Overview

Information Security Analyst Jobs in Jacksonville, FL at SoFi

Title: Information Security Analyst

Company: SoFi

Location: Jacksonville, FL

Employee Applicant Privacy NoticeWho we are:Shape a brighter financial future with us.

Together with our members, we’re changing the way people think about and interact with personal finance.

We’re a next-generation fintech company using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way.Join us to invest in yourself, your career, and the financial world.About The RoleSoFi Product Security team assists and partners with engineering, product and design organizations. Our mission is to secure the products and services delivered to our members and customers. We deploy best in class Product Security practices, compliance frameworks, and design patterns by collaborating with product owners, engineers, and executives. The mission is core to SoFi’s value “Put our member’s interest first”.

As an Information Security Specialist, you will be responsible for ensuring the security of our existing and new platforms, products, and services. You will work in conjunction with security architects, development (engineering), and product teams to review systems and services with security controls baked into them. This role is the primary face of the security organization to other groups within SoFi.

The ideal candidate will be highly collaborative, balancing the right level of security with business objectives, and working to creatively solve complex Product Security related problems in an agile environment.

What you’ll do:

Perform regular vulnerability assessments using different tools. Regularly drive remediation and reporting of cataloged vulnerabilities.

Assess discovered vulnerabilities and properly prioritize their scope, impact and necessary response actions.

Conduct security reviews of our products and production infrastructure.

Contribute to vulnerability management, application security and/or offensive/red-team operations.

Engage in security audit and security regulatory exercises with partners and vendors.

Support regulatory compliance monitoring and reporting

Support treatment and remediation activities with identified points of contact and system owners

Develop processes and document procedures for use by other team members and to enhance efficiencies

What you’ll need:

Bachelor’s Degree in Computer Science, Information Systems, or equivalent work-related experience

Strong knowledge of industry standards regarding vulnerability management including Common Vulnerabilities and Exposures (CVE), Common Vulnerability Scoring System (CVSS), OWASP, etc.

Experience with different types of vulnerability assessment tools or related experience in vulnerability detection DAST/SAST tools

Outstanding communication and interpersonal skills, with the capacity to effectively convey intricate security concepts to both technical and non-technical stakeholders.

Ability to demonstrate knowledge with prioritizing remediation activities with operational teams through risk ratings of vulnerabilities and assets

Experience judging the vulnerability priority based on risk and impact

Deep application security knowledge, with the ability to map an application vulnerability to exploitation indications and relevant investigative techniques.

Preferred Qualification…

Upload your CV/resume or any other relevant file. Max. file size: 800 MB.

About SoFi