
Job Overview
Location
WA - Seattle; UT - Cottonwood Heights; CA - San Francisco; MT - Helena; NY - New York City; TX - Frisco
Job Type
Full-time
Category
Cybersecurity
Date Posted
April 21, 2026
Full Job Description
đź“‹ Description
- • The Staff IAM Engineer at Social Finance, Inc. (SoFi) is responsible for securing and managing all non-human identities—including service accounts, application identities, machine credentials, APIs, bots, and workloads—across on-prem, cloud, and crypto infrastructure. This role ensures automated and machine-based identities follow the same governance, lifecycle, and least-privilege principles as human users, directly protecting sensitive financial data, crypto custody environments, and transaction systems from privilege misuse, credential leakage, and insider or supply chain threats.
- • Day to day, the engineer designs, implements, and maintains a Non-Human Identity (NHI) framework; implements centralized secrets management using tools like HashiCorp Vault or AWS Secrets Manager; builds integrations with CI/CD pipelines and cloud services (AWS, GCP, Azure) for automated credential rotation and JIT provisioning; develops automated workflows for NHI lifecycle management; creates visibility dashboards for NHI inventory and compliance; enforces least privilege and zero-trust principles; monitors for over-permissioned credentials; supports incident response with forensics on compromised credentials; maintains audit trails for compliance reporting (SOX, SOC 2, PCI DSS, FFIEC, crypto-custody); and evaluates emerging solutions like SPIFFE/SPIRE and workload identity federation to drive innovation in credentialless authentication.
- • SoFi is a next-generation financial services company and national bank using innovative, mobile-first technology to help millions of members reach their financial goals. The company is at the forefront of an unprecedented transformation in the financial industry, guided by core values that emphasize impact on people’s lives. Employees are encouraged to invest in their careers while contributing to a mission-driven culture focused on financial inclusion and innovation.
- • In this role, the Staff IAM Engineer will deepen expertise in machine identity security, gain hands-on experience with modern secrets management and automation tools, influence enterprise-wide NHI governance strategies, lead proof-of-concepts for cutting-edge identity technologies, and play a critical role in securing SoFi’s financial infrastructure—positioning themselves as a leader in the evolving field of non-human identity management within a high-impact, regulated fintech environment.
🎯 Requirements
- • Bachelor’s degree in Computer Science, Cybersecurity, or related discipline
- • 3–6 years of experience in IAM, DevSecOps, or Security Engineering roles
- • Hands-on experience with non-human identity or secrets management tools (e.g., HashiCorp Vault, AWS Secrets Manager)
- • Proficiency in automation and scripting (Python, PowerShell, or Bash)
- • Strong understanding of authentication standards (OIDC, OAuth 2.0, SAML, JWT)
- • Familiarity with cloud IAM concepts (AWS IAM Roles, Azure Managed Identities, GCP Service Accounts)
🏖️ Benefits
- • Competitive base pay range based on experience, skills, and location
- • Comprehensive benefits package (details available via SoFi Benefits page)
- • Equal employment opportunity employer committed to diversity and inclusion
- • Reasonable accommodations provided for candidates with physical or mental disabilities
- • Consideration of qualified applicants with arrest and conviction records per San Francisco Fair Chance Ordinance
Skills & Technologies
About Social Finance, Inc.
Social Finance, Inc. is an American online personal finance company that offers lending, savings, investing, and insurance products through a mobile-first platform. Founded in 2011, it provides student-loan refinancing, personal and mortgage loans, checking and savings accounts, credit cards, and active and automated investing. SoFi uses alternative underwriting data and career-based pricing, targets high-earning millennials, and bundles services into a membership model with career coaching and financial planning. Headquartered in San Francisco, it went public in 2021 through a SPAC merger and operates as a bank holding company after acquiring Golden Pacific Bancorp.
Subscribe to the weekly newsletter for similar remote roles and curated hiring updates.
Newsletter
Weekly remote jobs and featured talent.
No spam. Only curated remote roles and product updates. You can unsubscribe anytime.
Similar Opportunities

Akaysha Energy Pty Ltd
2 months ago

Arctic Wolf Networks, Inc.
27 days ago

Innovecs LLC
2 days ago
