Senior Security Engineer, Application Security

Cacheflow

San Francisco (CA)

On-site

USD 268,000 - 321,000

Full time

6 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Kikoff exists to help millions of people build credit. This role focuses on shaping the Application Security pillar across web, mobile, and API surfaces, driving strategy, sequencing work, and delivering secure code with AI-assisted review.

You will design controls for code written by AI agents and ensure security by default as engineers move fast. You will own authentication and session security, API and mobile app protections, and lead vulnerability management programs to satisfy PCI-DSS, SOC

Qualifications

  • 6+ years in security engineering with hands-on application security experience.
  • Fluency in at least one of Ruby, Python, Go, or TypeScript and comfort reading all of them.
  • Designed and shipped authentication/authorization systems (OAuth/OIDC, MFA, account recovery).
  • Hands-on with modern AppSec tooling (SAST, SCA, DAST, secrets scanning) and CI/CD integration.
  • Experience securing REST/GraphQL APIs and native mobile apps.
  • Experience running a pentest or bug bounty program and working in fintech or regulated environments (PCI-DSS, SOC 2).

Responsibilities

  • Drive the application security roadmap and secure SDLC.
  • Define strategy, sequence work, and drive delivery for security initiatives.
  • Build and enforce secure coding standards and tooling across teams.
  • Own authentication and session security (MFA, recovery, session management).
  • Secure APIs and mobile apps, including authorization models and device protection.
  • Develop AI-assisted review and triage tooling to scale AppSec.

Skills

Security engineering
Application security
Production code writing
Threat modeling
Code review

Tools

SAST
SCA
DAST
Secrets scanning
CI/CD integration

Job description

Kikoff: The Fintech Powering Financial Security at Scale
Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.
We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.

Why Kikoff:

This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.

About the Role

Kikoff exists to help millions of people build credit. That only works if the products they use are safe. This role helps shape the Application Security pillar at Kikoff: how code gets written, reviewed, shipped, and defended across our web, mobile, and API surfaces.

You will drive and help shape the application security roadmap. You define the strategy, sequence the work, and drive it to done. Engineers ship fast here, and increasingly with AI agents writing code alongside them. Your job is to make that speed safe by default.

In This Role, You Will
Drive the Pillar
  • Drive the application security roadmap: secure SDLC, code review, threat modeling, vulnerability management, and the pentest and bug bounty programs.
  • Set the standard for what secure code looks like at Kikoff and build the tooling that enforces it: SAST, SCA, secrets scanning, and dependency policy wired into CI with signal engineers trust.
  • Decide how AI-generated code gets reviewed and gated. Design the controls for a codebase where agents are contributors.
Build & Secure
  • Build paved roads into the frameworks engineers use: authn/authz libraries, input validation, safe defaults for common patterns, so the secure way is the only way most engineers encounter.
  • Own security for our authentication and session layer: MFA design, account recovery, session management, and defenses against credential stuffing and account takeover.
  • Secure our APIs and mobile apps: authorization models, rate limiting, abuse controls, certificate pinning, and secure storage on device.
  • Secure the AI features we ship to customers: prompt injection defenses, tool permission boundaries, and data exposure controls for LLM-backed flows.
Prove It
  • Run the penetration testing and bug bounty programs. Triage, drive remediation, and close the loop with engineering.
  • Build vulnerability management that holds up in front of auditors: defined SLAs, tracked remediation, and evidence that stands on its own for PCI-DSS, SOC 2, and IPO-readiness controls.
  • Threat model new products and major features before they ship, not after.
Enable Engineering
  • Be the security engineer product engineers actually want in their design reviews. Clear answers, fast turnaround, real fixes.
  • Stand up and run a security champions program so AppSec scales past one person.
  • Build internal tooling, including AI-assisted review and triage, that multiplies the team's reach.
Qualifications
  • 6+ years in security engineering with deep, hands-on application security experience: secure code review, threat modeling, vulnerability triage, and remediation at scale
  • You write production code. Fluency in at least one of Ruby, Python, Go, or TypeScript, and comfort reading all of them
  • You have designed and shipped authentication and authorization systems, not just reviewed them. OAuth/OIDC, session management, MFA, account recovery
  • Hands-on with modern AppSec tooling and the judgment to know when it is wrong: SAST, SCA, DAST, secrets scanning, CI/CD integration
  • Experience securing REST/GraphQL APIs and native mobile applications
  • You have run or built a pentest or bug bounty program
  • Comfortable in a fintech regulated environment: PCI-DSS, SOC 2, or similar
Bonus Points
  • Securing LLM-backed product features or agentic workloads in production
  • Fraud and abuse defense: bot detection, credential stuffing mitigation, device signals
  • Security champions or developer education programs you started, not inherited
  • Supply chain security depth: dependency provenance, artifact signing, build integrity
  • Consumer fintech or financial services background
Base Range

$268,000 — $321,000 USD

Equal Employment Opportunity Statement

Kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

Please reference the following for more information.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Application Security New San Francisco
Senior Security Engineer, Application Security New San Francisco

Kikoff • San Francisco (CA)

On-site
USD 268,000 - 321,000
Senior Security Engineer, Data Security
Senior Security Engineer, Data Security

Kikoff • San Francisco (CA)

On-site
USD 268,000 - 321,000
Senior Fullstack Engineer - User Retention & App Ecosystem
Senior Fullstack Engineer - User Retention & App Ecosystem

Kikoff • San Francisco (CA)

Hybrid
USD 244,000 - 292,000
Hybrid work model
SF office three days a week
Senior Frontend Engineer
Senior Frontend Engineer

Kikoff • San Francisco (CA)

On-site
USD 244,000 - 292,000
Staff Detection & Response Engineer
Staff Detection & Response Engineer

Kikoff • San Francisco (CA)

On-site
USD 338,000 - 387,000
Software Engineer - Recent Grad
Software Engineer - Recent Grad

Kikoff • San Francisco (CA)

On-site
USD 149,000 - 182,000
Senior Data Scientist
Senior Data Scientist

Kikoff • San Francisco (CA)

On-site
USD 226,000 - 254,000
Staff Engineer - Web Applications
Staff Engineer - Web Applications

Kikoff • San Francisco (CA)

On-site
USD 307,000 - 352,000
Senior Software Engineer - Product Platform
Senior Software Engineer - Product Platform

Kikoff • San Francisco (CA)

On-site
USD 180,000 - 240,000
Medical, dental, and vision coverage
Meaningful equity in the form of RSUs
20 days of paid time off
+2
Software Engineer - Recent Grad New San Francisco
Software Engineer - Recent Grad New San Francisco

Kikoff • San Francisco (CA), Northern (KY)

On-site
USD 149,000 - 182,000
Hybrid work model