Jobs / United States / Social Finance INC

Offensive Security Lead

Social Finance INC · 🇺🇸 CA - San Francisco; WA - Seattle; NY - New York City; UT - Cottonwood Heights; TX - Frisco; MT - Helena

Sponsorship verdict

Sponsorship possible

One solid signal, not two — worth applying, and worth asking about sponsorship early.

  • Employer is on a government sponsor recordThe US Department of Labor certified 186 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 49 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).
  • The posting doesn’t mention sponsorshipSilence isn’t a refusal — ask the recruiter before investing much time.
  • No salary bar for this routeH-1B has no fixed salary bar: the employer must pay at least the prevailing wage for the role and area. Cap-subject employers enter a lottery weighted by wage level. Source: https://www.federalregister.gov/documents/2025/12/29/2025-23853/weighted-selection-process-for-registrants-and-petitioners-seeking-to-file-cap-subject-h-1b, rules effective 2026-02-27.
  • What Social Finance INC paid sponsored hires in similar roles3 certified filings for “Sr Product Security Engineer” (Information Technology Project Managers) in NY: $207k–$212k, median $210k. Most were filed at wage level III (100%) — 3 lottery entries, ≈46% projected selection odds for cap-subject employers. Source: US Department of Labor LCA disclosure data (Oct 2025 – Jun 2026).
  • Confirmed live todayWhen a source last listed this job as open.

US H-1B: cap-subject employers enter a lottery weighted by wage level — Level I gets 1 entry, Level IV gets 4 (DHS projected selection odds ≈15% at Level I to ≈61% at Level IV). Universities and non-profit research employers are cap-exempt. The $100,000 fee for new petitions from abroad is currently blocked by a court order (appeal pending).

A verdict summarises public evidence; it is not legal advice and never a guarantee — the employer and the immigration authority decide. Sign in to factor in where you can already work.

Start free →

Or apply yourself on the official page →

Sponsor Radar — Social Finance INC

186 H-1B filings certified since Oct 2025

The US Department of Labor certified 186 H-1B/E-3 labor condition applications for this employer between Oct 2025 and Jun 2026 (latest Jun 2026) — the step every H-1B hire needs first. USCIS also records 49 H-1B approvals in FY2023. Source: LCA disclosure data (US Department of Labor (OFLC)).

Past sponsorship or register membership never guarantees sponsorship for this vacancy or for you. Full Sponsor Radar for Social Finance INC →

About the role

Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world. The Role: SoFi's Cyber Defense organization is looking for an Offensive Security Lead to mature and grow our Penetration Testing and Red Team functions. This is a hands-on leadership role for someone who has spent years both doing the work and building the program around it — someone equally comfortable running a red team engagement against a critical banking platform and designing the operating model that lets a small team of offensive operators keep pace with a fast-growing fintech. A defining part of this role is modernizing how the team scales. We're looking for a leader who has already built and implemented AI-assisted penetration testing and red teaming programs — using AI tooling to accelerate reconnaissance, exploit development, attack-path analysis, and reporting — and who can bring that experience to bear on the program. You'll own the strategy, staffing, tooling, and execution quality of both disciplines, report into Cyber Defense leadership, and act as a trusted advisor to engineering, product, and risk partners across the company. What You’ll Do: • Lead and unify Penetration Testing and Red Team into a single, cohesive Offensive Security function — shared standards, shared tradecraft, shared reporting, distinct missions. • Set and execute the offensive security roadmap, aligning testing scope and cadence to SoFi's risk profile, regulatory obligations, and the pace of product and platform change in the company. • Build and scale AI-augmented offensive security capabilities — design and implement tooling and workflows (AI-assisted recon, vulnerability triage, exploit chaining, purple-team simulation, report generation) that increase the team's coverage and throughput without sacrificing depth or tradecraft. • Personally lead and contribute to engagements where needed — network, application, cloud, and AI pentests; adversary emulation and full-scope red team operations — staying technically credible with the team you lead. • Manage and develop the team: hire, coach, mentor, and grow a mix of penetration testers and red team operators; build clear career paths between the two disciplines and into leadership or other disciplines. • Own program metrics and maturity: define KPIs for coverage, finding severity and remediation velocity, engagement quality, and program ROI; report progress to senior leadership and risk committees. • Partner cross-functionally with Vulnerability Management, SOC/Incident Response, Application Security, and engineering teams to ensure offensive findings drive real remediation and inform detection engineering. • Manage external partnerships — third-party pentest and red team tooling and/or execution vendors, — including scoping, quality oversight, and budget. • Represent Offensive Security in audits, regulatory exams, and executive briefings, translating technical risk into business risk clearly and credibly. What You’ll Need: • 8+ years in offensive security, with demonstrated hands-on experience in both penetration testing and red team/adversary emulation — not just one discipline. • 2+ years directly managing or lea

View the official posting →

Source: Greenhouse (employer board) First seen: 2026-09-03 Last confirmed: 2026-10-03 How our data works → Report this job

Similar opportunities