sofi

Staff Technical Program Manager, Security Programs

Apply Now

At a Glance

Location
San Francisco, CA; WA - Seattle; NY - New York City; UT - Cottonwood Heights
Experience
8+ years
Posted
2026-07-24T19:31:33-04:00

Key Requirements

Required Skills

CI/CD

Domain Knowledge

  • Automation
  • Banking
  • Cybersecurity
  • Engineering
  • Finance
  • Regulatory
  • Supply Chain

Requirements

8+ years of experience in technical program management, security program management, security operations, product security, application security, infrastructure security, DevSecOps, or a related technical discipline.

Demonstrated ownership of vulnerability management, product security, application security, cloud security, infrastructure security, or similar cybersecurity programs.

Experience driving large-scale, cross-functional programs across Security, Engineering, Product, Infrastructure, IT, Risk, Compliance, and senior leadership stakeholders.

Strong understanding of vulnerability management lifecycle concepts, including discovery, triage, prioritization, remediation, validation, SLA management, exception handling, and executive reporting.

Experience using data, KPIs, dashboards, and stakeholder reporting to improve program visibility, accountability, and outcomes.

Strong technical fluency with modern software, cloud, infrastructure, endpoint, container, API, and/or application security environments.

Responsibilities

SoFi is looking for a Staff Technical Program Manager to lead our Vulnerability Management program—the primary mandate for this role—while also providing strategic oversight and driving maturity across other critical cybersecurity initiatives.

This is a high-impact cybersecurity role focused on building durable program structure, improving remediation outcomes, and driving cross-functional execution across Security, Engineering, Product, Infrastructure, Enterprise Technology, Risk, and Compliance.

This person will not be expected to function as a hands-on vulnerability engineer, but they must have enough technical depth to operate credibly with security engineers, application teams, infrastructure teams, and senior leaders.

While technical depth is essential for credibility and navigating security domains, this role prioritizes your ability to influence stakeholders, navigate organizational dynamics, and convert ambiguous security data into clear, business-aligned risk reduction outcomes.

SoFi’s vulnerability management ecosystem spans multiple detection layers across code, containers, cloud infrastructure, endpoints, APIs, mobile, data, and secrets, with findings routed through centralized workflows and business-unit remediation queues.

This role will help strengthen that operating model by improving prioritization, accountability, reporting, stakeholder alignment, and program maturity.