Staff Cryptography Engineer
SoFi · New York, NY · 2 days ago
EngineeringFull-time
About the role
We are seeking a Staff Cryptography Engineer to support SoFi's enterprise readiness for post-quantum cryptography and long-term cryptographic resilience. This role is within our Security Assurance team and will collaborate with various departments to assess, modernize, and enhance cryptographic controls across the organization.
Responsibilities
- Lead efforts to assess and improve SoFi’s enterprise cryptographic posture, focusing on post-quantum cryptography preparedness and crypto-agility.
- Build and maintain an inventory of cryptographic assets, including keys, certificates, algorithms, protocols, libraries, services, and business-critical systems.
- Partner with product, engineering, infrastructure, cloud, and security teams to identify cryptographic dependencies and prioritize remediation or migration needs.
- Provide deep technical guidance on SSL/TLS, PKI, certificates, key management, encryption, cryptographic algorithms, and secure protocol usage.
- Define and document cryptographic standards, design patterns, review gates, and implementation guidance for engineering and product teams.
- Evaluate current and future cryptographic risks, including quantum-resistant key migration, algorithm deprecation, certificate lifecycle management, and insecure implementation patterns.
- Review product and platform architecture designs to identify cryptographic risks and recommend practical, scalable security improvements.
- Translate complex cryptographic concepts into clear guidance, roadmaps, and decision points for technical and non-technical stakeholders.
- Drive cross-functional execution across teams without direct authority, ensuring ownership, timelines, and risk decisions are clearly documented.
- Support security assurance activities, including threat modeling, architecture reviews, control validation, and post-review follow-through.
- Stay current on post-quantum cryptography developments, industry standards, and emerging security guidance, and translate relevant changes into actionable plans for SoFi.
Requirements
- 8+ years of experience in security engineering, product security, applied cryptography, security architecture, infrastructure security, or a related technical security discipline.
- Experience with post-quantum cryptography, crypto-agility, or cryptographic migration planning.
- Deep hands-on expertise in applied cryptography, including cryptographic algorithms, secure protocol design (e.g., SSL/TLS, mTLS, M2M), and the practical implementation and lifecycle management of enterprise-grade solutions such as HSMs, KMS, secrets management, and PKI programs.
- Experience assessing or designing cryptographic controls in production engineering environments, including cloud, distributed systems, services, APIs, or enterprise platforms.
- A strong understanding of public cloud environments and how cryptographic controls are implemented across infrastructure, applications, services, and data flows.
- Ability to review technical architecture and identify practical cryptographic risks, implementation gaps, and secure design alternatives.
- Experience creating or driving security standards, technical guidance, inventories, roadmaps, or enterprise-wide security initiatives.
- Strong communication skills, with the ability to explain complex cryptographic concepts to engineering, product, security, risk, and business stakeholders.
- Demonstrated ability to operate independently in ambiguous problem spaces and drive cross-functional work from discovery through execution.
- Strong project ownership and prioritization skills, including the ability to identify stakeholders, define milestones, document decisions, and manage follow-through.
Qualifications
- Bachelor’s degree in computer science, cybersecurity, engineering, mathematics, or a related field, or equivalent practical experience.
Skills
- Experience in financial services, fintech, banking, payments, cloud, SaaS, or other highly regulated technical environments.
- Familiarity with NIST, FIPS, PCI, or other security and cryptographic standards relevant to financial services.
- Experience partnering with product security, application security, infrastructure, platform engineering, or enterprise architecture teams.
- Experience building or leading cryptographic inventories, key-management programs, or encryption modernization efforts.
- Advanced degree or specialized training in cryptography, computer science, mathematics, or information security.
- Experience mentoring security engineers or influencing security architecture practices across multiple teams.
Benefits
To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!