Principal Fraud Strategist, Authentication and Device Trust
TX - Frisco·Posted today
cybersecuritypython
<div class="content-intro"><p><a href="https://www.sofi.com/sofi-employee-applicant-privacy-notice/" target="_blank"><strong>Employee Applicant Privacy Notice</strong></a></p> <p><strong>Who we are:</strong></p> <div> <p>Shape a brighter financial future with us.</p> <p>Together with our members, we’re changing the way people think about and interact with personal finance.</p> <p>We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. <strong>Join us to invest in yourself, your career, and the financial world.</strong></p> </div></div><p></p> <p>The role</p> <p>We are searching for a Principal Fraud Strategist to own SoFi’s authentication and device trust discipline end to end. This is a sophisticated, platform-level role at the intersection of adversarial threat intelligence, device intelligence, and risk decisioning architecture. You will design the layered defense that protects every member session at SoFi: login, password reset, MFA, step-up, account recovery, and high-risk transaction moments across web and mobile. You will own device trust outright: identification, recognition, intelligence, entity resolution, and the signal development work that keeps SoFi ahead of ATO, scam, and perimeter attack patterns as they evolve. The role spans strategy, orchestration, and vendor stack design (Transmit Security Mosaic and beyond), and scales across Money, Invest, Crypto, Card, and Lending. You will work cross-functionally with EPD, IAM, Fraud Ops, InfoSec, Product, and Data Science, and influence vendor roadmaps where SoFi’s needs run ahead of what the market ships.</p> <p>By joining SoFi, you'll become part of a forward-thinking company that is transforming financial services for the better. We offer the excitement of a rapidly growing startup with the stability of an industry leading leadership team.</p> <p>What you’ll do:</p> <p>The Principal Fraud Strategist, Authentication and Device Trust will help SoFi build and continuously evolve a layered authentication and device trust defense by:</p> <ul> <li> <p>Owning end-to-end strategy for authentication and device trust across web and mobile: signal architecture, decisioning topology, rule construction, threshold tuning, champion/challenger lifecycle, and rule-level loss and false-positive attribution.</p> </li> <li> <p>Architecting the layered perimeter defense against ATO, scam interception (authorized push payment, remote access, impostor, investment, business email compromise), credential stuffing, MFA bombing, OTP interception, SIM swap, adversary-in-the-middle phishing, and emulator-driven bot traffic. Convert live campaign telemetry into policy changes at the speed of the attack.</p> </li> <li> <p>Owning the device trust discipline: device identification, recognition, and intelligence across web and mobile; behavioral biometrics; network reputation; device-graph and entity resolution; emulator and VM detection; jailbreak and root signals; residential-proxy detection; and signal development for gaps the current vendor stack does not cover.</p> </li> <li> <p>Orchestrating the vendor stack that underpins authentication and device trust (Transmit Security Mosaic and adjacent providers): capability assessment, integration design, data flow architecture, decision timing, and continuous performance tuning. Influence vendor roadmaps where SoFi has needs the market has not yet met.</p> </li> <li> <p>Designing step-up authentication, account recovery, and high-risk transaction decisioning that synthesizes device, behavioral, network, and credential-risk signals into a single decision with explicit FPR budgets per surface. Keep controls invisible to legitimate members wherever possible.</p> </li> <li> <p>Leading 3DS, CNP, and tokenization decisioning for card-not-present transactions, coordinating with issuer processing and network rules to optimize approval rate without ceding losses.</p> </li> <li> <p>Partnering with InfoSec threat intelligence on credential-capture campaigns, phishing kits, SEO poisoning, and ATO-as-a-service marketplaces. Translate intelligence into rule changes inside the live policy stack and into new signal development priorities.</p> </li> <li> <p>Setting the technical bar for how SoFi builds durable fraud defense. Mentor the broader fraud strategy organization on authentication, device intelligence, and adversarial reasoning.</p> </li> </ul> <p>What you’ll need:</p> <ul> <li> <p>BA/BS in Statistics, Information Systems, Mathematics, Data Science, Computer Science, or related fields, or equivalent work experience, and 15+ years of work experience in Fraud Strategy, Authentication Risk, Device Intelligence, or Adversarial Security Engineering.</p> </li> <li> <p>ATO and Scam Defense: Deep track record reducing account takeover and scam losses across banking, card, crypto, and P2P surfaces. Fluency across the full kill chain: credential exposure, login compromise, in-session manipulation (remote access, screen share, social engineering), and money movement out.</p> </li> <li> <p>Perimeter Threat Fluency: Operational understanding of credential stuffing, MFA bombing, OTP interception, SIM swap, adversary-in-the-middle phishing, residential-proxy abuse, and emulator-driven automation. You have recognized campaigns in flight from telemetry and responded at the policy layer, more than once.</p> </li> <li> <p>Device Intelligence and Forensics: Hands-on architectural experience with device identification, recognition, and intelligence platforms. Fluency in device fingerprinting, emulator and VM detection, jailbreak and root signals, behavioral biometrics, and entity-level device-graph analysis. Direct experience with Transmit Security Mosaic, Iovation, ThreatMetrix, BioCatch, or comparable platforms as a builder, not just a consumer.</p> </li> <li> <p>Signal Development: Proven ability to identify signal gaps in production systems and develop new signals, either directly or in partnership with vendors, that close them. You do not wait for a vendor to invent the detection you need.</p> </li> <li> <p>Risk Architecture and Vendor Orchestration: Track record designing holistic fraud systems across multiple vendors, data feeds, and decisioning layers, with clear ownership of decision timing, feedback loops, metrics, and incident response paths.</p> </li> <li> <p>Authentication Stack Depth: Working knowledge of FIDO2/passkeys, OAuth/OIDC, 3DS protocol mechanics, tokenization, and the trade-offs between approval rate and chargeback exposure on CNP flows.</p> </li> <li> <p>Balance Friction and Growth: Deep mastery of evaluating trade-offs between fraud mitigation and UX. Keeps controls invisible to legitimate members wherever possible and spends friction judiciously where it delivers the greatest incremental protection.</p> </li> <li> <p>Architect Scalable Data Systems: Expert-level SQL/Python skills used to build automated, high-volume data architectures and statistical models that serve as the foundation for global risk detection.</p> </li> <li> <p>Drive Strategic Influence: A proactive leader who uses cross-functional persuasion to align EPD, IAM, InfoSec, Fraud Ops, and vendor partners on strategy changes, and owns end-to-end execution in fluid environments.</p> </li> <li> <p>Founders’ Mentality: You need to have a positive, proactive attitude, being able to identify problems, raise proposals, and be an advocate of your initiatives. Learn, iterate, and excel.</p> </li> </ul> <p></p><div class="content-conclusion"><div class="gmail_default"><strong>Compensation and Benefits</strong></div> <div class="gmail_default">The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location. </div> <div class="gmail_default"> </div> <div class="gmail_default">To view all of our comprehensive and competitive benefits, visit our <strong><a href="https://sofietyinfo.sofi.com/sofi-benefits" target="_blank" data-saferedirecturl="https://www.google.com/url?q=https://sofietyinfo.sofi.com/sofi-benefits&source=gmail&ust=1667318410571000&usg=AOvVaw0ZqbRtznVe1JsWWUOWQUnN">Benefits at SoFi</a> </strong>page!</div> <h5 style="text-align: center;"><span style="font-weight: 400;">SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.</span></h5> <h5 style="text-align: center;"><span style="font-weight: 400;">The Company hires the best qualified candidate for the job, without regard to protected characteristics.</span></h5> <h5 style="text-align: center;"><span style="font-weight: 400;">Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.</span></h5> <h5 style="text-align: center;"><a href="https://dol.ny.gov/system/files/documents/2022/02/ls740_1.pdf" target="_blank"><span style="font-weight: 400;">New York applicants: Notice of Employee Rights</span></a></h5> <h5 style="text-align: center;"><span style="font-weight: 400;">SoFi is committed to an inclusive culture. As part of this commitment, </span><span style="font-weight: 400;">SoFi </span><span style="font-weight: 400;">offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email </span><a href="mailto:accommodations@sofi.com" target="_blank">accommodations@sofi.com.</a></h5> <h5 style="text-align: center;"><span style="font-weight: 400;">Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.</span></h5> <div class="gmail_default"><strong>Internal Employees</strong></div> <div class="gmail_default">If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.</div></div>