Employee Applicant Privacy Notice
Who we are:
Shape a brighter financial future with us.
Together with our members, we’re changing the way people think about and interact with personal finance.
We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
The Role:
We are searching for a Fraud Strategist, Login and Auth to own the perimeter of the SoFi platform. This is a sophisticated role at the intersection of adversarial threat intelligence, device forensics, and real-time decisioning. You will design fraud strategy across login, password reset, MFA, step-up, and high-risk session events, calibrated against the full spectrum of perimeter threats: account takeover (ATO), authorized scams, credential stuffing, MFA bombing, OTP interception, SIM swap, adversary-in-the-middle phishing, and emulator-driven bot traffic. The work requires fluency in device intelligence,, behavioral biometrics, network reputation, and the device-graph forensics needed to attribute risk to entities, not just sessions. You will work cross-functionally with EPD, IAM, Fraud Ops, InfoSec, and partner risk teams to translate signals into production policy that scales across Money, Invest, Crypto, Card, and Lending.
By joining SoFi, you'll become part of a forward-thinking company that is transforming financial services for the better. We offer the excitement of a rapidly growing startup with the stability of an industry leading leadership team.
What You'll Do:
The Fraud Strategist, Login and Auth will help SoFi build a defensible authentication perimeter by:
Owning the end-to-end login risk strategy across web and mobile authentication surfaces: signal selection, rule construction, threshold tuning, champion/challenger lifecycle, and rule-level loss attribution.
Architecting perimeter-threat defense covering ATO, scam interception (authorized push payment, remote access, impostor, investment), MFA bombing, OTP interception, SIM swap, and adversary-in-the-middle phishing. Translate live campaign telemetry into production rule changes within hours
Driving device forensics at depth: device fingerprinting, emulator and VM detection, jailbreak and root signals, residential-proxy detection, and entity-level device-graph analysis to surface coordinated abuse hidden under individually clean sessions.
Designing step-up authentication, account recovery, and high-risk transaction decisioning that synthesizes device, behavioral, network, and credential-risk signals into a single decision, with explicit FPR budgets per surface.
Leading 3DS, CNP, and tokenization risk decisioning for card-not-present transactions, coordinating with issuer processing and network rules to optimize approval rate without ceding losses.
Partnering with InfoSec threat intel on credential-capture campaigns (phishing kits, SEO poisoning, ATO-as-a-service marketplaces) and translating intelligence into rule changes inside the live policy stack.
What You’ll Need:
BA/BS in Statistics, Information Systems, Mathematics, Data Science, or related fields, or equivalent work experience, and 5–8 years of work experience in Fraud Analytics, Authentication Risk, or Adversarial Security Engineering.
ATO and Scam Defense: Demonstrated track record reducing account takeover and scam losses across banking, card, and crypto surfaces. Comfort across the full kill chain: credential exposure, login compromise, in-session manipulation (remote access, screen share, social engineering), and money movement out.
Perimeter Threat Fluency: Operational understanding of credential stuffing, MFA bombing, OTP interception, SIM swap, adversary-in-the-middle phishing, residential-proxy abuse, and emulator-driven automation. You can recognize a campaign in flight from telemetry and respond at the policy layer.
Device Forensics: Hands-on experience with device fingerprinting, emulator and VM detection, jailbreak and root signals, behavioral biometrics, and entity-level device-graph analysis.
Authentication Stack Depth: Working knowledge of FIDO2/passkeys, OAuth/OIDC, 3DS protocol mechanics, tokenization, and the trade-offs between approval rate and chargeback exposure on CNP flows.
Balance Friction and Growth: Deep mastery of evaluating trade-offs between fraud mitigation and UX. You can articulate why a 50 bps lift in challenge rate is or is not worth the loss avoidance, with the data to back it.
Architect Scalable Data Systems: Expert-level SQL/Python skills used to build automated, high-volume data architectures and statistical models that serve as the foundation for global risk detection.
Drive Strategic Influence: A proactive operator who uses cross-functional persuasion to align EPD, IAM, InfoSec, and Fraud Ops on policy changes, and owns end-to-end execution in fluid environments.
Founders’ Mentality: You need to have a positive, proactive attitude, being able to identify problems, raise proposals, and be an advocate of your initiatives. Learn, iterate, and excel.
Skills Required
- BA/BS in Statistics, Information Systems, Mathematics, Data Science, or related field, or equivalent experience, plus 5-8 years in Fraud Analytics, Authentication Risk, or Adversarial Security Engineering
- Demonstrated track record reducing account takeover and scam losses across banking, card, or crypto products
- Operational knowledge of credential stuffing, MFA bombing, OTP interception, SIM swap, adversary-in-the-middle phishing, and emulator-driven automation
- Hands-on experience with device forensics: device fingerprinting, emulator/VM detection, jailbreak/root signals, residential-proxy detection, and entity-level device-graph analysis
- Working knowledge of authentication protocols and tooling: FIDO2/passkeys, OAuth/OIDC, 3DS protocol mechanics, and tokenization
- Expert-level SQL and Python skills for building automated, high-volume data architectures and statistical models
- Experience designing step-up authentication, account recovery, and high-risk transaction decisioning with explicit false-positive budgets
- Ability to translate threat intelligence into production policy quickly and influence cross-functional stakeholders (EPD, IAM, InfoSec, Fraud Ops)
- Experience with 3DS, card-not-present (CNP) risk decisioning, and optimizing approval rates versus chargeback exposure
SoFi Compensation & Benefits Highlights
-
Healthcare Strength — Comprehensive medical, dental, and vision plans are paired with mental-health coaching/therapy, EAP access, and wellness programs, with options noted for low or fully covered premiums. Company-paid life and disability insurance further strengthen core protection.
-
Parental & Family Support — Up to 12 weeks fully paid parental leave is complemented by fertility/adoption resources, subsidized back-up child/elder care, caregiver leave, and pet insurance. A 2026 program also matches a new federal $1,000 seed for eligible children’s investment accounts.
-
Leave & Time Off Breadth — Exempt employees have flexible/unlimited vacation alongside early-release “SoFi Fridays,” while non-exempt employees receive generous vacation and sick time. Paid volunteer time and role-appropriate leave options extend time-away coverage.
SoFi Insights
What We Do
SoFi wasn’t built to be a bank. Or a technology company. We were built for one mission: help people achieve financial independence so they can realize their ambitions. Redefining an entire industry isn’t easy work—and it’s not for the faint of heart. It takes a certain kind of team. People with diverse perspectives and expertise, united by a common sense of purpose. People willing to challenge assumptions but always do the right thing. People proving that innovation and responsibility don’t have to compete, but can come together to create something truly unconventional in the world. For the last eight years, we’ve been charting this new path forward. We call it The SoFi Way. At SoFi, we don’t just talk about culture: we live it. The SoFi Way is how we show up every day, how we make decisions, and how we build for our members, clients, and each other.
Why Work With Us
Together with our members, we’re changing the way people think about and interact with personal finance. We’re a next-generation Fintech company using innovative, mobile-first technology to help our members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront.
Gallery
SoFi Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
For the majority of our workforce who work on a hybrid schedule, the in-office requirement is a handful of days per month!


























