Staff Vulnerability Management Engineer

SoFi

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
Seattle, WASan Francisco, CA
Salary
$144,000–$247,500 / yr
Posted
43 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Competitive pay

How this pay compares to similar roles

Similar $192k
This role $196k
$130k most similar roles pay here $260k

This role pays more than 55% of similar roles. Most pay $162,000–$222,000 — the shaded band above. At the midpoint, this role pays about $196k versus about $192k for comparable roles.

Based on 240 similar postings.

Employer

About SoFi

SoFi Technologies is a fintech company offering student and personal loans, mortgages, credit cards, investing, banking, and insurance products, positioning itself as a one-stop financial services platform. Industry: Financial Technology & Personal Finance

SoFi currently has 17 open roles on FindRole.

Listed pay typically runs $156,800–$247,500 across 17 roles with salary data.

Most-posted roles

View all roles at SoFi

At a glance

TL;DR · Staff Vulnerability Management Engineer

As a Staff Vulnerability Management Engineer, you will lead complex technical initiatives within the Vulnerability Management program to protect infrastructure and software supply chains. You will design and build scalable systems to identify, prioritize, and track vulnerabilities across cloud environments, containers, and hardware surfaces like GPU and firmware. Day-to-day responsibilities include developing risk-based prioritization models, automating triage workflows, and serving as a senior technical responder for zero-day events. You will write production code in Python, Go, or JavaScript/TypeScript to integrate tools such as Wiz, Semgrep, Snyk, and Rapid7 into CI/CD pipelines. The role requires deep expertise in CVSS, EPSS, and CISA KEV metrics while managing security risks across Kubernetes and cloud-native platforms. You will also evaluate AI/ML techniques for triage and collaborate with cross-functional teams to ensure audit-ready compliance and remediation.

What you'll do

  • Design and build scalable systems to identify, prioritize, and track vulnerabilities across cloud, infrastructure, and software supply chains.
  • Develop risk-based prioritization models using threat intelligence, asset criticality, and compliance requirements.
  • Automate triage workflows including scanner integrations, enrichment pipelines, and ownership resolution.
  • Act as a senior technical responder for zero-day events and high-impact vulnerability incidents.
  • Build and manage software supply chain capabilities including SBOM inventory and CI/CD security integrations.
  • Create automated remediation workflows using AI/ML techniques to identify and apply security patches.
  • Define technical standards for vulnerability severity, remediation service levels, and audit-ready reporting.
  • Produce actionable metrics and risk insights for both technical teams and executive leadership.

What we're looking for

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or a related field, or equivalent practical experience.
  • Deep expertise in vulnerability management, security engineering, and modern infrastructure including cloud, containers, and distributed systems.
  • Strong programming skills in Python, Go, Java, or similar languages to build automation at scale.
  • Extensive knowledge of vulnerability standards such as CVSS, EPSS, CISA KEV, and risk-based prioritization models.
  • Hands-on experience with security tools like Wiz, Semgrep, Snyk, Socket, Rapid7, Tenable, or Checkmarx.
  • Experience designing end-to-end workflows integrating scanners, asset inventories, ticketing systems, and CI/CD platforms.
  • Working knowledge of cloud-native environments (AWS, GCP, or Azure), Kubernetes, SBOMs, and Infrastructure as Code.
  • Demonstrated ability to lead cross-functional initiatives, mentor engineers, and communicate complex security risks to stakeholders.

More like this

Similar roles

Senior Vulnerability Management Engineer

SoFi

Seattle, WA +1 7 days ago $124,800$234,000
Vulnerability Management Kubernetes Python Go Java Bash SCA SAST DAST CI/CD Qualys Helm Maven Gradle Webhooks OWASP CVE CVSS CWE
4+ yrs exp

Vulnerability Management Engineer

SoFi

San Francisco, CA 7 days ago $99,200$186,000
Vulnerability Management AppSec SAST DAST AWS Python Go Bash Java CI/CD OWASP CVE CVSS Agile

Lead Vulnerability Management Engineer

Cloudflare, Inc

Austin, TX 23 days ago
Vulnerability Management AI Python Qualys Nessus Rapid7 InsightVM JIRA CVSS EPSS SOC-2 PCI-DSS FedRAMP NIST ISO 27001 Infrastructure Pentesting Systems Design
5+ yrs exp Hybrid

Staff Security Engineer, Vulnerability Management

GEICO

Remote (Seattle, WA) +3 85 days ago $110,000$230,000
Vulnerability Management Security Engineering Python Go Java SQL CI/CD DevSecOps SIEM SOAR Containers Distributed Systems Threat Modeling Offensive Security PCI NYDFS
8+ yrs exp Remote

Senior Systems Engineer, Vulnerability Management

Neurocrine

Remote (San Diego, CA) 8 days ago $103,300$141,000
AWS Azure Linux Windows Python Bash PowerShell Ansible SSM) Patch Manager WSUS SCCM Intune Configuration Management ITIL ServiceNow GxP SOX Vulnerability Management Patch Management
4+ yrs exp Remote