About the company
Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals.
Responsibilities
- Drive the strategic program management of high-priority cybersecurity initiatives, providing governance and roadmap planning for critical security domains.
- Own and mature the technical program strategy for SoFi’s vulnerability management program.
- Partner closely with Threat and Vulnerability Management, Product Security, Engineering, Infrastructure, Enterprise Technology, Risk, Compliance, and business-unit stakeholders.
- Build scalable operating rhythms for vulnerability intake, triage, prioritization, remediation tracking, escalation, exception handling, and executive reporting.
- Improve risk-based vulnerability prioritization by incorporating severity, exploitability, asset criticality, exposure, business context, and remediation feasibility.
- Drive cross-functional remediation campaigns that reduce risk, improve mean time to remediate, and create clear accountability.
- Define, track, and communicate program KPIs, KRIs, and operational health metrics.
- Establish durable governance and reporting mechanisms.
- Identify process gaps, tooling gaps, and workflow friction.
- Influence technical decisions without direct authority.
- Proactively identify opportunities for operational improvement.
Requirements
- 8+ years of experience in technical program management, security program management, security operations, product security, application security, infrastructure security, DevSecOps, or related discipline.
- Demonstrated ownership of vulnerability management, product security, application security, cloud security, infrastructure security, or similar cybersecurity programs.
- Experience driving large-scale, cross-functional programs across Security, Engineering, Product, Infrastructure, IT, Risk, Compliance, and senior leadership.
- Strong understanding of vulnerability management lifecycle concepts.
- Ability to translate ambiguous security objectives into structured roadmaps.
- Experience using data, KPIs, dashboards, and stakeholder reporting.
- Strong technical fluency with modern software, cloud, infrastructure, endpoint, container, API, and/or application security environments.