HHiring Reality
← SoFi

Offensive Security Lead

SoFi
Location
CA - San Francisco; WA - Seattle; NY - New York City; UT - Cottonwood Heights; TX - Frisco; MT - Helena
Posted
17 days ago
Department
Information Security
What they actually want (must-haves)
  • 8+ years in offensive security with hands-on experience in penetration testing and red team/adversary emulation
  • 2+ years managing or leading offensive security teams in a regulated industry
  • Experience designing and implementing AI-led or AI-assisted offensive security programs
  • Deep technical fluency across network, web/application, cloud (AWS/GCP/Azure), and mobile attack surfaces
  • Strong written and verbal communication skills
  • Experience operating in a highly regulated environment
Nice to have
  • Experience with adversary emulation frameworks (e.g., MITRE ATT&CK) and C2 tooling
  • Relevant certifications (OSCP, OSCE, OSEP, GPEN, GXPN, CRTO) preferred but not required
What the job really is

As the Offensive Security Lead at SoFi, you will oversee and enhance the Penetration Testing and Red Team functions, focusing on integrating these disciplines into a cohesive offensive security strategy. Your role involves leading hands-on engagements, implementing AI-assisted security programs, managing a team of security professionals, and ensuring that offensive findings contribute to real remediation efforts across the organization.

Things to weigh
  • No specific salary figures provided, only a base pay range based on experience and location
  • The role requires a mix of hands-on technical skills and leadership, which may be demanding
  • Experience in a regulated environment is emphasized, which may limit flexibility in approach
Job score2.8/5
Benefits1/5
Freshness4/5
Career value4/5
Role clarity5/5
Pay transparency0/5

Applying to SoFi?

See how your résumé matches this role — and tailor it from what actually gets interviews.