Cybersecurity Architect

1 month ago


New York, New York, United States SoFi Full time

Employee Applicant Privacy Notice
Who we are:
Shape a brighter financial future with us.
Together with our members, we're changing the way people think about and interact with personal finance.
We're a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we're at the forefront. We're proud to come to work every day knowing that what we do has a direct impact on people's lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
About The role
SoFi Product Security team assists and partners with engineering and product and design organizations. Our mission is to build secure products and services delivered to our members and customers. We deploy strong Product Security practices, compliance frameworks, and design patterns while collaborating with product owners, engineers, and executives to ensure new products and features meet the highest security standards and regulations.
As a Cybersecurity Architect, you will be responsible for the end-to-end security architecture of our platforms, products, and services. You will work in conjunction with security, compliance, and risk teams to make decisions and help lead initiatives to ensure timely delivery of security solutions that support our business objectives.
The ideal candidate will be highly collaborative, balancing the right level of security with business objectives, and working to creatively solve complex Product Security related problems in an agile environment.
What you'll do:

  • Be an Cybersecurity architect evangelist who can translate security concepts into language that is meaningful to our product teams and engineering. Integrate new and existing security tools, standards, and processes into the development life cycle.
  • Develop Security test plans for new products. Design security solution blueprints that meet the system needs. Automate security checklists and implement them as "security as code" using cloud services and CI/CD components.
  • Advise on the secure design of product and application architecture; communicate security requirements with well defined user stories and initiatives and epics.
  • Review new features / product offerings and perform threat modeling in a continuous delivery agile environment.
  • Conducts business-level security architecture assessments to evaluate existing security program and cloud application architecture, identify weaknesses, and make recommendations.
  • Work with our risk and compliance organization to provide input to security risk impact assessment. Contribute to security policy, standards, and guidelines related to Information Security.
  • Work with engineering teams, to ensure that application security risks are effectively identified using market leading tools (SAST, DAST, SCA, etc) and appropriately addressed while maintaining a balance between security & usability.
  • Architects, designs, prioritizes, coordinates, and communicates the security technologies necessary to ensure a highly secure yet usable computing environment.
  • Provide subject matter expertise on encryption, security controls, secure design and programming practices across the Technology organization.
  • Train and mentor Security Champions throughout the development team.
  • Develop key partnerships with executive leadership and their staff to facilitate positive change.

What you'll need:

  • Good understanding of cloud services, AWS, and Well Architected Framework security pillar
  • Experience with the application of threat modeling or other risk identification techniques
  • Experience working and architecting security solutions with highly distributed and scalable systems
  • Demonstrate deep understanding of Infrastructure, IAM and PAM.
  • Knowledge of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols)
  • Identity and Access Management, Authentication and authorization protocols like OIDC, OAuth2.0, SAML
  • Web application security, Microservices and API design patterns
  • Service Mesh/Istio, microsegmentation, and network security
  • Cryptographic protocols and standards (Data encryption)
  • Demonstrated knowledge on threat landscape, security threat and vulnerability management, and security monitoring and analytics.
  • Ability to prioritize between and execute on multiple work streams
  • Written and verbal skills for communicating security concepts and solutions
  • Secure software development lifecycle / "Shift Left"

Preferred Qualifications:

  • Bachelor's degree in computer science or equivalent from a fully accredited college or university
  • 10+ Experience in Infrastructure and product security architecture
  • Experience with cloud native products and in-depth understanding of microservice topologies and implementations
  • 10+ years of experience with cloud technologies
  • Demonstrated ability to think strategically about business, product, and technical challenges
  • Proven ability to work with compliance frameworks and requirements such as PCI, GLBA, HIPAA, GDPR, SOX, etc.
  • Ability to manage relationships with other business units, external vendors and stakeholders when IT security risks are present, and system or process changes must be made to mitigate risk
  • Familiarity with AWS and at-scale services
  • Ability to work in a fast paced and Agile development environment
  • Work and play well with others; SoFi is a collaborative environment

Nice to have:

  • CISSP, CISM, GSEC or AWS Certified Security Architect
  • Master's or PhD in Computer Science or Engineering
  • Financial services experience

Compensation and Benefits
The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate's experience, skills, and location.
To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page
SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.
The Company hires the best qualified candidate for the job, without regard to protected characteristics.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
New York applicants: Notice of Employee Rights
SoFi is committed to embracing diversity. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email
Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.
Internal Employees
If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.



  • New York, New York, United States Palo Alto Networks Full time

    Job OverviewCompany OverviewOur VisionAt Palo Alto Networks, our journey begins and ends with our vision:To be the preferred cybersecurity ally, safeguarding our digital existence.We aspire to create a world where each day is more secure than the last. Achieving these ambitious goals is no small feat - but we thrive on challenges. We are a company rooted in...


  • New York, New York, United States Loginsoft Full time

    NOTE: THIS POSITION IS TO JOIN AS W2 ONLY.Cybersecurity Solutions ArchitectLocation: RemoteDuration: 5 MonthsThe Cybersecurity Solutions Architect plays a pivotal role in safeguarding the integrity and compliance of Loginsoft's enterprise architecture. This position is designed for a technical authority who will ensure that the organization's technology...


  • New York, New York, United States Clear Street Full time

    Company Overview:Clear Street is at the forefront of modern financial infrastructure, established to transform the way institutions operate in today's capital markets. Our innovative approach involves creating a fully cloud-native clearing and custody platform that meets the demands of a complex, global trading environment.The Role:As a Cybersecurity...


  • New York, New York, United States Evolve Esolutions LLC Full time

    About the RoleWe are seeking a highly skilled Cybersecurity Architect to join our team at Evolve Esolutions LLC. As a key member of our security team, you will be responsible for designing, documenting, testing, maintaining, and providing issue resolution recommendations for highly complex security solutions related to Micro-Segmentation.Key...


  • New York, New York, United States Bitly Full time

    Position OverviewWe are in search of a skilled and proactive Security Engineer. The ideal candidate will have a strong passion for cybersecurity and a solid technical foundation in application and cloud network technologies. In this position, you will work closely with our application production engineering teams and the Infosec team to embed security best...


  • New York, New York, United States Bitly Full time

    Position OverviewWe are looking for a skilled and dedicated Security Engineer who is enthusiastic about safeguarding digital assets. The ideal candidate will have a solid technical foundation in application and cloud network technologies, along with a strong commitment to cybersecurity. In this position, you will work closely with various engineering teams...


  • New York, New York, United States Bitly Full time

    Position OverviewWe are looking for a skilled and motivated Security Engineer to enhance our cybersecurity efforts. The successful candidate will have a strong technical foundation in application and cloud network technologies and a genuine interest in safeguarding digital assets. This role involves close collaboration with application production engineering...


  • New York, New York, United States Bitly Full time

    Position OverviewWe are looking for a skilled and motivated Security Engineer to enhance our cybersecurity efforts. The successful candidate will have a strong passion for safeguarding digital assets and a solid technical foundation in application and cloud networking technologies. This role involves close collaboration with our application production...


  • New York, New York, United States Bitly Full time

    Position OverviewWe are looking for a skilled and motivated Security Engineer to enhance our cybersecurity efforts. The successful candidate will have a strong passion for safeguarding digital assets and a solid technical foundation in application and cloud network technologies. This role involves close collaboration with our application production...


  • New York, New York, United States PGMTEK Inc. Full time

    Job Overview We are seeking an experienced Senior Cybersecurity Analyst to join our team at PGMTEK Inc. This role involves a long-term engagement focused on safeguarding our digital infrastructure.KEY RESPONSIBILITIES: Cybersecurity Expertise - 5-7 years of relevant experience. Formulate and execute a robust cybersecurity framework and policies to secure...


  • New York, New York, United States Rose International Full time

    Position Overview:As a Senior Management Consultant specializing in Cybersecurity, you will play a pivotal role in advising financial institutions on compliance with US regulatory standards. Your expertise will be essential in evaluating existing banking applications and proposing enhancements to ensure robust security measures are in place.Key...


  • New York, New York, United States Rose International Full time

    Position Overview:As a key member of our team at Rose International, the Senior Management Consultant will focus on enhancing cybersecurity measures within financial services. This role requires a deep understanding of regulatory compliance and the ability to assess and improve existing banking applications.Key Responsibilities:Evaluate current cybersecurity...


  • New York, New York, United States Rose International Full time

    Position Overview:We are seeking a highly skilled Senior Management Consultant specializing in Cybersecurity to provide expert guidance in the financial services sector. The ideal candidate will possess a deep understanding of regulatory requirements and technical solutions related to information security.Key Responsibilities:Assess compliance of banking...


  • New York, New York, United States Rose International Full time

    Position Overview:We are seeking a highly skilled Senior Management Consultant specializing in Cybersecurity to join our team. The ideal candidate will possess a robust understanding of both Japanese and English, allowing for effective communication in a bilingual environment.Key Responsibilities:Assess and analyze the current cybersecurity posture of...


  • New York, New York, United States Bitly Full time

    Position OverviewWe are looking for a skilled and motivated Security Engineer who is enthusiastic about safeguarding digital assets. The successful candidate will have a solid technical foundation in both application and cloud security technologies. In this role, you will work in close collaboration with engineering teams and the Information Security...


  • New York, New York, United States C4 Technical Services Full time

    Position OverviewBilingual Cybersecurity Analyst - Proficient in Japanese and EnglishContract Duration: 7 MonthsWork Arrangement: Remote with occasional travelRole Summary:We are seeking a skilled bilingual professional (Japanese-English) to fulfill the role of Cybersecurity Analyst. This position requires a deep understanding of cybersecurity principles,...


  • New York, New York, United States Rose International Full time

    Position Overview:We are seeking a highly skilled Senior Management Consultant specializing in Cybersecurity to join our team. This role requires a deep understanding of cybersecurity regulations and the ability to assess and enhance existing banking applications to ensure compliance with US regulatory standards.Key Responsibilities:Bilingual Proficiency:...


  • New York, New York, United States Rose International Full time

    Position Overview:We are seeking a highly skilled professional to fill the role of Senior Management Consultant specializing in Cybersecurity. This position requires a strong understanding of both Japanese and English, as well as a comprehensive grasp of US regulatory information security and cybersecurity requirements.Key Responsibilities:Evaluate and...


  • New York, New York, United States Rose International Full time

    Position Overview:We are seeking a highly skilled Senior Management Consultant specializing in Cybersecurity to provide expert guidance and strategic insights. The ideal candidate will possess a deep understanding of regulatory requirements and technical solutions in the cybersecurity domain.Key Responsibilities:Fluency in both Japanese and English is...


  • New York, New York, United States Rose International Full time

    Position Overview:We are seeking a highly skilled Senior Management Consultant specializing in Cybersecurity to join our team. This role requires a deep understanding of regulatory compliance and security protocols within the financial services sector.Key Responsibilities:Fluency in both Japanese and English is essential.Comprehend US regulatory information...