240 similar postings.

Employer

About SoFi

SoFi Technologies is a fintech company offering student and personal loans, mortgages, credit cards, investing, banking, and insurance products, positioning itself as a one-stop financial services platform. Industry: Financial Technology & Personal Finance

SoFi currently has 17 open roles on FindRole.

Listed pay typically runs $156,800–$247,500 across 17 roles with salary data.

Most-posted roles

View all roles at SoFi

At a glance

TL;DR · Senior Vulnerability Management Engineer

As a Senior Vulnerability Management Engineer, you will independently identify, assess, and prioritize vulnerabilities across applications, infrastructure, containers, Kubernetes environments, and third-party dependencies. You will investigate how vulnerable dependencies enter systems, determine if they are direct or transitive, and partner with engineering teams to implement validated fixes. Your daily responsibilities include maintaining source-code repositories for internal tools, integrating security platforms via APIs and webhooks, and developing dashboards to communicate risk and remediation progress. The role requires proficiency in Python, Java, Go, or Bash, along with experience using Qualys, SAST, DAST, and SCA tools. You will navigate complex technical landscapes involving Helm, CI/CD pipelines, and Maven or Gradle systems. This position focuses on solving security risks within a regulated financial services environment by managing the full lifecycle of vulnerability remediation and automation.

What you'll do

  • Perform vulnerability assessments across applications, operating systems, containers, Kubernetes clusters, and third-party dependencies.
  • Investigate vulnerable dependencies to determine their origin and identify whether they are direct or transitive.
  • Recommend safe remediation options including dependency upgrades, configuration changes, patches, or compensating controls.
  • Maintain source-code repositories for internal vulnerability-management tools and reporting applications.
  • Integrate security tools with ticketing systems, dashboards, and reporting platforms using APIs and webhooks.
  • Utilize AI-assisted development tools to accelerate coding, debugging, research, and documentation tasks.
  • Identify and filter out false positives, duplicate findings, and incorrect asset associations.
  • Develop dashboards and reports to communicate risk levels, remediation progress, and program effectiveness.

What we're looking for

  • Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or equivalent practical experience.
  • 4+ years of experience in information security, vulnerability management, application security, security engineering, or a related discipline.
  • Strong understanding of CVE, CVSS, CWE, CISA KEV, EPSS, OWASP, and risk-based vulnerability prioritization.
  • Experience investigating vulnerable dependencies using build files, dependency trees, lock files, container images, and SCA tools.
  • Hands-on experience operating vulnerability-management platforms like Qualys or similar tools.
  • Experience with SAST, DAST, SCA, container security, or infrastructure vulnerability-scanning tools.
  • Proficiency in at least one programming or scripting language such as Python, Java, Go, or Bash.
  • Familiarity with containers, Kubernetes workloads, Helm, CI/CD pipelines, and configuration management.

More like this

Similar roles

Vulnerability Management Engineer

SoFi

San Francisco, CA 7 days ago $99,200$186,000
Vulnerability Management AppSec SAST DAST AWS Python Go Bash Java CI/CD OWASP CVE CVSS Agile

Staff Vulnerability Management Engineer

SoFi

Seattle, WA +1 43 days ago $144,000$247,500
Vulnerability Management Python Go JavaScript TypeScript Java Kubernetes AWS GCP Azure CI/CD Infrastructure as Code SAST SCA SBOM Tines Wiz Semgrep Snyk Rapid7 Tenable Checkmarx CVSS EPSS CISA KEV AI/ML

Lead InfoSec Engineer, Vulnerability Management

S&P Global

New York, NY 53 days ago $125,000$145,000
Vulnerability Management SAST DAST Qualys Tanium Rapid7 Fortify Checkmarx Veracode Power BI Tableau NIST Cybersecurity Framework ISO 27001 CVE CVSS CWE AI/ML Risk Management
7+ yrs exp

Lead Vulnerability Management Engineer

Cloudflare, Inc

Austin, TX 23 days ago
Vulnerability Management AI Python Qualys Nessus Rapid7 InsightVM JIRA CVSS EPSS SOC-2 PCI-DSS FedRAMP NIST ISO 27001 Infrastructure Pentesting Systems Design
5+ yrs exp Hybrid

Senior Systems Engineer, Vulnerability Management

Neurocrine

Remote (San Diego, CA) 8 days ago $103,300$141,000
AWS Azure Linux Windows Python Bash PowerShell Ansible SSM) Patch Manager WSUS SCCM Intune Configuration Management ITIL ServiceNow GxP SOX Vulnerability Management Patch Management
4+ yrs exp Remote