Vulnerability Management Engineer

SoFi

Confirmed live 2 days ago High trust

Quick summary

Work type
On-site
Location
San Francisco, CA
Salary
$99,200–$186,000 / yr
Posted
7 days ago
Freshness
Confirmed live 2 days ago

Market check

Salary context

Below market

How this pay compares to similar roles

Similar $182k
This role $143k
$84k most similar roles pay here $240k

This role pays less than 79% of similar roles. Most pay $149,874–$214,800 — the shaded band above. At the midpoint, this role pays about $143k versus about $182k for comparable roles.

Based on 240 similar postings.

Employer

About SoFi

SoFi Technologies is a fintech company offering student and personal loans, mortgages, credit cards, investing, banking, and insurance products, positioning itself as a one-stop financial services platform. Industry: Financial Technology & Personal Finance

SoFi currently has 17 open roles on FindRole.

Listed pay typically runs $156,800–$247,500 across 17 roles with salary data.

Most-posted roles

View all roles at SoFi

At a glance

TL;DR · Vulnerability Management Engineer

As a Vulnerability Management Engineer, you will join the security team to support the identification, assessment, prioritization, and remediation of vulnerabilities across applications and infrastructure. You will perform regular assessments using various tools, conduct security reviews of products and production environments, and engage with engineering teams to track fixes for identified issues. Your daily work involves maintaining internal management tools, developing procedures, and participating in security audits and regulatory compliance monitoring. The role requires expertise in CVE, CVSS, OWASP, and Secure Software Development Life Cycles. You will utilize DAST/SAST tools, coding languages such as Bash, Go, Python, or Java, and AI tools like Claude for documentation and scripting. This position addresses the critical challenge of securing financial services infrastructure through proactive vulnerability management and risk-based remediation in a micro-service architecture.

What you'll do

  • Perform regular vulnerability assessments using various tools across applications and infrastructure.
  • Prioritize vulnerabilities based on scope, impact, and necessary response actions.
  • Conduct security reviews of products and production infrastructure.
  • Engage with engineering teams and system owners to track and execute remediation activities.
  • Support regulatory compliance monitoring and participate in security audit exercises.
  • Maintain internal vulnerability management tools, including scripts, documentation, and reporting.
  • Develop processes and document procedures to improve team efficiency.

What we're looking for

  • Bachelor's Degree in Computer Science, Information Systems, or equivalent work-related experience.
  • Strong knowledge of industry standards including CVE, CVSS, and OWASP.
  • Experience with vulnerability assessment tools and DAST/SAST tools.
  • Deep application security knowledge to map vulnerabilities to exploitation indications and investigative techniques.
  • Hands-on experience with at least one coding language such as Bash, Go, Python, or Java.
  • Experience with Secure Software Development Life Cycles (SDLC).
  • 2+ years of experience in an information technology or security role.
  • 2+ years of experience with cloud technologies and familiarity with AWS.

More like this

Similar roles

Senior Vulnerability Management Engineer

SoFi

Seattle, WA +1 7 days ago $124,800$234,000
Vulnerability Management Kubernetes Python Go Java Bash SCA SAST DAST CI/CD Qualys Helm Maven Gradle Webhooks OWASP CVE CVSS CWE
4+ yrs exp

Staff Vulnerability Management Engineer

SoFi

Seattle, WA +1 43 days ago $144,000$247,500
Vulnerability Management Python Go JavaScript TypeScript Java Kubernetes AWS GCP Azure CI/CD Infrastructure as Code SAST SCA SBOM Tines Wiz Semgrep Snyk Rapid7 Tenable Checkmarx CVSS EPSS CISA KEV AI/ML

Lead Vulnerability Management Engineer

Cloudflare, Inc

Austin, TX 23 days ago
Vulnerability Management AI Python Qualys Nessus Rapid7 InsightVM JIRA CVSS EPSS SOC-2 PCI-DSS FedRAMP NIST ISO 27001 Infrastructure Pentesting Systems Design
5+ yrs exp Hybrid

Senior Systems Engineer, Vulnerability Management

Neurocrine

Remote (San Diego, CA) 8 days ago $103,300$141,000
AWS Azure Linux Windows Python Bash PowerShell Ansible SSM) Patch Manager WSUS SCCM Intune Configuration Management ITIL ServiceNow GxP SOX Vulnerability Management Patch Management
4+ yrs exp Remote

Lead InfoSec Engineer, Vulnerability Management

S&P Global

New York, NY 53 days ago $125,000$145,000
Vulnerability Management SAST DAST Qualys Tanium Rapid7 Fortify Checkmarx Veracode Power BI Tableau NIST Cybersecurity Framework ISO 27001 CVE CVSS CWE AI/ML Risk Management
7+ yrs exp