or apply directly on SoFi's site. We never take the application ourselves.
Is this posting real?
- This role has been open
- 12 days SoFi's roles stay open a median of 33 days
- Reposted
- No
- Salary listed
- No 7% of SoFi's roles list one
- Ghost-job risk at SoFi
- high 23 stale, 5 reposted of 61 open
- Hiring momentum
- 122 roles opened in the last 90 days ↑ up vs. the prior 90 days
- Last confirmed on the employer's board
- 2026-09-17
Measured from postings appearing on and disappearing from SoFi's own greenhouse board since 2026-08-03. Full hiring picture for SoFi.
About this role
As a Senior Vulnerability Management Engineer, you will identify, assess, and prioritize vulnerabilities across various environments, including applications and infrastructure. You will drive remediation efforts, enhance internal vulnerability management tools, and collaborate with engineering teams to implement fixes. The role also involves using AI tools to support development and security automation, as well as developing dashboards and reports to communicate vulnerability risks and remediation progress.
- benefits
- 1/5
- freshness
- 4/5
- career value
- 4/5
- role clarity
- 5/5
- pay transparency
- 0/5
Scored from the posting itself — how clearly the role is described, how much it says about pay and benefits, and how recently it was listed. Not a judgement of SoFi as an employer.
What you need
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or equivalent practical experience
- 4+ years of experience in information security, vulnerability management, application security, security engineering, or a related discipline
- Strong understanding of CVE, CVSS, CWE, CISA KEV, EPSS, OWASP, and risk-based vulnerability prioritization
- Experience investigating vulnerable dependencies using build files, dependency trees, lock files, container images, and software-composition-analysis tools
- Ability to determine where a vulnerable package originates and recommend a safe, compatible remediation
- Hands-on experience operating vulnerability-management platforms such as Qualys or similar tools
Nice to have
- Experience with cloud platforms and cloud-native services
- Experience with microservice architectures and Kubernetes-based applications
- Experience developing vulnerability-management automation and self-service security tools
- Knowledge of Java dependency-management systems such as Gradle or Maven, including transitive dependency analysis
- Ability to collaborate with engineering, infrastructure, business, compliance, and external vendor teams
Worth weighing
- No specific salary figures provided, only that it will be determined based on experience and location.
- The role involves using AI tools, which may indicate a modern approach to vulnerability management but could also imply reliance on automation.
- The job requires collaboration with multiple teams, which may involve navigating complex organizational dynamics.
Summarised from SoFi's posting. Read the full original.
Listed by SoFi on their greenhouse job board, last confirmed open on 2026-09-17. PitchMeAI is not the employer.
More roles at SoFi
- Branch Operations SupervisorCA - Sacramento
- Staff Data ScientistAdd ALL locations here
- Senior Software Engineering ManagerAdd ALL locations here
- Principal Program Manager, Performance ManagementSan Francisco, CA; Seattle, WA
- Principal Product Manager, Commercial BankingCA - San Francisco; NY - New York City; WA - Seattle
- Senior Manager, SoFi Plus Member AcquisitionUnited States
- Director, People Business Partner (Global Operations)Jacksonville - FL; Cottonwood Heights - UT; New York City - NY
- Senior Operations Surveillance and Support SpecialistUT - Cottonwood Heights