New RJRP now shows Market-Observed Roles alongside verified postings — scored by our Hiring Activity algorithm. How it works →
🔍
Market-Observed Role 🔍 Observed Very Active (80-100)
This role was detected through SoFi's hiring system and hasn't been verified directly by the employer. Our algorithm scored it as Very Active (80-100) based on freshness, specificity, and company patterns. What does this mean? →

Security Product Lead –  Enterprise & Identity Security

SoFi
🔍 Observed
84
Hiring Activity Score
Very Active (80-100)
  • Base score
  • Posted 1 days ago
  • has location, quality description (10107 chars)
  • 145 new listings in 30d (×0.98 age 1d)
  • Tier 1 reputable (SoFi) ×0.98 age 1d
  • Direct ATS (greenhouse)
How the Hiring Activity Score works →
WA - Seattle; UT - Cottonwood Heights; CA - San Francisco; TX - Frisco First seen 1 day, 5 hours ago Last seen 5 hours, 39 minutes ago Greenhouse
Apply on Greenhouse Search Google for This Role

ATS links often expire — Google search finds the latest posting

Job Description

Employee Applicant Privacy Notice

Who we are:

Shape a brighter financial future with us.

Together with our members, we’re changing the way people think about and interact with personal finance.

We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.

Role Overview

The Security Product Lead – Enterprise & Identity Security is responsible for defining the strategic direction, roadmap, and measurable outcomes for securing the organization's enterprise infrastructure, critical internal systems, and user identities. This role sits within the Security Strategy & Delivery team and partners closely with the Identity & Access Management (IAM), Infrastructure Security, and Engineering functional leaders and operational teams.

This position ensures that Enterprise Security and Identity Security capabilities are treated as internal security products—aligned to enterprise risk priorities, supported by a clear roadmap, measured through defined KPIs, and delivered through structured program governance.

The role requires strong cross-functional collaboration, strategic thinking, and the ability to influence without direct authority. By ensuring robust identity governance and securing enterprise infrastructure, this role directly supports the organization's overarching goal of protecting member trust, safeguarding corporate assets, and ensuring the continued stability and growth of the business.

 

Key Responsibilities

Strategy & Roadmap Stewardship

  • Develop and maintain a multi-year strategy and roadmap for Enterprise Security, Identity Security (IAM, PAM, Authentication), and AI Security capabilities.
  • Align roadmap priorities with enterprise risk objectives, regulatory requirements (e.g., access controls, data governance, AI governance), and evolving threat landscape.
  • Identify capability gaps (e.g., zero-trust adoption, privileged access maturity, AI model integrity) and define strategic investment opportunities.
  • Translate strategic objectives into structured, sequenced initiatives.

 

Product & Capability Management

  • Enterprise Security
  • Define the value proposition and service model for Enterprise Security capabilities (e.g., infrastructure hardening, cloud security posture).
  • Add aspects of data security under enterprise security: Establish product requirements and roadmaps for Data Security capabilities, including data loss prevention (DLP), data classification, data encryption, and ensuring compliance with data privacy regulations.
  • Identity Management
    • Define the value proposition and service model for Identity Management capabilities (e.g., self-service access, least privilege principle, lifecycle management).
    • Establish clear capability maturity targets (e.g., IAM coverage, access certification completeness) and continuous improvement plans.
  • Maintain and prioritize a strategic backlog across all areas aligned to measurable risk reduction outcomes (e.g., reduction in over-privileged accounts, faster access revocation, secure-by-design adoption in AI).
  • Ensure capabilities are treated as ongoing products with lifecycle ownership, not one-time projects.
  • Define and track outcome-based metrics (risk reduction, adoption, efficiency) for core security platforms and identity controls.

 

Portfolio & Program Management

  • Own the portfolio view of Enterprise, Identity, and AI Security initiatives within the broader security strategy.
  • Structure and manage strategic programs required to deliver roadmap objectives (e.g., rollout of new PAM solution, AI Model SecOps integration).
  • Define milestones, delivery plans, and success metrics for major initiatives.
  • Track progress against portfolio commitments and escalate risks proactively.
  • Manage cross-functional dependencies across Engineering, IT, HR, Legal, and other stakeholders.
  • Ensure predictable execution through structured governance and reporting cadence.

Cross-Functional Collaboration

  • Partner closely with the Identity & Access Management, Infrastructure Security, and AI/ML functional leaders to align on priorities and execution sequencing.
  • Collaborate with Product Management, Engineering, Data Science, Legal, Risk, and Compliance stakeholders.
  • Facilitate stakeholder alignment, trade-off decisions, and expectation management.
  • Influence without direct authority to drive security principles across enterprise systems.

Continuous Improvement & Innovation

  • Monitor industry trends in enterprise architecture security, identity threats (e.g., phishing, credential stuffing), and AI-specific threats (e.g., model poisoning, prompt injection).
  • Identify opportunities for automation, analytics enhancement, and process optimization within identity lifecycles and infrastructure monitoring.
  • Incorporate lessons learned from security audits and penetration tests into roadmap evolution.

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, or related discipline.
  • 7+ years of experience in cybersecurity, risk management, or technology strategy roles.
  • Demonstrated experience in Identity & Access Management (IAM), Privileged Access Management (PAM), Enterprise Security, Data Security, or AI/ML Security domains.
  • Demonstrated experience building and managing strategic roadmaps tied to measurable outcomes.
  • Strong understanding of security frameworks, identity protocols (e.g., OAuth, SAML, SCIM), and enterprise risk.
  • Understanding of AI/ML concepts and associated security risks, including data provenance, model integrity, and adversarial machine learning.
  • Strong product mindset with ability to translate strategy into execution.
  • Experience working in matrixed organizations with cross-functional stakeholders.
  • Strong analytical, communication, and executive presentation skills.

 

Compensation and Benefits
The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the candidate’s experience, skills, and location. 
 
To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!
SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.
The Company hires the best qualified candidate for the job, without regard to protected characteristics.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
New York applicants: Notice of Employee Rights
SoFi is committed to an inclusive culture. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com.
Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.
Internal Employees
If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open roles.

Skills

rust go
Job Information
  • Company:
    SoFi
  • Location:
    WA - Seattle; UT - Cottonwood Heights; CA - San Francisco; TX - Frisco
  • Job Type:
    Internship
  • Work Location:
    Remote
  • Experience Level:
    Senior
  • Source:
    Greenhouse
  • Status:
    Active
Activity Score
84 /100
Very Active (84)

Higher scores indicate more likely active hiring based on listing freshness, company activity, and other signals. Learn more →

+
🔍

We now show two types of job listings

Same commitment to real jobs. More opportunities for you. Here's how it works.

✓ Verified Employer-Verified Posts

These jobs were posted directly to RJRP by the employer. The company has been verified through our multi-step process. This is our gold standard — the employer is real, the job is real, and you can apply with confidence.

✓ 100% employer verified
🔍 Observed Market-Observed Roles

These roles were detected through employer hiring systems like Workday. They haven't been verified by the employer directly, so we score each one using our Hiring Activity Score — an algorithm that analyzes freshness, specificity, company hiring patterns, and more to estimate whether the role is actively being filled.

📊 Only high-scoring listings are shown

Our promise hasn't changed. We will never show you a listing we can't stand behind. Market-observed roles must pass our scoring threshold before they appear on RJRP. Anything that looks like a ghost job, a talent pipeline, or a dead listing gets filtered out — you'll never see it.