Staff Cybersecurity Controls Specialist
SoFiUSA1mo ago
Job description
About the role
As a , you will play a pivotal role in safeguarding the organization's digital assets and ensuring compliance with industry regulations. This position is designed for a seasoned professional with a strong background in cybersecurity controls, risk management, and compliance frameworks. You will work closely with cross-functional teams to identify vulnerabilities, develop robust security measures, and enhance the overall security posture of the organization. Your expertise will be critical in shaping the cybersecurity strategy and ensuring that SoFi continues to provide a safe and secure environment for its customers.
Key facts
What you'll do
- Develop and implement comprehensive cybersecurity controls that align with industry best practices and regulatory requirements.
- Conduct thorough risk assessments to identify potential vulnerabilities within SoFi's systems and processes, and recommend appropriate mitigation strategies.
- Collaborate with IT and engineering teams to integrate security measures into the software development lifecycle, ensuring that security is a fundamental aspect of all projects.
- Monitor and analyze security incidents and breaches, providing detailed reports and recommendations for improvement to senior management.
- Lead initiatives to enhance the organization's security awareness and training programs, fostering a culture of security among all employees.
- Stay up-to-date with the latest cybersecurity trends, threats, and technologies to ensure SoFi's defenses remain robust and effective.
- Participate in audits and assessments to evaluate the effectiveness of existing security controls and recommend enhancements as needed.
- Develop and maintain documentation related to security policies, procedures, and controls, ensuring that all materials are current and accessible.
- Work with external partners and vendors to assess their security practices and ensure alignment with SoFi's security standards.
- Assist in the development of incident response plans and play a key role in responding to security incidents, including coordinating with law enforcement when necessary.
- Provide guidance and mentorship to junior cybersecurity team members, fostering their professional growth and development.
- Engage with regulatory bodies and industry groups to stay informed about compliance requirements and best practices.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 5 years of experience in cybersecurity, with a focus on controls and compliance.
- Strong understanding of cybersecurity frameworks such as NIST, ISO 27001, and CIS Controls.
- Proven experience in risk assessment methodologies and vulnerability management.
- Familiarity with security technologies such as firewalls, intrusion detection systems, and endpoint protection solutions.
- Excellent analytical and problem-solving skills, with the ability to think critically and make sound decisions under pressure.
- Strong communication skills, both verbal and written, with the ability to convey complex security concepts to non-technical stakeholders.
- Experience working in a fast-paced, agile environment, with the ability to manage multiple priorities effectively.
- Relevant certifications such as CISSP, CISM, or CISA are highly desirable.
Nice to have
- Experience in the financial services industry or a regulated environment.
- Knowledge of cloud security practices and tools, particularly in AWS or Azure environments.
- Familiarity with DevSecOps practices and tools.
- Experience with security incident response and forensic analysis.
- Understanding of data privacy regulations such as GDPR or CCPA.
Skills & tools
- Proficient in security assessment tools and methodologies.
- Familiarity with SIEM solutions and threat intelligence platforms.
- Knowledge of programming or scripting languages such as Python, PowerShell, or Bash is a plus.
- Experience with security frameworks and compliance management tools.
Practical notes
- This position is based in New York City, and candidates should be prepared for a hybrid work environment that includes both remote and in-office work.
- The role may require occasional travel for training or conferences.
- SoFi values diversity and encourages applicants from all backgrounds to apply.
- Interested candidates can submit their applications through the provided link.