
Sofi · Seattle; CA - San Francisco
Employee Applicant Privacy Notice Who we are: Shape a brighter financial future with us. Together with our members, we’re changing the way people think about...
Employee Applicant Privacy Notice
Shape a brighter financial future with us.
Together with our members, we’re changing the way people think about and interact with personal finance.
We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our
millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront.
We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding
us every step of the way. Join us to invest in yourself, your career, and the financial world.
We are seeking a Cybersecurity Incident Commander to join SoFi’s Cyber Defense program and lead incident command efforts across
the organization. This role will serve as a central driver for security incident response, ensuring effective management of
day-to-day incidents as well as large-scale, high-impact cybersecurity events.
The SOC team is responsible for monitoring, analyzing, and responding to security events across SoFi’s infrastructure and
applications. As a dedicated incident response resource within Cyber Defense, you will coordinate cross-functional response
efforts, maintain incident command structure during active events, and ensure consistent communication, documentation, and
resolution tracking.
This is a highly visible role that partners closely with SOC Analysts, Threat Research, Offensive Security, Tools Automation &
Operations (TAO), Engineering, IT, Legal, Risk, Executive team, and other stakeholders to drive timely containment, eradication,
and recovery. The ideal candidate thrives in fast-paced environments, brings structure to ambiguity, has exceptional communication
skills, and can effectively drive complex incidents from detection through post-incident review.
recovery, and closure.
response.
taken.
business needs and expectations.
capabilities.
or data exfiltration events.
stakeholders.
incidents.
monitoring tools.
Compensation and Benefits
The base pay range for this role is listed below. Final base pay offer will be determined based on individual factors such as the
candidate’s experience, skills, and location.
To view all of our comprehensive and competitive benefits, visit our Benefits at SoFi page!
SOFI PROVIDES EQUAL EMPLOYMENT OPPORTUNITIES (EEO) TO ALL EMPLOYEES AND APPLICANTS FOR EMPLOYMENT WITHOUT REGARD TO RACE, COLOR,
RELIGION (INCLUDING RELIGIOUS DRESS AND GROOMING PRACTICES), SEX (INCLUDING PREGNANCY, CHILDBIRTH AND RELATED MEDICAL CONDITIONS,
BREASTFEEDING, AND CONDITIONS RELATED TO BREASTFEEDING), GENDER, GENDER IDENTITY, GENDER EXPRESSION, NATIONAL ORIGIN, ANCESTRY,
AGE (40 OR OVER), PHYSICAL OR MEDICAL DISABILITY, MEDICAL CONDITION, MARITAL STATUS, REGISTERED DOMESTIC PARTNER STATUS, SEXUAL
ORIENTATION, GENETIC INFORMATION, MILITARY AND/OR VETERAN STATUS, OR ANY OTHER BASIS PROHIBITED BY APPLICABLE STATE OR FEDERAL
THE COMPANY HIRES THE BEST QUALIFIED CANDIDATE FOR THE JOB, WITHOUT REGARD TO PROTECTED CHARACTERISTICS.
PURSUANT TO THE SAN FRANCISCO FAIR CHANCE ORDINANCE, WE WILL CONSIDER FOR EMPLOYMENT QUALIFIED APPLICANTS WITH ARREST AND
SOFI IS COMMITTED TO AN INCLUSIVE CULTURE. AS PART OF THIS COMMITMENT, SOFI OFFERS REASONABLE ACCOMMODATIONS TO CANDIDATES WITH
PHYSICAL OR MENTAL DISABILITIES. IF YOU NEED ACCOMMODATIONS TO PARTICIPATE IN THE JOB APPLICATION OR INTERVIEW PROCESS, PLEASE LET
DUE TO INSURANCE COVERAGE ISSUES, WE ARE UNABLE TO ACCOMMODATE REMOTE WORK FROM HAWAII OR ALASKA AT THIS TIME.
Internal Employees
If you are a current employee, do not apply here - please navigate to our Internal Job Board in Greenhouse to apply to our open
roles.
GitLab is the intelligent orchestration platform for DevSecOps. GitLab enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and accelerate digital transformation. More than 50 million registered users and more than 50% of the Fortune 100* trust GitLab to ship better, more secure software faster. The same principles built into our products are reflected in how our team works: we embrace AI as a core productivity multiplier, with all team members expected to incorporate AI into their daily workflows to drive efficiency, innovation, and impact. GitLab is where careers accelerate, innovation flourishes, and every voice is valued. Our high-performance culture is driven by our values and continuous knowledge exchange, enabling our team members to reach their full potential while collaborating with industry leaders to solve complex problems. Co-create the future with us as we build technology that transforms how the world develops software. *Fortune 500® is a registered trademark of Fortune Media IP Limited, used under license. Claim based on GitLab data. Fortune 100 refers to the top 20% ranked companies in the 2025 Fortune 500 list, published in June 2025. Fortune and Fortune Media IP Limited are not affiliated with, and do not endorse products or services of GitLab. AN OVERVIEW OF THIS ROLE We’re looking for a manager to lead the GitLab security incident response team (SIRT) in the Americas region. GitLab SIRT manages and investigates cybersecurity incidents across all GitLab operating environments and operates in a tierless SOC model. The team is responsible for threat hunting, alert triage, security investigations, deep-dive DFIR, and large-scale incident response, among other responsibilities. In this role, you will manage the day-to-day work of a team of incident response engineers - setting clear performance expectations, coaching their growth, and holding the team accountable for delivering quality results. You should have a strong technical background, be comfortable owning the full incident lifecycle from alert triage to retrospective actions, and be skilled at developing others to do the same. We are looking for someone who makes sound operational decisions under pressure and who actively looks for opportunities to "shift left" - improving defenses and leveraging AI and automation to optimize team workflows. You will implement program direction, maintain a culture of high performance, and defend GitLab infrastructure and products including GitLab.com, GitLab Dedicated, and GitLab Dedicated for Government (FedRAMP). This role requires availability during US West Coast business hours. Candidates based on the West Coast are preferred, though candidates in other time zones who are comfortable working these hours are also welcome to apply. Some after-hours and weekend coverage may be required to support engineers during high-severity incidents. Learn more about the Security Operations Department: * Security Incident Response Team * Trust and Safety Team * Security Logging Team * Red Team * Signals Engineering Team WHAT YOU'LL DO * Manage day-to-day team operations - establish clear goals, performance expectations, and accountability for direct reports; monitor progress and ensure timely delivery of quality results. * Develop and coach incident responders - provide candid, real-time feedback; advise on career growth; and foster a culture of investigation excellence, prioritizing depth and accuracy of analysis. * Proactively identify and fill talent gaps - participate in hiring decisions with a focus on candidates who will amplify GitLab's values and raise the team's technical bar. * Drive engagement and retention - recognize team member contributions, address engagement risks early, and create an environment of open feedback and psychological safety. * Cascade organizational context - translate division and company-wide strategy into clear, actionable team priorities; keep team members informed in a timely manner. * Implement and mature incident response processes - build and improve runbooks, procedures, and team capabilities that translate functional plans into tactical execution. * Lead incident response - serve as an escalation point and incident commander for high-severity events, including occasional nights and weekends; model the standard for quality investigations. * Enable cross-functional collaboration - coordinate effectively with peer SecOps teams, Legal, Customer Support, and Infrastructure to resolve incidents and close defense gaps through actionable retrospective mitigations. * Align the team on defensive improvements - drive insights from alerts, investigations, and incidents to improve GitLab's security posture and support a "shift left" mindset. * Champion remote-first practices - consistently model and coach team members on GitLab's remote working best practices, async communication norms, and handbook-first culture. WHAT YOU'LL BRING * Proven people management experience - track record of managing and developing a team of security engineers, setting performance expectations, providing coaching, and driving accountability for results. * Incident response leadership - demonstrated experience leading complex incident response operations, including large-scale incident coordination and the full lifecycle from triage to retrospective. * Hands-on technical background - experience conducting security investigations and log analysis using SIEM tools (e.g., Splunk, Elastic); working knowledge of GCP and/or AWS, including cloud forensics. * Customer-facing credibility - comfortable representing GitLab Security during customer escalations and high-visibility cybersecurity discussions. * Proactive hunting and threat intelligence - proficiency in threat hunting based on intelligence, and familiarity with supply chain threats targeting SaaS platforms. * AI and automation mindset - experience using AI/LLMs to improve incident response workflows and automate repetitive processes. * Platform familiarity - experience using GitLab (or a comparable DevSecOps platform) for project tracking; bonus if you have experience responding to threats against a SaaS platform. * Prioritization under pressure - ability to make sound operational decisions quickly, escalate issues cleanly, and guide the team on balancing what is urgent versus what is important. Due to government requirements, you must be a United States Citizen (defined as any individual who is a citizen of the United States by law, birth, or naturalization) to fill this position. ABOUT THE TEAM The Security Incident Response Team is a globally distributed team of incident response engineers split across three core regions; AMER, APAC and EMEA, and is at the forefront of security events that impact both GitLab’s products and company. We are both proactive and reactive, responding to security alerts, leading security investigations, conducting threat hunts and collaborating with peer Security Operations teams to conduct purple teaming exercises, build threat detections, improve security telemetry and investigate trending threats. Even though we’re a global team, we work together in a cross-regional manner and have automation and processes to facilitate collaboration when resolving incidents, handovers, and general collaboration for project work as well. The base salary range for this role’s listed level is currently for residents of the United States only. This range is intended to reflect the role's base salary rate in locations throughout the US. Grade level and salary ranges are determined through interviews and a review of education, experience, knowledge, skills, abilities of the applicant, equity with other team members, alignment with market data, and geographic location. The base salary range does not include any bonuses, equity, or benefits. See more information on our benefits and equity. Sales roles are also eligible for incentive pay targeted at up to 100% of the offered base salary. United States Salary Range $150,000—$235,000 USD HOW GITLAB SUPPORTS FULL-TIME EMPLOYEES * Benefits to support your health, finances, and well-being * Flexible Paid Time Off * Team Member Resource Groups * Equity Compensation & Employee Stock Purchase Plan * Growth and Development Fund * Parental Leave Please note that we welcome interest from candidates with varying levels of experience; many successful candidates do not meet every single requirement. Additionally, studies have shown that people from underrepresented groups are less likely to apply to a job unless they meet every single qualification. If you're excited about this role, please apply and allow our recruiters to assess your application. ---------------------------------------------------------------------------------------------------------------------------------- Country Hiring Guidelines: GitLab hires new team members in countries around the world. All of our roles are remote, however some roles may carry specific location-based eligibility requirements. Our Talent Acquisition team can help answer any questions about location after starting the recruiting process. Privacy Policy: Please review our Recruitment Privacy Policy. Your privacy is important to us. GitLab is proud to be an equal opportunity workplace and is an affirmative action employer. GitLab’s policies and practices relating to recruitment, employment, career development and advancement, promotion, and retirement are based solely on merit, regardless of race, color, religion, ancestry, sex (including pregnancy, lactation, sexual orientation, gender identity, or gender expression), national origin, age, citizenship, marital status, mental or physical disability, genetic information (including family medical history), discharge status from the military, protected veteran status (which includes disabled veterans, recently separated veterans, active duty wartime or campaign badge veterans, and Armed Forces service medal veterans), or any other basis protected by law. GitLab will not tolerate discrimination or harassment based on any of these characteristics. See also GitLab’s EEO Policy and EEO is the Law. If you have a disability or special need that requires accommodation, please let us know during the recruiting process.
Lead with Purpose. Partner with Impact. We are seeking a Director of Observability to stand up a brand-new observability and reliability practice from the ground up at Kestra Holdings. This is a working leadership role — the Director will be expected to be hands-on in the early phase: selecting and configuring tooling, writing instrumentation standards, building the first dashboards and alerting pipelines, and personally running incident command for major events while the team and platform mature. This is a newly created leadership role reporting directly to the Head of IT Infrastructure & Cybersecurity. The Director will start with two direct reports — a to be hired Senior Observability Architect (India-based) and a future US-based Observability/Reliability Engineer — and will be expected to scale the team over time as the practice and service catalog grow. What you’ll Do: * Observability Strategy & Platform Hands-On Build-Out. * Define and execute the observability strategy for Kestra Holdings, aligned with business objectives, regulatory requirements, and the enterprise technology roadmap. * Personally lead the initial build-out of the observability platform across metrics, logs, traces, profiles, and alerting — including tool evaluation, POCs, architecture, deployment, and configuration (e.g., Azure Monitor/Log Analytics, Datadog, Grafana, OpenTelemetry, Elastic/Splunk). * Work with and enforce existing instrumentation standards (OpenTelemetry, structured logging, distributed tracing) across infrastructure and application teams. * Build the first generation of dashboards, SLO scorecards, and a single pane of glass for Tier-1 service health — rolling up sleeves alongside the Sr. Architect and engineer. * Operate the firm's end-to-end incident management lifecycle — detection, response, escalation, communication, and blameless post-incident review. * Stand up on-call schedules, escalation policies, and runbook-driven triage for Sev1–Sev4 incidents via PagerDuty/xMatters or equivalent. * Serve as primary incident commander for major incidents during the initial build phase, transitioning command responsibilities to senior team members as the practice matures. * Integrate the incident lifecycle with Jira / Jira Service Management (JSM) for ticketing, change correlation, and remediation tracking; partner with Cybersecurity so incidents run once, not separately by Infra and Cyber * Facilitate post-incident reviews (PIRs), track remediation items in Jira, and report trends to leadership. * Drive adoption of SRE principles across the firm: SLI/SLO definition, error budget policy and enforcement, toil identification and automation, and operational readiness reviews. * Establish release of reliability gates and embed reliability into the service lifecycle from design through production. * Partner with Cloud & Platform Engineering, Cybersecurity, and application teams to ensure all services are fully instrumented, measurable, and integrated into the firm's SLO and incident frameworks. * Ensure observability and incident management practices align with NIST CSF 2.0 maturity targets and support the firm's cybersecurity roadmap. * Partner with the Cybersecurity team to integrate observability data with Jira/JSM, CMDB, and SIEM for enriched context during incidents. * Support regulatory and audit requirements appropriate for a SEC-regulated financial services firm (e.g., logging retention, evidentiary integrity, access controls on telemetry data). * Directly lead and mentor a small, high-leverage team of two to start: a Senior Observability Architect (India-based) and a US-based Observability/Reliability Engineer. * Operate as a player-coach — splitting time between strategic leadership, hands-on engineering, and direct mentorship of the senior architect. * Build a multi-year workforce plan and talent pipeline to scale the team as the platform, service catalog, and 24/7 coverage needs grow. * Foster a culture of blameless learning, operational excellence, and engineering-led reliability across US and India hours of coverage. * Serve as the primary technical liaison for observability and incident management vendors (e.g., Datadog, PagerDuty/xMatters, Grafana Labs, Elastic/Splunk, Atlassian). * Represent Observability & Reliability in the Architecture Review Board, IT Change Management Board, and incident command forums. * Provide regular reporting to SVP and executive leadership on reliability KPIs (MTTD, MTTA, MTTR, SLO compliance, alert signal-to-noise), incident trends, and strategic initiatives. What You Bring: * 10+ years in observability, SRE, platform engineering, or infrastructure operations roles, with 3+ years in a people leadership capacity (Director or Sr. Manager level). * Demonstrated experience building an observability or SRE practice from scratch — tool selection, instrumentation rollout, first SLOs, and standing up incident command. * Strong hands-on technical depths must be willing and able to write code/IaC, configure platforms, build dashboards, and run incidents personally, not just delegate. * Deep expertise across the observability stack: metrics (Prometheus, Datadog, Azure Monitor), log aggregation (Elastic/OpenSearch, Log Analytics, Splunk), distributed tracing (OpenTelemetry, Jaeger, Datadog APM), and profiling. * Proven experience defining SLIs/SLOs, error budgets, and toil reduction programs. * Hands-on experience with incident management platforms (PagerDuty, xMatters) and Jira / Jira Service Management integration for ticketing and workflow. * Experience leading distributed teams across US and India time zones. * Experience operating in a regulated industry (financial services, healthcare, or similar) with familiarity with compliance frameworks (NIST CSF, SOC 2, SEC, FINRA). * Excellent communication skills — able to present reliability posture, incident retrospectives, and risk to executive and board-level audiences. * Experience with IaC (Terraform, Bicep, ARM), CI/CD pipelines, and embedding observability-as-code into modern DevOps practices.
About Zscaler Zscaler accelerates digital transformation to ensure our customers can be more agile, efficient, resilient, and secure. As an AI-forward enterprise, we are constantly pushing the envelope, leveraging the world’s largest security data lake to power our cloud-native Zero Trust Exchange platform. This innovation protects our customers from cyberattacks and data loss by securely connecting users, devices, and applications in any location. Here, impact in your role matters more than title and trust is built on results. We say, impact over activity. We seek innovators who actively use AI to amplify their impact and who thrive in an environment where we leverage intelligent systems to stay ahead of evolving threats. We believe in transparency and value constructive, honest debate—we’re focused on getting to the best ideas, faster. We build high-performing teams that can make an impact quickly and with high quality. To do this, we are building a culture of execution centered on customer obsession, collaboration, ownership, and accountability. We value high-impact, high-accountability with a sense of urgency where you’re enabled to do your best work and embrace your potential. If you’re driven by purpose, thrive on solving complex challenges, and want to be part of the team that’s helping to secure the AI age, we invite you to bring your talents to Zscaler and help shape the future of cybersecurity. Role We are looking for a Production Engineer to join our team. This role is available as a hybrid opportunity 3 days a week in San Jose, CA or Remote reporting to Production Engineering in the Cloud Infrastructure & Operations department. Join Zscaler to be a force multiplier for the reliability of a global platform processing 200+ billion transactions daily across tens of millions of enterprise users. In this role, you will provide the technical vision and hands-on execution to drive an "automation-first" culture across the company. By maturing our observability and architectural standards, you will directly reduce our Mean Time to Mitigate (MTTM) and shape the scalability of our globally distributed, multi-cloud infrastructure. What you’ll do (Role Expectations) * Implement highly available, scalable infrastructure across AWS, GCP, and bare-metal environments * Drive an "automation-first" culture by writing code (Python/Go) to eliminate manual toil and build self-healing systems * Implement and maintain sophisticated observability (Prometheus, Grafana, OpenTelemetry), define SLIs/SLOs, and establish error budgets * Act as a lead Incident Commander (TDO on-call), develop response playbooks, and conduct deep-dive post-incident analyses * Partner with Engineering and partner teams to conduct operability reviews Who You Are (Success Profile) * You act like an owner with a bias for action and integrity. * You are a pragmatic builder obsessed with creating, iterating, and shipping. * You champion simplicity by distilling complex problems into clear, actionable plans. * You are data-driven, valuing evidence over assumptions. * You think at scale, building solutions and processes built to last a high-growth global organization. What We’re Looking for (Minimum Qualifications) * Demonstrated curiosity and active exploration of AI tools, with a proven history of integrating new technologies to enhance daily workflows and augment problem-solving * 1-3 years of experience managing reliability, scalability, and availability for large-scale production services * Deep expertise in programming (e.g., Python, Go, or C/C++) * Strong background in networking protocols, Linux/RHEL systems, and distributed architecture * Experience in high-stakes incident management and participation in a 24/7 on-call rotation * Proficiency in leveraging ITIL frameworks and incident data to drive service maturity through systematic problem management and technical operability reviews What Will Make You Stand Out (Preferred Qualifications) * Extensive experience with public cloud (AWS, Azure, GCP) and Infrastructure-as-Code (Ansible, Terraform, Helm, Temporal) * Experience with chaos engineering and disaster recovery planning at scale * Expertise in global routing (BGP) and traffic tunneling (GRE, IPSec) with a deep understanding of L7 proxy architectures (HAProxy), DNS at scale, and OS networking stack internals #LI-AJ1 #LI-Hybrid Zscaler’s salary ranges are benchmarked and are determined by role and level. The range displayed on each job posting reflects the minimum and maximum target for new hire salaries for the position across all US locations and could be higher or lower based on a multitude of factors, including job-related skills, experience, and relevant education or training. The base salary range listed for this full-time position excludes commission/ bonus/ equity (if applicable) + benefits. Base Pay Range $102,400—$128,000 USD At Zscaler, we are committed to building a team that reflects the communities we serve and the customers we work with. We foster an inclusive environment that values all backgrounds and perspectives, emphasizing collaboration and belonging. Join us in our mission to make doing business seamless and secure. Our Benefits program is one of the most important ways we support our employees. Zscaler proudly offers comprehensive and inclusive benefits to meet the diverse needs of our employees and their families throughout their life stages, including: * Various health plans * Time off plans for vacation and sick time * Parental leave options * Retirement options * Education reimbursement * In-office perks, and more! Learn more about Zscaler's hybrid working model and benefits here. By applying for this role, you adhere to applicable laws, regulations, and Zscaler policies, including those related to security and privacy standards and guidelines. Zscaler is committed to providing equal employment opportunities to all individuals. We strive to create a workplace where employees are treated with respect and have the chance to succeed. All qualified applicants will be considered for employment without regard to race, color, religion, sex (including pregnancy or related medical conditions), age, national origin, sexual orientation, gender identity or expression, genetic information, disability status, protected veteran status, or any other characteristic protected by federal, state, or local laws. See more information by clicking on the Know Your Rights: Workplace Discrimination is Illegal link. Pay Transparency Zscaler complies with all applicable federal, state, and local pay transparency rules. Zscaler is committed to providing reasonable support (called accommodations or adjustments) in our recruiting processes for candidates who are differently abled, have long term conditions, mental health conditions or sincerely held religious beliefs, or who are neurodivergent or require pregnancy-related support.