# Offensive Security Lead at SoFi

- Company: SoFi
- What the company does: Backed by IVP.
- Company website: https://www.sofi.com
- Type: Startups
- Level: Senior
- Location: CA - San Francisco; WA - Seattle; NY - New York City; UT - Cottonwood Heights; TX - Frisco; MT - Helena
- Work setup: On-site
- Posted: 2026-09-03
- Apply by: 2026-10-18
- Apply: https://sofi.com/careers/job/7985585003?gh_jid=7985585003
- Page: https://www.1752.vc/careers/jobs/sofi-offensive-security-lead/

## About the role

SoFi's Cyber Defense organization is looking for an Offensive Security Lead to mature and grow our Penetration Testing and Red Team functions. This is a hands-on leadership role for someone who has spent years both doing the work and building the program around it — someone equally comfortable running a red team engagement against a critical banking platform and designing the operating model that lets a small team of offensive operators keep pace with a fast-growing fintech.

## What they're looking for

- 8+ years in offensive security, with demonstrated hands-on experience in both penetration testing and red team/adversary emulation — not just one discipline
- 2+ years directly managing or leading offensive security teams, ideally within a regulated industry (financial services, fintech, healthcare, or similar)
- Proven experience designing and implementing AI-led or AI-assisted offensive security programs — you can speak concretely to what you built, what tooling/models you used, what scaled and what didn't, and how it changed team output
- Deep technical fluency across network, web/application, cloud (AWS/GCP/Azure), and mobile attack surfaces, plus familiarity with adversary emulation frameworks (e.g., MITRE ATT&CK) and C2 tooling
- Track record of building programs from the ground up or maturing existing ones — process, tooling, metrics, and team structure, not just individual engagements
- Strong written and verbal communication skills, comfort presenting findings and program strategy to engineering leaders, risk teams, and executives

Tags: Information Security
