Offensive Security Lead
San Francisco, CA - USA
Job Summary
Employee Applicant Privacy Notice
Who we are:
Shape a brighter financial future with us.
Together with our members were changing the way people think about and interact with personal finance.
Were a next-generation financial services company and national bank using innovative mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation and were at the forefront. Were proud to come to work every day knowing that what we do has a direct impact on peoples lives with our core values guiding us every step of the way. Join us to invest in yourself your career and the financial world.
The Role:
SoFis Cyber Defense organization is looking for an Offensive Security Lead to mature and grow our Penetration Testing and Red Team functions. This is a hands-on leadership role for someone who has spent years both doing the work and building the program around it someone equally comfortable running a red team engagement against a critical banking platform and designing the operating model that lets a small team of offensive operators keep pace with a fast-growing fintech.
A defining part of this role is modernizing how the team scales. Were looking for a leader who has already built and implemented AI-assisted penetration testing and red teaming programs using AI tooling to accelerate reconnaissance exploit development attack-path analysis and reporting and who can bring that experience to bear on the program.
Youll own the strategy staffing tooling and execution quality of both disciplines report into Cyber Defense leadership and act as a trusted advisor to engineering product and risk partners across the company.
What Youll Do:
Lead and unify Penetration Testing and Red Team into a single cohesive Offensive Security function shared standards shared tradecraft shared reporting distinct missions.
Set and execute the offensive security roadmap aligning testing scope and cadence to SoFis risk profile regulatory obligations and the pace of product and platform change in the company.
Build and scale AI-augmented offensive security capabilities design and implement tooling and workflows (AI-assisted recon vulnerability triage exploit chaining purple-team simulation report generation) that increase the teams coverage and throughput without sacrificing depth or tradecraft.
Personally lead and contribute to engagements where needed network application cloud and AI pentests; adversary emulation and full-scope red team operations staying technically credible with the team you lead.
Manage and develop the team: hire coach mentor and grow a mix of penetration testers and red team operators; build clear career paths between the two disciplines and into leadership or other disciplines.
Own program metrics and maturity: define KPIs for coverage finding severity and remediation velocity engagement quality and program ROI; report progress to senior leadership and risk committees.
Partner cross-functionally with Vulnerability Management SOC/Incident Response Application Security and engineering teams to ensure offensive findings drive real remediation and inform detection engineering.
Manage external partnerships third-party pentest and red team tooling and/or execution vendors including scoping quality oversight and budget.
Represent Offensive Security in audits regulatory exams and executive briefings translating technical risk into business risk clearly and credibly.
What Youll Need:
8 years in offensive security with demonstrated hands-on experience in both penetration testing and red team/adversary emulation not just one discipline.
2 years directly managing or leading offensive security teams ideally within a regulated industry (financial services fintech healthcare or similar).
Proven experience designing and implementing AI-led or AI-assisted offensive security programs you can speak concretely to what you built what tooling/models you used what scaled and what didnt and how it changed team output.
Deep technical fluency across network web/application cloud (AWS/GCP/Azure) and mobile attack surfaces plus familiarity with adversary emulation frameworks (e.g. MITRE ATT&CK) and C2 tooling.
Track record of building programs from the ground up or maturing existing ones process tooling metrics and team structure not just individual engagements.
Strong written and verbal communication skills; comfort presenting findings and program strategy to engineering leaders risk teams and executives.
Experience operating in a highly regulated environment and working with auditors/examiners is a strong plus.
Relevant certifications (OSCP OSCE OSEP GPEN GXPN CRTO or equivalent demonstrated experience) preferred but not required in lieu of strong hands-on track record.
About Company
Why do 10M+ members trust SoFi? Financial solutions for school, marriage, starting a family, home buying, retirement, or whatever’s next. Member FDIC.