Staff Cryptography Engineer
SoFi
- Location
- WA - Seattle; UT - Cottonwood Heights; CA - San Francisco; NY - New York City; TX - Frisco
- Work model
- On-Site
- Level
- Staff
- Posted
- 2h ago
Skills
About this role
Employee Applicant Privacy Notice
Who we are
Shape a brighter financial future with us.
Together with our members, we’re changing the way people think about and interact with personal finance.
We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
The role
We are looking for a Staff Cryptography Engineer to help lead SoFi’s enterprise readiness for post-quantum cryptography and long-term cryptographic resilience. This role sits within our Security Assurance organization and will partner closely with security, engineering, infrastructure, product, and business stakeholders to assess, modernize, and strengthen cryptographic controls across the enterprise.
This is a highly cross-functional and strategic role. The ideal candidate brings deep applied cryptography expertise, strong engineering and architecture judgment, and the ability to drive complex security initiatives in ambiguous environments. You will help build SoFi’s cryptographic inventory, identify where cryptographic keys, protocols, algorithms, certificates, and libraries are used, and guide teams through the implementation of quantum-resistant and crypto-agile solutions.
What you'll do
• Lead efforts to assess and improve SoFi’s enterprise cryptographic posture, with a focus on post-quantum cryptography preparedness and crypto-agility.
• Build and maintain an inventory of cryptographic assets, including keys, certificates, algorithms, protocols, libraries, services, and business-critical systems.
• Partner with product, engineering, infrastructure, cloud, and security teams to identify cryptographic dependencies and prioritize remediation or migration needs.
• Provide deep technical guidance on SSL/TLS, PKI, certificates, key management, encryption, cryptographic algorithms, and secure protocol usage.
• Define and document cryptographic standards, design patterns, review gates, and implementation guidance for engineering and product teams.
• Evaluate current and future cryptographic risks, including quantum-resistant key migration, algorithm deprecation, certificate lifecycle management, and insecure implementation patterns.
• Review product and platform architecture designs to identify cryptographic risks and recommend practical, scalable security improvements.
• Translate complex cryptographic concepts into clear guidance, roadmaps, and decision points for technical and non-technical stakeholders.
• Drive cross-functional execution across teams without direct authority, ensuring ownership, timelines, and risk decisions are clearly documented.
• Support security assurance activities, including threat modeling, architecture reviews, control validation, and post-review follow-through.
• Stay current on post-quantum cryptography developments, industry standards, and emerging security guidance, and translate relevant changes into actionable plans for SoFi.
What you'll need
• 8+ years of experience in security engineering, product security, applied cryptography, security architecture, infrastructure security, or a related technical security discipline.
• Experience with post-quantum cryptography, crypto-agility, or cryptographic