Social Finance, Inc. logo

Staff IAM Engineer

Job Overview

Location

WA - Seattle; UT - Cottonwood Heights; CA - San Francisco; MT - Helena; NY - New York City; TX - Frisco

Job Type

Full-time

Category

Cybersecurity

Date Posted

April 21, 2026

Full Job Description

đź“‹ Description

  • • The Staff IAM Engineer at Social Finance, Inc. (SoFi) is responsible for securing and managing all non-human identities—including service accounts, application identities, machine credentials, APIs, bots, and workloads—across on-prem, cloud, and crypto infrastructure. This role ensures automated and machine-based identities follow the same governance, lifecycle, and least-privilege principles as human users, directly protecting sensitive financial data, crypto custody environments, and transaction systems from privilege misuse, credential leakage, and insider or supply chain threats.
  • • Day to day, the engineer designs, implements, and maintains a Non-Human Identity (NHI) framework; implements centralized secrets management using tools like HashiCorp Vault or AWS Secrets Manager; builds integrations with CI/CD pipelines and cloud services (AWS, GCP, Azure) for automated credential rotation and JIT provisioning; develops automated workflows for NHI lifecycle management; creates visibility dashboards for NHI inventory and compliance; enforces least privilege and zero-trust principles; monitors for over-permissioned credentials; supports incident response with forensics on compromised credentials; maintains audit trails for compliance reporting (SOX, SOC 2, PCI DSS, FFIEC, crypto-custody); and evaluates emerging solutions like SPIFFE/SPIRE and workload identity federation to drive innovation in credentialless authentication.
  • • SoFi is a next-generation financial services company and national bank using innovative, mobile-first technology to help millions of members reach their financial goals. The company is at the forefront of an unprecedented transformation in the financial industry, guided by core values that emphasize impact on people’s lives. Employees are encouraged to invest in their careers while contributing to a mission-driven culture focused on financial inclusion and innovation.
  • • In this role, the Staff IAM Engineer will deepen expertise in machine identity security, gain hands-on experience with modern secrets management and automation tools, influence enterprise-wide NHI governance strategies, lead proof-of-concepts for cutting-edge identity technologies, and play a critical role in securing SoFi’s financial infrastructure—positioning themselves as a leader in the evolving field of non-human identity management within a high-impact, regulated fintech environment.

🎯 Requirements

  • • Bachelor’s degree in Computer Science, Cybersecurity, or related discipline
  • • 3–6 years of experience in IAM, DevSecOps, or Security Engineering roles
  • • Hands-on experience with non-human identity or secrets management tools (e.g., HashiCorp Vault, AWS Secrets Manager)
  • • Proficiency in automation and scripting (Python, PowerShell, or Bash)
  • • Strong understanding of authentication standards (OIDC, OAuth 2.0, SAML, JWT)
  • • Familiarity with cloud IAM concepts (AWS IAM Roles, Azure Managed Identities, GCP Service Accounts)

🏖️ Benefits

  • • Competitive base pay range based on experience, skills, and location
  • • Comprehensive benefits package (details available via SoFi Benefits page)
  • • Equal employment opportunity employer committed to diversity and inclusion
  • • Reasonable accommodations provided for candidates with physical or mental disabilities
  • • Consideration of qualified applicants with arrest and conviction records per San Francisco Fair Chance Ordinance

Skills & Technologies

Python
AWS
Azure
GCP
Kubernetes
Senior
Remote
Degree Required

Ready to Apply?

You will be redirected to an external site to apply.

Social Finance, Inc. logo
Social Finance, Inc.
Visit Website

About Social Finance, Inc.

Social Finance, Inc. is an American online personal finance company that offers lending, savings, investing, and insurance products through a mobile-first platform. Founded in 2011, it provides student-loan refinancing, personal and mortgage loans, checking and savings accounts, credit cards, and active and automated investing. SoFi uses alternative underwriting data and career-based pricing, targets high-earning millennials, and bundles services into a membership model with career coaching and financial planning. Headquartered in San Francisco, it went public in 2021 through a SPAC merger and operates as a bank holding company after acquiring Golden Pacific Bancorp.

Get more remote jobs like this

Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.

Newsletter

Weekly remote jobs and featured talent.

No spam. Only curated remote roles and product updates. You can unsubscribe anytime.

Similar Opportunities

⏰ EXPIRES SOON
Akaysha Energy Pty Ltd logo

Akaysha Energy Pty Ltd

Cremorne, Victoria, Australia; Sydney, New South Wales, Australia
Full-time
Expires Apr 25, 2026 (Soon)
Senior
Remote

2 months ago

Apply
Arctic Wolf Networks, Inc. logo

Arctic Wolf Networks, Inc.

Remote - AUS - Western Australia
Full-time
Expires May 26, 2026
Remote

27 days ago

Apply
Paris, France
Full-time
Expires Jun 13, 2026
Python
Java
Go
+3 more

9 days ago

Apply
Ukraine, Poland, Romania, Spain, Remote
Full-time
Expires Jun 20, 2026
Senior
Remote

2 days ago

Apply