Staff Enterprise Security Engineer
SoFi · WA - Seattle; CA - San Francisco; UT - Cottonwood Heights; NY - New York City; TX - Frisco
About this role
**Employee Applicant Privacy Notice** https://www.sofi.com/sofi-employee-applicant-privacy-notice/ **Who we are** Shape a brighter financial future with SoFi. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help millions of members reach their goals. **The role** As a **Staff Enterprise Security Engineer**, you’ll serve as the subject matter expert for **Data Loss Prevention (DLP)** while driving engineering across broader enterprise security domains—**email security, endpoint protection, network defense, and phishing simulation**. You’ll sit within the **Enterprise Security** team, balancing data protection focus with hands-on architecture, operations, and automation of foundational IT and corporate security controls. We’re looking for security leaders who combine tool administration expertise (e.g., **Zscaler, Proofpoint, Sentra, CrowdStrike**) with systems thinking to mitigate risk across diverse threat vectors. You’ll define risk mitigation strategies and build clear technical roadmaps—accelerating security delivery while maintaining safety, correctness, and data protection. **What you’ll do** - Lead end-to-end delivery and architecture for enterprise security capabilities: **enterprise zero-trust networks, endpoint security, and SaaS posture management**. - Frame complex security challenges: clarify requirements, threat models, failure modes, and success metrics; propose architectural options and tradeoffs. - Design for scale and resilience: establish secure baselines, automate security guardrails, and reduce systemic attack surfaces with minimal enterprise friction. - Collaborate with internal security teams to establish and maintain **threat signaling** for proper visibility and alerting across tooling. - Raise cybersecurity standards through design reviews, active mentorship, and establishing enterprise security patterns and best practices. - Collaborate cross-functionally with **IT, Infrastructure, Risk/Compliance, and Engineering** to deliver secure member outcomes. **What you’ll need** - **Education & experience:** Bachelor’s + **3–4 years** OR Master’s + **2–3 years** in cybersecurity, computer science, information technology, or related field. - **3+ years** of cybersecurity experience with a focus on **DLP**. - Hands-on experience with cloud-based DLP solutions (e.g., **Zscaler, Proofpoint, Sentra**). - Experience administering and operating core enterprise security tools (**EDR, email security gateways, web proxies**). - Experience with **Infrastructure as Code (IaC)** (e.g., **Terraform**) and scripting languages (**Python, Go, or PowerShell**) for tooling and automation. - Experience with **incident response, log analysis, threat detection, and digital forensics**. - Experience collaborating across multiple lines of defense for issue analysis, evidence gathering, and remediation. - Proven problem-solving skills; ability to work independently and collaboratively in a fast-paced environment. - Strong written and verbal communication for technical documentation, cross-functional collaboration, and threat modeling. **Nice to have** - Professional security certifications (e.g., **CISSP, CCSP, CISM, AWS Certified Security – Specialty**). - Experience with **CI/CD security pipeline automation**, **SIEM detections**, and **SOAR playbooks**. - Knowledge of financial compliance frameworks and regulatory environments (**PCI-DSS, SOC1/SOC2, SOX, GLBA, NIST CSF,
Listing freshness
CronJobs last confirmed this listing 1h ago. If its source stops confirming the opening for seven days, this page is removed from active inventory.