layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
SoFi
CA - San Francisco; WA - Seattle; NY - New York City; UT - Cottonwood Heights; TX - Frisco; MT - Helena
Source: SoFi careers · View original posting
From SoFi's posting. “We” and “our” refer to the employer.
Employee Applicant Privacy Notice
Shape a brighter financial future with us.
Together with our members, we’re changing the way people think about and interact with personal finance.
We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way.
Join us to invest in yourself, your career, and the financial world.
SoFi's Cyber Defense organization is looking for an Offensive Security Lead to mature and grow our Penetration Testing and Red Team functions. This is a hands-on leadership role for someone who has spent years both doing the work and building the program around it — someone equally comfortable running a red team engagement against a critical banking platform and designing the operating model that lets a small team of offensive operators keep pace with a fast-growing fintech.
A defining part of this role is modernizing how the team scales. We're looking for a leader who has already built and implemented AI-assisted penetration testing and red teaming programs — using AI tooling to accelerate reconnaissance, exploit development, attack-path analysis, and reporting — and who can bring that experience to bear on the program.
You'll own the strategy, staffing, tooling, and execution quality of both disciplines, report into Cyber Defense leadership, and act as a trusted advisor to engineering, product, and risk partners across the company.
8+ years in offensive security, with demonstrated hands-on experience in both penetration testing and red team/adversary emulation — not just one discipline.
2+ years directly managing or leading offensive security teams, ideally within a regulated industry (financial services, fintech, healthcare, or similar).
Proven experience designing and implementing AI-led or AI-assisted offensive security programs — you can speak concretely to what you built, what tooling/models you used, what scaled and what didn't, and how it changed team output.
Deep technical fluency across network, web/application, cloud (AWS/GCP/Azure), and mobile attack surfaces, plus familiarity with adversary emulation frameworks (e.g., MITRE ATT&CK) and C2 tooling.
Track record of building programs from the ground up or maturing existing ones — process, tooling, metrics, and team structure, not just individual engagements.
Strong written and verbal communication skills; comfort presenting findings and program strategy to engineering leaders, risk teams, and executives.
Experience operating in a highly regulated environment and working with auditors/examiners is a strong plus.
Relevant certifications (OSCP, OSCE, OSEP, GPEN, GXPN, CRTO, or equivalent demonstrated experience) preferred but not required in lieu of strong hands-on track record.
Compensation
The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location.
To view all of our comprehensive and competitive benefits, visit our
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: