
Fraud Strategist - Ecosystem
Job description
About the role
You will own the horizontal fraud strategy for the entire SoFi member journey, designing decisioning that travels with the member and recognizes threats as they cross product seams. This role requires fluency in device forensics, entity resolution, account takeover defense, and scam interception to translate risk insights into production policy. You will architect a unified cross-product signal layer that replaces fixed dollar caps with risk-tiered frameworks priced on velocity, recency, and counterparty risk. The position demands reasoning across the full product and user lifecycle as a single risk surface, from onboarding and account creation through funding and high-value activity. You will partner with EPD, Fraud Ops, InfoSec, and product owners to govern rule-engine changes and monitor performance against loss forecasts. By joining SoFi, you will help shape a brighter financial future for millions of members while working at the forefront of a transformed financial services industry.
Key facts
What you'll do
- Own fraud strategy across the full SoFi product surface, designing decisioning that leverages signals from onboarding, login, money movement, and product activity in a unified framework rather than in isolation.
- Lead cross-product perimeter defense covering account takeover carryover from compromised credentials, scam interception (authorized push payment, romance, investment, impostor, business email compromise), mule-account detection, and synthetic-identity attacks at funding.
- Drive device forensics across product lines by building and maintaining shared device-graph infrastructure, monitoring emulator and VM detection, jailbreak and root signals, residential-proxy detection, and entity resolution that links a single bad actor across accounts that appear clean in isolation.
- Design risk-tiered money movement decisioning for ACH, FedNow, Wire, Zelle, and P2P flows, replacing static dollar caps with dynamic frameworks that price velocity, recency, counterparty risk, and scam telemetry.
- Build the cross-product analytics layer in SQL and Python, creating shared feature tables, entity-resolution signals, and rule-level attribution so every product line can see a member's full risk posture.
- Partner with EPD, Fraud Ops, InfoSec, and product owners to ship strategy changes through the rules engine with clean governance, performance monitoring, and clear escalation when losses deviate from forecast.
- Define and manage the rule-engine craft and operational guardrails that allow rapid iteration on fraud controls while maintaining stability, auditability, and compliance across all member segments.
- Translate emerging scam typologies and threat intelligence into defensive logic, ensuring that new attack patterns are detected and mitigated across the ecosystem before they can cause widespread harm.
Requirements
- Hold a BA/BS in Statistics, Information Systems, Mathematics, Data Science, or a related field, or possess equivalent work experience that demonstrates the required analytical rigor.
- Bring 5-8 years of work experience in Fraud Analytics across multiple product lines, with a proven ability to own strategy that spans diverse risk surfaces.
- Demonstrate a documented track record of reducing account takeover and scam losses across more than one product line, showing impact through measurable loss reduction.
- Exhibit detailed comfort with the scam taxonomy, including authorized push payment, romance, investment, impostor, remote access, business email compromise, and the shared signals that link these threat vectors.
- Show operational fluency in perimeter defense concepts such as ATO carryover from compromised credentials, account creation abuse, and synthetic identity attacks at funding.
- Possess hands-on experience with device forensics, including shared device-graphs, emulator and VM detection, jailbreak and root signals, and residential-proxy detection.
- Apply advanced SQL and Python skills to build analytics layers, shared feature tables, and rule-level attribution that provide visibility into member risk across the full journey.
- Work effectively with cross-functional stakeholders including EPD, Fraud Ops, InfoSec, and product owners to implement and monitor fraud strategy in production environments.
Practical notes
LENGTH: 700-900 words. No HTML, no markdown, no em dashes. Output the page only.