Mariner Finance operates a network of over 500 branches across 28 states, managing a loan portfolio exceeding $2 billion for more than 650,000 customers. The company's model centers on providing personal loans up to $25,000 to near-prime borrowers - a customer segment that sits in the credit spectrum between prime and subprime, carrying specific risk profiles and data-handling requirements.
This scale - hundreds of physical locations, a large customer base with sensitive financial data, and a hybrid digital-and-branch operating model - creates a substantial attack surface. The threat environment for a consumer lender of this size involves protecting PII at rest and in transit, defending against credential stuffing and account takeover on customer portals, securing branch endpoints and internal networks, and managing third-party risk across a wide vendor ecosystem. Fraud prevention and regulatory compliance (think GLBA, state-level privacy statutes) are not peripheral concerns here; they're core to the business.
For security practitioners, the draw is concrete: a company that processes high volumes of personal and financial data through both digital channels and a sprawling physical footprint, where the work isn't theoretical. The mandate runs from infrastructure hardening and identity management to application security and incident response, all under the pressure of a regulated financial environment with real money and real customer trust on the line.





