Staff Vulnerability Management Engineer
SoFi
Who we are Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The role We are seeking a Staff Vulnerability Management Engineer to lead the most complex technical work in SoFi’s Vulnerability Management program. You will design and build scalable systems that identify, enrich, prioritize, route, and track vulnerabilities across applications, cloud and infrastructure, containers, software supply chains, and specialized hardware or firmware surfaces. This is a hands-on engineering role with broad technical influence: you will write production code, make architecture decisions, establish vulnerability management standards, and improve how teams understand and reduce vulnerability risk. You will partner with Engineering, Infrastructure, SRE, Compliance, Legal, and business stakeholders to accelerate remediation while protecting engineering velocity and customer trust. You will also serve as a senior technical responder for embargoed disclosures and zero-day events, lead root-cause analysis for high-impact vulnerability incidents, and mentor engineers.
The ideal candidate combines deep vulnerability management expertise with strong software engineering judgment, systems thinking, and a bias for durable, measurable outcomes. What you’ll do - Lead high-complexity vulnerability management initiatives and make architecture decisions for assigned program areas, from detection and assessment through ticket routing, remediation, exception handling, and closure validation. - Design, build, and productionize scalable triage and prioritization automation, including scanner and asset integrations, enrichment pipelines, decision logic, deduplication, ownership resolution, service-level tracking, observability, and failure recovery. - Develop risk-based prioritization models that combine CVSS, EPSS, CISA Known Exploited Vulnerabilities, threat intelligence, asset criticality, exposure, compensating controls, business context, and compliance obligations. - Engineer and improve vulnerability workflows across application security, cloud and infrastructure, containers and Kubernetes, open-source dependencies, secrets, software supply chain, and hardware-adjacent surfaces such as GPU, DPU/BlueField, BMC, and firmware. - Own or materially advance software supply chain capabilities, including SBOM inventory, dependency visibility, SLSA-aligned controls, and integration of SAST, SCA, secret scanning, and container scanning into CI/CD. - Act as a senior technical responder for critical vulnerabilities, embargoed disclosures, and zero-day events; coordinate technical assessment, containment, mitigation, patch deployment, validation, and executive communication with service owners and incident response teams. - Partner directly with development and platform teams to define practical remediation paths and, when appropriate, review or contribute secure changes in Python, Go, JavaScript/TypeScript, or infrastructure code. - Define technical standards for vulnerability severity, remediation service levels, exceptions, evidence, and closure criteria; ensure workflows support audit-ready reporting for applicable regulatory and compliance frameworks. - Produce actionable metrics, dashboards, and risk insights for technical and executive audiences, with clear accountability, trend analysis, compliance posture, and execution risks.
- ...guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.About The roleAs a Vulnerability Management Engineer, you will support the identification, assessment, prioritization, and remediation of vulnerabilities across...SuggestedRemote work
$100.63k - $167.79k
....S. work authorization that does not require employer sponsorship.Job Overview:LPL Financial is in search of a Senior Vulnerability Management Engineer who can execute and mature the existing Vulnerability Management program at LPL and its subsidiaries. As a member of the...SuggestedFull timeWork from home$75k - $125k
...Security Group (CSG) is looking for an experienced and skilled individual to join the Vulnerability Operations (VO) team. Nelnet’s Vulnerability Operations team is responsible for managing the attack surface and collaboration with various business units to assess risk by...SuggestedFull timeContract workTemporary workWork experience placementWork at officeLocal areaRemote work3 days per week- ...every step of the way. Join us to invest in yourself, your career, and the financial world.About the roleAs a Senior Vulnerability Management Engineer you will independently identify, assess, prioritize, and drive the remediation of vulnerabilities across applications,...SuggestedRemote work
- Job DescriptionThe Role: As a Senior Cybersecurity Vulnerability Engineer, you will serve as a highly capable individual contributor responsible... ...improvement, and continuous maturity of GM Vulnerability Management core services across enterprise infrastructure, client...SuggestedFull timeInterim roleLocal areaImmediate startWork from homeRelocation package
- ...Splunk Vulnerability Management Team Member Join the Splunk Vulnerability Management team, where we are dedicated to securing our products... ...threats. We want someone who enjoys partnering directly with engineering teams to address risks head-on and get critical fixes...Remote work
- ...Vulnerability Management Engineer Location: Oxon Hill, Maryland (Remote) Duration: 6+ month contract-to-hire Clearance: Must be eligible to obtain/maintain a Public Trust Role Overview We are seeking a Vulnerability Management Engineer to identify, prioritize...Contract workRemote work
$75 - $85 per hour
...This position supports advancing the enterprise vulnerability management program across four functional pillars: Detect, Prioritize... ...- 5+ years hands-on vulnerability management or security engineering - Direct implementation experience with at least one enterprise...Hourly payContract workLocal areaRemote work2 days per week3 days per week- Senior Vulnerability Management & SOAR Engineer Since 1906, New Balance has empowered people through sport and craftsmanship to create positive change in communities around the world. We innovate fearlessly, guided by our core values and driven by the belief that conventions...Temporary workPart timeRemote work
- Job Description Peraton is seeking a Senior Vulnerability Engineer to lead enterprise vulnerability management, exposure management, compliance auditing, and web application scanning initiatives across AWS cloud and on-prem environments. This is a highly technical engineering...Remote job
- ...Job Description Job Description Job Title: Saviynt IAM Staff Augmentation - Senior Identity & Access Management Engineer Available Locations: Scottsdale, AZ, Chicago, IL, San Francisco, CA (Onsite) Type: Long term Contract Core Capabilities Saviynt IGA Delivery...Long term contractWork from homeFlexible hours
$106k - $126k
Position: IR Plume Mod/Sim Systems Engineer Location: Colorado Springs, CORemote Status: On-Site Job Id: 13908-TASD-Eric # of Openings: 1 Auria is looking to hire a Modeling & Simulation Systems...Contract workWork at officeRemote workFlexible hours- ...About the Position We're looking for a Cybersecurity Engineer to help us mature our vulnerability management program. You'll join our Cybersecurity team, a skilled group of programmers and security experts dedicated to keeping the firm safe. Vulnerability management...Full time
- ...Functional Skills: 2+ years of experience in Site Reliability Engineering, DevOps, Infrastructure Engineering, or a related role... ...cloud-based production environments. Practical vulnerability-management experience; familiarity with Qualys, JFrog Xray, SCA/SBOM,...Full timeWorldwide
$50.96 - $60.58 per hour
Position: IR Plume Mod/Sim Systems Engineer Location: Colorado Springs, CORemote Status: On-Site Job Id: 13908-TASD-Eric # of Openings: 1 Auria is looking to hire a Modeling & Simulation Systems...Full timeContract workWork at officeRemote workFlexible hours$130.2k - $195.4k
...company and a leading AI platform for managing people, money, and agents, we’re shaping... ...TeamSecurity Automation & Integration Engineering (SecAIE) transforms cybersecurity... ...and the shape of common security data (vulnerabilities, incidents, identity, threat intel). You...Full timeWork at officeRemote workHome officeFlexible hours- ...portfolio of acquisition and program management support efforts. While this role is not... ...Systems is recruiting to fill Cybersecurity Engineers of all levels supporting the ISR/SOF... ...-tamper (AT) plans, cyber findings, vulnerabilities, and risks.Conduct technical...Contract workLive outRemote work
- ...refreshing its Continuous Threat Exposure Management (CTEM) and internal penetration... ...execution across the exposure surface. Our engineers do the complex, creative, context-... ...yet do — business logic flaws, chained vulnerabilities, social engineering, and novel attack...Full timeLocal areaRemote workRelocation
- POSITION: Senior Microsoft 365 Engineer (Identity, Endpoint & Compliance)We’re hiring the... ...is what we’ll run on, and how it gets managed is yours to define.A week in this job:... ...security surface — sit with infrastructure.• Vulnerability response: CVE triage from SecOps,...Full timeWork at officeShift work
$87k - $148k
...evolving world. As a premier global asset management organization with more than 85 years of... ...role serves as the Level 3 Messaging Engineer for the Collaboration Team and is the... ...phishing/anti-malware).Plans and executes vulnerability response, security updates, and patch...Full timeLocal areaRemote workWork from home2 days per week3 days per week$69.4k - $158k
...experience in systems and network security engineering to safeguard our nation's resources?... ...identify the tools needed to assess vulnerabilities and recommend the best solution and... ...variety of audiences, including senior management. Implement infrastructure and cyber security...Full timeContract workPart timeWork at officeLocal areaRemote work- ...cybersecurity posture, the full-time salaried Cybersecurity Engineer III will identify, analyze, and remediate vulnerabilities across various enterprise environments while leading Continuous Threat Exposure Management (CTEM) initiatives in a remote setting. Key...Full timeRemote work
- ...Senior Endpoint Engineer Department: IT Employment... ...reliable operation of endpoint management through Microsoft Intune,... ...endpoint security policies, and vulnerability remediation. • Use pilot... ...currently comprises 5,500+ staff across the US. For more information...Full timeContract workWork at officeLocal areaRemote workRelocation
- ...Identity and Access Management Date: Aug 26, 2026 Location: Bangalore, KA, IN, 560100 Req ID: 37586 Work Mode: Remote India Summary... ...and well-being of the members they serve — a community's most vulnerable. Connect your passion with purpose, teaming with people who...Remote workShift work
- ...Job Title: OT Engineer Location: Hybrid Onsite in Austin or Temple, TX Type: Direct Hire Top 3-5 Must Have... ...presence (video on; collared shirt) and ability to discuss vulnerability management concepts (plus). Job Description: Are you passionate...Extra incomeWork at officeRemote work3 days per week
$71.6k - $119.4k
...sciences companies to create product data management strategies and meet compliance... ...the RoleReed Tech is seeking a Systems Engineer III responsible for the design, implementation... ...authentication services.Lead vulnerability remediation efforts by identifying, prioritizing...Full timeLocal areaImmediate startWorldwideFlexible hours$112.8k - $257k
ISSO Cybersecurity Engineer, LeadThe Opportunity: This is your opportunity to own and sustain... ...technical evidence.What You’ll Work On:Manage the RMF lifecycle activities and... ...security conceptsAbility to validate STIG and vulnerability findings, false positives, risk...Full timeContract workPart timeWork at officeLocal areaRemote work- ...Cybersecurity Engineer Reporting to the Executive Director, Information Security and GRC, the Cybersecurity Engineer... ...security monitoring, incident investigation and response, vulnerability and patch management, security awareness, and the administration of essential...Work experience placementRemote workFlexible hours
- ...Enterprise Solutions and Management (ESM) is a rapidly growing government contractor that... ...customers. We are hiring a Cybersecurity Engineer to support an enterprise-level program... ...Ability to conduct security analysis, vulnerability assessments, and incident response...Full timeFor contractorsWork at officeLocal areaRemote work
- ...Description Position Summary The Systems Engineer is responsible for designing,... ...abilities, and the capability to independently manage complex infrastructure projects while... ...Microsoft Defender for Servers. Perform vulnerability remediation. Assist with incident...Work at officeRemote workWeekend workAfternoon shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Staff Vulnerability Management Engineer. Be the first to apply!
- engineering aide Remote
- technology administrator Remote
- staff security engineer Remote
- assistant engineering manager Remote
- project engineer assistant project manager Remote
- assistant chief engineer Remote
- staff data engineer Remote
- senior staff systems engineer Remote
- senior staff engineer Remote
- staff engineer Remote




