# Senior Vulnerability Management Engineer at SoFi

- Company: SoFi
- What the company does: Backed by IVP.
- Company website: https://www.sofi.com
- Type: Startups
- Level: Senior
- Location: WA - Seattle; CA - San Francisco
- Work setup: On-site
- Posted: 2026-09-04
- Apply by: 2026-10-19
- Apply: https://sofi.com/careers/job/7986999003?gh_jid=7986999003
- Page: https://www.1752.vc/careers/jobs/sofi-senior-vulnerability-management-engineer/

## About the role

As a Senior Vulnerability Management Engineer you will independently identify, assess, prioritize, and drive the remediation of vulnerabilities across applications, infrastructure, containers, Kubernetes environments, and third-party dependencies. You will be expected to understand how vulnerable dependencies enter an application, determine whether they are direct or transitive, identify appropriate remediation options, and work with engineering teams to implement and validate fixes.

## What they're looking for

- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or equivalent practical experience
- 4+ years of experience in information security, vulnerability management, application security, security engineering, or a related discipline
- Strong understanding of CVE, CVSS, CWE, CISA KEV, EPSS, OWASP, and risk-based vulnerability prioritization
- Experience investigating vulnerable dependencies using build files, dependency trees, lock files, container images, and software-composition-analysis tools
- Ability to determine where a vulnerable package originates and recommend a safe, compatible remediation
- Hands-on experience operating vulnerability-management platforms such as Qualys or similar tools

Tags: Information Security
