Cybersecurity Risk Manager
SoFiAbout the role
Employee Applicant Privacy Notice
Who we are:
Shape a brighter financial future with us.
Together with our members, we’re changing the way people think about and interact with personal finance.
We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
The role:
The Cybersecurity Risk Manager will develop and implement SoFi's second line of defense (2LOD) cyber risk and control evaluation program. This role requires a proven expertise in and understanding of Amazon Web Services (AWS) security options and best-practice configurations. Expertise in cloud configurations, especially AWS, will be equivalent to the first line of defense (1LOD) cloud operators.
The manager will collaborate closely with 1LOD IT and Cybersecurity teams to analyze cloud based controls and must have the hands-on skills necessary to navigate and evaluate configurations. In AWS, this means expertise in GuardDuty for continuous threat detection, Inspector for vulnerability assessments, CloudWatch for monitoring and alerting, and other cloud-native controls such as Cloud Access Security Broker (CASB) solutions that oversee and govern cloud-first technologies, ensuring robust security controls and compliance with industry-leading cybersecurity frameworks.
The role requires a deep understanding of cyber risk and the ability to create oversight and governance processes and procedures, providing credible expert challenges, and conducting independent assessments to ensure IT and cybersecurity programs are well-designed and operating effectively. Results of these reviews will be thoroughly documented and require effective translation from technical summaries to risk reports that are easily consumed by the risk owners (1LOD) and leadership. The Cybersecurity Risk Manager will also be a leader in developing 2LOD policies, standards, frameworks, procedures, guidelines, and reporting to support and influence risk management associated with the 1LOD cybersecurity program. Furthermore, the manager will oversee workload management strategies within AWS environments, optimizing resource allocation and ensuring resilience against cyber threats. By leveraging CASB solutions and AWS tools, the manager will ensure that SoFi's cybersecurity programs and processes comply with operational, regulatory, and established SoFi policies, standards, procedures, and guidelines, safeguarding critical assets and data in cloud environments effectively. Proven experience with AWS services and tools, as well as a strong understanding of cybersecurity frameworks and standards, are essential for this role.
What you’ll do:
- Establish a strategic plan for the review and development of the independent review of 1LOD and the technical evaluation of the breadth and depth of the control environment.
- Develop and implement a comprehensive 2LOD cybersecurity risk management program.
- Provide independent assessment and credible challenge to the 1LOD cybersecurity team’s controls, processes and procedures.
- Collaborate closely with the 1LOD IT and cybersecurity teams to provide risk guidance and framework support.
- Perform reviews of 1LOD risk and control self-assessments (RCSA) to identify, analyze, and evaluate cybersecurity risks and gaps and to ensure controls are designed and operating effectively across SoFi and affiliates.
- Ensure 1LOD activities properly identify, document, and risk rank critical cyber assets on-prem and in cloud services in a timely manner, and those risks are reflected in monitoring and incident response protocols to ensure a low cyber risk tolerance.
- Conduct regular reviews and provide credible challenges to cloud configurations, settings, procedures and processes, especially in the AWS environment to ensure residual risks do not exceed SoFi’s low-risk tolerance.
- Provide technical expertise with Infrastructure as Code (IaC) tools and practices (e.g, Terraform, CloudFormation)
- Assess and enhance the security posture of 1LOD Cloud environments using key security tools like: AWS GuardDuty, AWS Inspector, AWS Security Hub, and Cloudflare.
- Evaluate the effectiveness of AWS monitoring and logging tools, including Amazon CloudWatch and AWS CloudTrail and their integration with the SIEM.
- Develop custom scripts to aid
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s