Staff Enterprise Security Engineer

WA - Seattle; CA - San Francisco; UT - Cottonwood Heights; NY - New York City; TX - Frisco·Posted today
cybersecuritysaaspythongoawsterraform
<div class="content-intro"><p><a href="https://www.sofi.com/sofi-employee-applicant-privacy-notice/" target="_blank"><strong>Employee Applicant Privacy Notice</strong></a></p> <p><strong>Who we are:</strong></p> <div> <p>Shape a brighter financial future with us.</p> <p>Together with our members, we’re changing the way people think about and interact with personal finance.</p> <p>We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. <strong>Join us to invest in yourself, your career, and the financial world.</strong></p> </div></div><p><strong>The role</strong></p> <p>As a Staff Enterprise Security Engineer at SoFi, you will serve as the subject matter expert for Data Loss Prevention (DLP) while driving engineering across broader enterprise security domains—including email security, endpoint protection, network defense, and phishing simulation. Sitting within the Enterprise Security team, this role balances technical focus on data protection with hands-on architecture, operation, and automation of foundational IT and corporate security controls.</p> <p>We seek security leaders who combine technical mastery in tool administration (e.g., Zscaler, Proofpoint, Sentra, CrowdStrike) with systems thinking to mitigate risk across diverse threat vectors. In this role, you will define risk mitigation strategies and build clear technical roadmaps—accelerating security delivery while maintaining safety, correctness, and data protection.</p> <p>&nbsp;</p> <p><strong>What you’ll do</strong></p> <ul> <li>Lead end-to-end delivery and architecture for enterprise security capabilities: enterprise zero-trust networks, endpoint security, and SaaS posture management.</li> <li>Frame complex security challenges: clarify security requirements, threat models, failure modes, and success metrics while proposing clear architectural options and tradeoffs.</li> <li>Design for scale and resilience: establish secure baseline configurations, automate security guardrails, and reduce systemic attack surfaces with minimal enterprise friction.</li> <li>Collaborate with internal security teams to establish and maintain threat signaling to ensure that proper visibility and alerting is achieved across tooling.</li> <li>Raise cybersecurity standards through design reviews, active mentorship of team members, and establishing enterprise security patterns and best practices.</li> <li>Collaborate cross-functionally with IT, Infrastructure, Risk/Compliance, and Engineering teams to deliver secure member outcomes.</li> </ul> <p>&nbsp;</p> <p><strong>What you’ll need</strong></p> <ul> <li>Education &amp; Minimum Experience Requirements: Bachelor’s Degree + 3–4 Years of Experience OR Master’s Degree + 2–3 Years of Experience in Cybersecurity, Computer Science, Information Technology, or a related field.</li> <li>3+ years of experience in cybersecurity with a focus on Data Loss Prevention (DLP).</li> <li>Hands-on experience with cloud-based DLP solutions (e.g., Zscaler, Proofpoint, Sentra).</li> <li>Experience administering and operating core enterprise security tools (EDR, email security gateways, and web proxies).</li> <li>Experience with Infrastructure as Code (IaC) solutions such as Terraform, along with scripting languages (Python, Go, or PowerShell) for tooling and automation.</li> <li>Experience with incident response, log analysis, threat detection, and digital forensics.</li> <li>Experience collaborating with multiple lines of defense for issue analysis, evidence gathering and remediation.</li> <li>Proven problem-solving skills with the ability to work independently and collaboratively in a fast-paced environment.</li> <li>Solid written and verbal communication skills for technical documentation, cross-functional collaboration, and threat modeling.</li> </ul> <p>&nbsp;</p> <p><strong>Nice to have</strong></p> <ul> <li>Professional security certifications (e.g., CISSP, CCSP, CISM, or AWS Certified Security Specialty).</li> <li>Experience with CI/CD security pipeline automation, SIEM detections, and SOAR playbooks.</li> <li>Knowledge of financial compliance frameworks and regulatory environments (PCI-DSS, SOC1/SOC2, SOX, GLBA, NIST CSF, ISO 27001).</li> </ul><div class="content-conclusion"><div class="gmail_default"><strong>Compensation and Benefits</strong></div> <div class="gmail_default">The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location.&nbsp;</div> <div class="gmail_default">&nbsp;</div> <div class="gmail_default">To view all of our comprehensive&nbsp;and competitive&nbsp;benefits, visit our&nbsp;<strong><a href="https://sofietyinfo.sofi.com/sofi-benefits" target="_blank" data-saferedirecturl="https://www.google.com/url?q=https://sofietyinfo.sofi.com/sofi-benefits&amp;source=gmail&amp;ust=1667318410571000&amp;usg=AOvVaw0ZqbRtznVe1JsWWUOWQUnN">Benefits at SoFi</a>&nbsp;</strong>page!</div> <h5 style="text-align: center;"><span style="font-weight: 400;">SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.</span></h5> <h5 style="text-align: center;"><span style="font-weight: 400;">The Company hires the best qualified candidate for the job, without regard to protected characteristics.</span></h5> <h5 style="text-align: center;"><span style="font-weight: 400;">Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.</span></h5> <h5 style="text-align: center;"><a href="https://dol.ny.gov/system/files/documents/2022/02/ls740_1.pdf" target="_blank"><span style="font-weight: 400;">New York applicants: Notice of Employee Rights</span></a></h5> <h5 style="text-align: center;"><span style="font-weight: 400;">SoFi is committed to an inclusive culture. As part of this commitment, </span><span style="font-weight: 400;">SoFi </span><span style="font-weight: 400;">offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email </span><a href="mailto:accommodations@sofi.com" target="_blank">accommodations@sofi.com.</a></h5> <h5 style="text-align: center;"><span style="font-weight: 400;">We are unable to accommodate remote work from Hawaii, Alaska or Puerto Rico at this time.</span></h5> <div class="gmail_default"><strong>Internal Employees</strong></div> <div class="gmail_default">If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.</div></div>