Staff Cryptography Engineer
San Francisco, CA - USA
Job Summary
Employee Applicant Privacy Notice
Who we are:
Shape a brighter financial future with us.
Together with our members were changing the way people think about and interact with personal finance.
Were a next-generation financial services company and national bank using innovative mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation and were at the forefront. Were proud to come to work every day knowing that what we do has a direct impact on peoples lives with our core values guiding us every step of the way. Join us to invest in yourself your career and the financial world.
The role
We are looking for a Staff Cryptography Engineer to help lead SoFis enterprise readiness for post-quantum cryptography and long-term cryptographic resilience. This role sits within our Security Assurance organization and will partner closely with security engineering infrastructure product and business stakeholders to assess modernize and strengthen cryptographic controls across the enterprise.
This is a highly cross-functional and strategic role. The ideal candidate brings deep applied cryptography expertise strong engineering and architecture judgment and the ability to drive complex security initiatives in ambiguous environments. You will help build SoFis cryptographic inventory identify where cryptographic keys protocols algorithms certificates and libraries are used and guide teams through the implementation of quantum-resistant and crypto-agile solutions.
What youll do
- Lead efforts to assess and improve SoFis enterprise cryptographic posture with a focus on post-quantum cryptography preparedness and crypto-agility.
- Build and maintain an inventory of cryptographic assets including keys certificates algorithms protocols libraries services and business-critical systems.
- Partner with product engineering infrastructure cloud and security teams to identify cryptographic dependencies and prioritize remediation or migration needs.
- Provide deep technical guidance on SSL/TLS PKI certificates key management encryption cryptographic algorithms and secure protocol usage.
- Define and document cryptographic standards design patterns review gates and implementation guidance for engineering and product teams.
- Evaluate current and future cryptographic risks including quantum-resistant key migration algorithm deprecation certificate lifecycle management and insecure implementation patterns.
- Review product and platform architecture designs to identify cryptographic risks and recommend practical scalable security improvements.
- Translate complex cryptographic concepts into clear guidance roadmaps and decision points for technical and non-technical stakeholders.
- Drive cross-functional execution across teams without direct authority ensuring ownership timelines and risk decisions are clearly documented.
- Support security assurance activities including threat modeling architecture reviews control validation and post-review follow-through.
- Stay current on post-quantum cryptography developments industry standards and emerging security guidance and translate relevant changes into actionable plans for SoFi.
What youll need
- 8 years of experience in security engineering product security applied cryptography security architecture infrastructure security or a related technical security discipline.
- Experience with post-quantum cryptography crypto-agility or cryptographic migration planning.
- Deep hands-on expertise in applied cryptography including cryptographic algorithms secure protocol design (e.g. SSL/TLS mTLS M2M) and the practical implementation and lifecycle management of enterprise-grade solutions such as HSMs KMS secrets management and PKI programs.
- Experience assessing or designing cryptographic controls in production engineering environments including cloud distributed systems services APIs or enterprise platforms.
- Strong understanding of public cloud environments and how cryptographic controls are implemented across infrastructure applications services and data flows.
- Ability to review technical architecture and identify practical cryptographic risks implementation gaps and secure design alternatives.
- Experience creating or driving security standards technical guidance inventories roadmaps or enterprise-wide security initiatives.
- Strong communication skills with the ability to explain complex cryptographic concepts to engineering product security risk and business stakeholders.
- Demonstrated ability to operate independently in ambiguous problem spaces and drive cross-functional work from discovery through execution.
- Strong project ownership and prioritization skills including the ability to identify stakeholders define milestones document decisions and manage follow-through.
- Bachelors degree in computer science cybersecurity engineering mathematics or a related field or equivalent practical experience.
Nice to have
- Experience in financial services fintech banking payments cloud SaaS or other highly regulated technical environments.
- Familiarity with NIST FIPS PCI or other security and cryptographic standards relevant to financial services.
- Experience partnering with product security application security infrastructure platform engineering or enterprise architecture teams.
- Experience building or leading cryptographic inventories key-management programs or encryption modernization efforts.
- Advanced degree or specialized training in cryptography computer science mathematics or information security.
- Experience mentoring security engineers or influencing security architecture practices across multiple teams.
Required Experience:
Staff IC
About Company
Why do 10M+ members trust SoFi? Financial solutions for school, marriage, starting a family, home buying, retirement, or whatever’s next. Member FDIC.