Cybersecurity Risk Manager

1 month ago


Seattle, Washington, United States SoFi Full time

Employee Applicant Privacy Notice
Who we are:
Shape a brighter financial future with us.
Together with our members, we're changing the way people think about and interact with personal finance.
We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we're at the forefront. We're proud to come to work every day knowing that what we do has a direct impact on people's lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
The role:
The Cybersecurity Risk Manager will develop and implement SoFi's second line of defense (2LOD) cyber risk and control evaluation program. This role requires a proven expertise in and understanding of Amazon Web Services (AWS) security options and best-practice configurations. Expertise in cloud configurations, especially AWS, will be equivalent to the first line of defense (1LOD) cloud operators.
The manager will collaborate closely with 1LOD IT and Cybersecurity teams to analyze cloud based controls and must have the hands-on skills necessary to navigate and evaluate configurations. In AWS, this means expertise in GuardDuty for continuous threat detection, Inspector for vulnerability assessments, CloudWatch for monitoring and alerting, and other cloud-native controls such as Cloud Access Security Broker (CASB) solutions that oversee and govern cloud-first technologies, ensuring robust security controls and compliance with industry-leading cybersecurity frameworks.
The role requires a deep understanding of cyber risk and the ability to create oversight and governance processes and procedures, providing credible expert challenges, and conducting independent assessments to ensure IT and cybersecurity programs are well-designed and operating effectively. Results of these reviews will be thoroughly documented and require effective translation from technical summaries to risk reports that are easily consumed by the risk owners (1LOD) and leadership. The Cybersecurity Risk Manager will also be a leader in developing 2LOD policies, standards, frameworks, procedures, guidelines, and reporting to support and influence risk management associated with the 1LOD cybersecurity program. Furthermore, the manager will oversee workload management strategies within AWS environments, optimizing resource allocation and ensuring resilience against cyber threats. By leveraging CASB solutions and AWS tools, the manager will ensure that SoFi's cybersecurity programs and processes comply with operational, regulatory, and established SoFi policies, standards, procedures, and guidelines, safeguarding critical assets and data in cloud environments effectively. Proven experience with AWS services and tools, as well as a strong understanding of cybersecurity frameworks and standards, are essential for this role.
What you'll do:

  • Establish a strategic plan for the review and development of the independent review of 1LOD and the technical evaluation of the breadth and depth of the control environment.
  • Develop and implement a comprehensive 2LOD cybersecurity risk management program.
  • Provide independent assessment and credible challenge to the 1LOD cybersecurity team's controls, processes and procedures.
  • Collaborate closely with the 1LOD IT and cybersecurity teams to provide risk guidance and framework support.
  • Perform reviews of 1LOD risk and control self-assessments (RCSA) to identify, analyze, and evaluate cybersecurity risks and gaps and to ensure controls are designed and operating effectively across SoFi and affiliates.
  • Ensure 1LOD activities properly identify, document, and risk rank critical cyber assets on-prem and in cloud services in a timely manner, and those risks are reflected in monitoring and incident response protocols to ensure a low cyber risk tolerance.
  • Conduct regular reviews and provide credible challenges to cloud configurations, settings, procedures and processes, especially in the AWS environment to ensure residual risks do not exceed SoFi's low-risk tolerance.
  • Provide technical expertise with Infrastructure as Code (IaC) tools and practices (e.g, Terraform, CloudFormation)
  • Assess and enhance the security posture of 1LOD Cloud environments using key security tools like: AWS GuardDuty, AWS Inspector, AWS Security Hub, and Cloudflare.
  • Evaluate the effectiveness of AWS monitoring and logging tools, including Amazon CloudWatch and AWS CloudTrail and their integration with the SIEM.
  • Develop custom scripts to aid in evaluations, utilizing tools such as AWS CLI and AWS SDKs.
  • Utilize industry-leading frameworks and best practices for risk assessment and mitigation including CIS AWS Foundations Benchmark, FFIEC management booklet, and NIST CSF.
  • Perform frequent reviews of security metrics from all security controls ensuring they are reporting per SLA, and appropriate monitoring, alerting, and responses are managed and working effectively.
  • Engage with senior cyber management and other stakeholders to communicate risk posture, gaps, and recommend actions.
  • Ensure compliance with relevant regulatory requirements and industry standards (e.g., FFIEC, NIST, CIS).
  • Work closely with 1LOD cross-functional teams to stay updated on the latest cybersecurity risks, threats, trends, and regulatory changes.
  • Stay up to date on emerging AWS services and security features.
  • Review cybersecurity training and awareness programs to ensure the organization is establishing an effective culture of cyber risk awareness and proactive cyber risk testing.
  • Implement sound cyber risk management methodologies and requirements to be deployed by 1LOD risk owners.
  • Develop and maintain comprehensive documentation of cyber risk assessments.
  • Collect key cyber risk and performance data, establish cyber risk trends, analyze and report regularly on elevated risks failing to meet expected levels of cyber risk management and performance.
  • Identify, document and test automated 1LOD cyber controls, and recommend opportunities for additional risk mitigation.
  • Prepare and deliver clear, concise, and actionable reporting to senior leadership and governance committees.

What you'll need:

  • Bachelor's degree or equivalent experience and certifications in cybersecurity, information technology, computer science or a related field
  • 8+ years of relevant cybersecurity, technology, risk management, regulatory and compliance, or Internal Audit experience
  • Minimum of 3 years assessing risk, cloud-based infrastructure management or development in a cloud-first environment
  • Extensive knowledge of AWS cloud platform and capabilities, with equivalent cloud-provider experience in Azure or GCS a plus
  • Cybersecurity operations background and deep understanding of risk management practices
  • Proven record working with control frameworks, testing methodologies, and risk assessments
  • Highly effective interpersonal and communication skills and proven ability to positively influence all levels of personnel, including IT/Security partners and senior leadership
  • Strong understanding of risk governance and 2LOD processes used to review and challenge first line IT, cybersecurity, and business unit risk management processes
  • Wide breadth of knowledge regarding primary risks associated with the products and services of online banking and infrastructure operations
  • Experience leading and developing team members in a cybersecurity or risk group
  • Proven success building and implementing control testing programs to evaluate the design and adequacy and effectiveness of key controls
  • Experience building and maturing governance, risk, and compliance (GRC) systems
  • Self-motivated with strong collaboration instincts and communication skills

Examples Include:

  • Minimum Education Requirements such as: High School Diploma or Bachelor's Degree
  • Minimum Experience Requirements such as: 1 year experience in a similar role. Be careful not to require more years than is necessary to gain the minimum qualifications.
  • Knowledge of certain systems, policies, and procedures that are necessary to perform basic job functions right away.
  • Language requirements if consistently partnering with teams that have a large client base with a foreign language.

Nice to have:

  • Prior experience in a cybersecurity operations or cyber risk leadership role with significant risk management background
  • Advanced degree; relevant industry certifications, for example, CSSP, CISSP, CISM, CCSK, CISA, Cloud Audit Academy certification, AWS Certified Security, AWS Certified Solutions Architect
  • Ability to drive risk and control innovation, direct new cybersecurity practices in 1LOD
  • Experience in banking, fintech, or highly regulated industry
  • Experience preparing reports for and interacting with and presenting to regulators (Fed, OCC, CFPB, NYDFS) and executive leadership within IT and Risk
  • Enterprise experience assessing AI risks
  • Experience working in Google Docs, Sheets and Slides

Compensation and Benefits
The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location.
To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page
SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.
The Company hires the best qualified candidate for the job, without regard to protected characteristics.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
New York applicants: Notice of Employee Rights
SoFi is committed to embracing diversity. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email
Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.
Internal Employees
If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.



  • Seattle, Washington, United States Cybersecurity company Full time

    Job OverviewThis SLED Cybersecurity Account Executive role is open to candidates located in cities with major airports that provide direct access to various western locations.Preferred Locations: Los Angeles, Seattle, Las Vegas, Salt Lake City, Denver, Phoenix, and Chicago.Our esteemed Global Cybersecurity client is in search of a seasoned Account Executive...


  • Seattle, Washington, United States ITmPowered, LLC Full time

    Position Overview:The Senior Consultant for Technology Risk Management will play a pivotal role in the Cybersecurity division at ITmPowered, focusing on the national initiative for Medical Device and IoT Cybersecurity. This position is integral in guiding the clinical healthcare technology sector through the complexities of cyber threats and regulatory...


  • Seattle, Washington, United States ITmPowered, LLC Full time

    Position Overview:The Senior Consultant for Technology Risk Management will play a pivotal role in the Technology Risk Management organization, focusing on a national initiative related to Medical Device and IoT Cybersecurity. This position involves guiding the medical device cybersecurity program and clinical healthcare technology teams in navigating the...


  • Seattle, Washington, United States Federal Reserve Bank of Cleveland Full time

    Company Federal Reserve Bank of Cleveland At the Federal Reserve Bank of Cleveland, we are dedicated to enhancing the nation's monetary, financial, and payment systems to foster a robust economy for all citizens. We pride ourselves on being a community-focused institution, striving to understand and serve the diverse communities within our jurisdiction. Our...


  • Seattle, Washington, United States RSM US LLP Full time

    About the RoleRSM US LLP is seeking a highly skilled Cybersecurity Governance and Compliance Manager to join our team. As a key member of our Security, Privacy, and Risk Consulting practice, you will be responsible for leading and developing teams, managing personnel, and overseeing the completion of assessments to identify risks within an organization's...


  • Seattle, Washington, United States ITmPowered, LLC Full time

    Position Overview:The Senior Cybersecurity Risk Consultant will play a pivotal role within the Technology Risk Management division, focusing on a national initiative for Medical Device and IoT Cybersecurity. This role is essential in guiding the clinical healthcare technology sector through the complexities of the cyber and regulatory environment, ensuring...


  • Seattle, Washington, United States Expeditors Full time

    Job SummaryWe are seeking a highly skilled Cybersecurity Expert to join our global team at Expeditors. As a key member of our Cybersecurity Team, you will play a critical role in protecting our data and our customers' information.Key Responsibilities:Enhance security operations tools and processes to ensure the confidentiality, integrity, and availability of...


  • Seattle, Washington, United States TEKsystems Full time

    Job OverviewWe are seeking a skilled Cybersecurity Analyst to join our newly established Digital Security division at TEKsystems. In this pivotal role, you will collaborate closely with both the Enterprise Security Team and the Digital Team to implement transformative security measures across our e-commerce platform.Your responsibilities will include working...


  • Seattle, Washington, United States Expeditors Full time

    Company Overview "We're not in the shipping business; we're in the information business" -Peter Rose, Expeditors Founder At Expeditors, we specialize in global supply chain management, but our core values are rooted in professionalism, leadership, and a collaborative atmosphere that promotes innovation and exceptional customer service. 18,000 skilled...


  • Seattle, Washington, United States ZHH Staffing Full time

    ABOUT THE TEAMThe Cybersecurity Portfolio division plays a crucial role in aligning Cybersecurity initiatives with our strategic goals, facilitating ongoing capabilities that safeguard the organization while promoting sustainable growth. To achieve this, enhanced visibility into the diverse Cybersecurity services across the global enterprise is essential. We...


  • Seattle, Washington, United States Expeditors Full time

    Join the Expeditors Cybersecurity TeamWe are seeking a dedicated Cybersecurity Operations Expert to become a vital part of our international team, focusing on safeguarding our sensitive data and ensuring the security of our clients' information. If you possess a robust background in cybersecurity and a keen analytical perspective, we encourage you to explore...


  • Seattle, Washington, United States CareOregon Full time

    Career Opportunities: Cybersecurity Specialist II Full TimePermanentRemote Work AvailableMulti Location Job Summary: The Cybersecurity Specialist II role is essential in implementing and upholding security measures to safeguard CareOregon's digital infrastructure and sensitive information from cyber threats. This position plays a pivotal role in influencing...


  • Seattle, Washington, United States Lululemon Athletica Full time

    Position Overview:Lululemon Athletica is seeking a Technology Manager specializing in Cybersecurity Services. This role is essential for guiding a team in the realm of cybersecurity, ensuring that strategic priorities are effectively communicated and executed.Direct strategic initiatives in cybersecurityAssess the influence of strategic projects on...


  • Seattle, Washington, United States Lululemon Athletica Full time

    Position Overview:Lululemon Athletica is seeking a Technology Manager specializing in Cybersecurity Services. This role is essential for overseeing a range of cybersecurity projects and programs, ensuring effective communication of priorities and objectives.Direct strategic initiatives within the cybersecurity domainAssess the influence of strategic projects...


  • Seattle, Washington, United States Lululemon Athletica Full time

    Position Overview:Lululemon Athletica is seeking a Technology Manager specializing in Cybersecurity Services. This role is pivotal for individuals with extensive experience in overseeing portfolios, programs, and projects within the cybersecurity domain. You will be instrumental in guiding a dedicated team and ensuring that strategic priorities are...


  • Seattle, Washington, United States Lululemon Athletica Full time

    Position Overview:Lululemon Athletica is seeking a Technology Manager specializing in Cybersecurity Services. This role is essential for guiding our cybersecurity initiatives and ensuring effective communication of priorities within the organization.Direct strategic cybersecurity projects and initiativesAssess the implications of strategic decisions on...


  • Seattle, Washington, United States Insight Global Full time

    Position Overview:Insight Global is seeking a Senior Cybersecurity Portfolio Analyst to join our team. This role is pivotal in ensuring the strategic alignment and financial management of the Cybersecurity Portfolio. The ideal candidate will possess strong analytical skills, be adept with financial tools, and thrive in dynamic environments while navigating...


  • Seattle, Washington, United States Lululemon Athletica Full time

    Position Overview:Lululemon Athletica is seeking a Technology Manager specializing in Cybersecurity Services. This pivotal role requires a seasoned professional with extensive experience in overseeing portfolios, programs, and projects within the cybersecurity domain. The successful candidate will be instrumental in guiding a dedicated team and ensuring that...


  • Seattle, Washington, United States Lululemon Athletica Full time

    Position Overview:Lululemon Athletica is seeking a Technology Manager specializing in Cybersecurity Services. This role is essential for individuals with a robust history in overseeing portfolios, programs, and projects. The successful candidate will be pivotal in guiding a team and ensuring that priorities are communicated with clarity.Direct strategic...


  • Seattle, Washington, United States Remitly, Inc. Full time

    Job DescriptionRemitly, Inc. is seeking a highly skilled Cybersecurity Systems Architect to design and build robust information security systems for detecting and investigating potentially malicious activity.Key Responsibilities:Design and implement threat detection and response solutions in a cloud-first environment, including IaaS, PaaS, and SaaS.Develop...