Fraud Strategist - Login and Auth
Quick Summary
The Fraud Strategist,
Shape a brighter financial future with us.
Together with our members, we’re changing the way people think about and interact with personal finance.
We’re a next-generation financial services company and national bank using innovative, mobile-first technology to help our millions of members reach their goals. The industry is going through an unprecedented transformation, and we’re at the forefront. We’re proud to come to work every day knowing that what we do has a direct impact on people’s lives, with our core values guiding us every step of the way. Join us to invest in yourself, your career, and the financial world.
We are searching for a Fraud Strategist, Login and Auth to own the perimeter of the SoFi platform. This is a sophisticated role at the intersection of adversarial threat intelligence, device forensics, and real-time decisioning. You will design fraud strategy across login, password reset, MFA, step-up, and high-risk session events, calibrated against the full spectrum of perimeter threats: account takeover (ATO), authorized scams, credential stuffing, MFA bombing, OTP interception, SIM swap, adversary-in-the-middle phishing, and emulator-driven bot traffic. The work requires fluency in device intelligence,, behavioral biometrics, network reputation, and the device-graph forensics needed to attribute risk to entities, not just sessions. You will work cross-functionally with EPD, IAM, Fraud Ops, InfoSec, and partner risk teams to translate signals into production policy that scales across Money, Invest, Crypto, Card, and Lending.
By joining SoFi, you'll become part of a forward-thinking company that is transforming financial services for the better. We offer the excitement of a rapidly growing startup with the stability of an industry leading leadership team.
Responsibilities
~1 min readThe Fraud Strategist, Login and Auth will help SoFi build a defensible authentication perimeter by:
- →
Owning the end-to-end login risk strategy across web and mobile authentication surfaces: signal selection, rule construction, threshold tuning, champion/challenger lifecycle, and rule-level loss attribution.
- →
Architecting perimeter-threat defense covering ATO, scam interception (authorized push payment, remote access, impostor, investment), MFA bombing, OTP interception, SIM swap, and adversary-in-the-middle phishing. Translate live campaign telemetry into production rule changes within hours
- →
Driving device forensics at depth: device fingerprinting, emulator and VM detection, jailbreak and root signals, residential-proxy detection, and entity-level device-graph analysis to surface coordinated abuse hidden under individually clean sessions.
- →
Designing step-up authentication, account recovery, and high-risk transaction decisioning that synthesizes device, behavioral, network, and credential-risk signals into a single decision, with explicit FPR budgets per surface.
- →
Leading 3DS, CNP, and tokenization risk decisioning for card-not-present transactions, coordinating with issuer processing and network rules to optimize approval rate without ceding losses.
- →
Partnering with InfoSec threat intel on credential-capture campaigns (phishing kits, SEO poisoning, ATO-as-a-service marketplaces) and translating intelligence into rule changes inside the live policy stack.
-
BA/BS in Statistics, Information Systems, Mathematics, Data Science, or related fields, or equivalent work experience, and 5–8 years of work experience in Fraud Analytics, Authentication Risk, or Adversarial Security Engineering.
-
ATO and Scam Defense: Demonstrated track record reducing account takeover and scam losses across banking, card, and crypto surfaces. Comfort across the full kill chain: credential exposure, login compromise, in-session manipulation (remote access, screen share, social engineering), and money movement out.
-
Perimeter Threat Fluency: Operational understanding of credential stuffing, MFA bombing, OTP interception, SIM swap, adversary-in-the-middle phishing, residential-proxy abuse, and emulator-driven automation. You can recognize a campaign in flight from telemetry and respond at the policy layer.
-
Device Forensics: Hands-on experience with device fingerprinting, emulator and VM detection, jailbreak and root signals, behavioral biometrics, and entity-level device-graph analysis.
-
Authentication Stack Depth: Working knowledge of FIDO2/passkeys, OAuth/OIDC, 3DS protocol mechanics, tokenization, and the trade-offs between approval rate and chargeback exposure on CNP flows.
-
Balance Friction and Growth: Deep mastery of evaluating trade-offs between fraud mitigation and UX. You can articulate why a 50 bps lift in challenge rate is or is not worth the loss avoidance, with the data to back it.
-
Architect Scalable Data Systems: Expert-level SQL/Python skills used to build automated, high-volume data architectures and statistical models that serve as the foundation for global risk detection.
-
Drive Strategic Influence: A proactive operator who uses cross-functional persuasion to align EPD, IAM, InfoSec, and Fraud Ops on policy changes, and owns end-to-end execution in fluid environments.
-
Founders’ Mentality: You need to have a positive, proactive attitude, being able to identify problems, raise proposals, and be an advocate of your initiatives. Learn, iterate, and excel.
SoFi provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion (including religious dress and grooming practices), sex (including pregnancy, childbirth and related medical conditions, breastfeeding, and conditions related to breastfeeding), gender, gender identity, gender expression, national origin, ancestry, age (40 or over), physical or medical disability, medical condition, marital status, registered domestic partner status, sexual orientation, genetic information, military and/or veteran status, or any other basis prohibited by applicable state or federal law.
The Company hires the best qualified candidate for the job, without regard to protected characteristics.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
New York applicants: Notice of Employee Rights
SoFi is committed to an inclusive culture. As part of this commitment, SoFi offers reasonable accommodations to candidates with physical or mental disabilities. If you need accommodations to participate in the job application or interview process, please let your recruiter know or email accommodations@sofi.com.
Due to insurance coverage issues, we are unable to accommodate remote work from Hawaii or Alaska at this time.
Location & Eligibility
Listing Details
- Posted
- June 30, 2026
- First seen
- June 30, 2026
- Last seen
- June 30, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 67%
- Scored at
- June 30, 2026
Signal breakdown
Please let Sofi know you found this job on Jobera.
3 other jobs at Sofi
View all →Explore open roles at Sofi.
Similar Strategist jobs
View all →Browse Similar Jobs
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
No spam. Unsubscribe at any time.
