Senior Security Engineer, Data Security

Kikoff

San Francisco (CA)

On-site

USD 268,000 - 321,000

Full time

42 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Kikoff is seeking a data security leader to own and drive the data security pillar across our stack. You will define strategy, set roadmaps, and ensure secure handling of sensitive data as we scale.

Your work will impact engineers and customers alike, shaping encryption, access controls, and audit visibility. You will collaborate with Legal, Compliance, and Engineering to implement scalable, auditable security controls, including AI data access safeguards and tokenization strategies.

Qualifications

  • 6+ years in security engineering with hands-on data security: encryption, tokenization, access control design, key management.
  • Strong command of AWS security primitives (IAM, KMS, S3 security, VPC controls).
  • Experience securing a modern data stack: Snowflake or a comparable warehouse, plus relational databases in production.
  • You've designed and shipped access control systems, not just configured them. Row/column-level security, ABAC/RBAC, access brokering.
  • Fluency in at least one language for automation (Python, Go, Ruby, or similar).
  • Hands-on with infrastructure-as-code (Terraform or Pulumi).

Responsibilities

  • Own the data security roadmap end to end: classification, access controls, encryption, tokenization, and data flow security across AWS, Snowflake, and internal pipelines.
  • Define and enforce access controls for AI agents to guarantee least privilege permissions and proper audibility.
  • Build audit logging and data access monitoring that holds up in front of auditors and regulators, not just dashboards.
  • Partner with Legal and Compliance on data handling requirements, and translate them into infrastructure, not policy docs.

Skills

Security engineering
AWS security
Access control design
Data security
Automation scripting
IaC (Terraform/Pulumi)

Tools

Snowflake
Terraform
Pulumi

Job description

Kikoff: The Fintech Powering Financial Security at Scale

Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.


We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.


Why Kikoff

This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.


About The Role

Kikoff exists to help millions of people build credit. That only works if they trust us with their financial data. This role owns the Data Security pillar at Kikoff: how data is classified, accessed, encrypted, moved, and audited across our entire stack.


You will own and dictate the data security roadmap. You define the strategy, sequence the work, and drive it to done. Your work will be felt by every engineer at Kikoff and every customer we serve, and it will shape how we handle sensitive data as we scale.


In This Role, You Will

Own the Pillar

  • Own the data security roadmap end to end: classification, access controls, encryption, tokenization, and data flow security across AWS, Snowflake, and our internal pipelines.
  • Set the strategy for how humans, services, and AI agents access sensitive data. You decide what good looks like and build towards it.
  • Drive least-privilege access at scale, including brokered access patterns for our data warehouse and production databases rather than standing credentials.

Build & Secure

  • Design and ship tokenization and field-level protection for our most sensitive data
  • Build column-level and role-based access controls across Snowflake and RDS, with audit visibility into who touched what and why
  • Secure data flows between cloud storage, pipelines, and application services so the secure path is the default path
  • Define and enforce access controls for AI agents to guarantee least privilege permissions and proper audibility.

Prove It

  • Build audit logging and data access monitoring that holds up in front of auditors and regulators, not just dashboards
  • Support data mapping and privacy engineering work for new markets and regulatory regimes (GLBA, LGPD, state privacy laws)
  • Partner with Legal and Compliance on data handling requirements, and translate them into infrastructure, not policy docs

Enable Engineering

  • Give engineers paved roads for handling sensitive data: reusable patterns, clear guidance, fast answers
  • Threat model new data flows before they ship, not after

Qualifications

  • 6+ years in security engineering with deep, hands‑on data security experience: encryption, tokenization, access control design, key management
  • Strong command of AWS security primitives (IAM, KMS, S3 security, VPC controls)
  • Experience securing a modern data stack: Snowflake or a comparable warehouse, plus relational databases in production

  • You\'ve designed and shipped access control systems, not just configured them. Row/column-level security, ABAC/RBAC, access brokering
  • Fluency in at least one language for automation (Python, Go, Ruby, or similar)
  • Comfortable in a regulated environment
  • Hands‑on with infrastructure-as-code (Terraform or Pulumi)

Bonus Points

  • Experience securing data access for AI/LLM systems and agentic workloads
  • Tokenization at scale in fintech or payments
  • Audit logging and data access monitoring you built yourself, not bought
  • Privacy engineering depth: data mapping, retention, deletion pipelines, cross-border transfer controls
  • Consumer fintech or financial services background

Base Range

$268,000 - $321,000 USD


Equal Employment Opportunity Statement

Kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.


Please reference the following for more information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Detection & Response Engineer
Staff Detection & Response Engineer

Kikoff • San Francisco (CA)

On-site
USD 338,000 - 387,000
Engineering Manager, Infrastructure
Engineering Manager, Infrastructure

Kikoff • San Francisco (CA)

Hybrid
USD 307,000 - 352,000
Hybrid work model
IT Systems Engineer
IT Systems Engineer

Cacheflow • San Francisco (CA)

On-site
USD 190,000 - 240,000
Staff Infrastructure Engineer
Staff Infrastructure Engineer

Socket.dev • San Francisco (CA)

On-site
USD 307,000 - 352,000
Software Engineer - Recent Grad New San Francisco
Software Engineer - Recent Grad New San Francisco

Kikoff • San Francisco (CA), Northern (KY)

On-site
USD 149,000 - 182,000
Hybrid work model
Senior Machine Learning Engineer
Senior Machine Learning Engineer

Kikoff • San Francisco (CA)

On-site
USD 244,000 - 292,000
Senior HRBP
Senior HRBP

Cacheflow • San Francisco (CA)

On-site
USD 170,000 - 210,000
Medical, dental, vision coverage at no cost for employees
Stock options
Visa sponsorship available
Growth Marketer
Growth Marketer

Kikoff • San Francisco (CA)

On-site
USD 120,000 - 145,000
Equity
Benefits
Senior Frontend Engineer
Senior Frontend Engineer

Kikoff • San Francisco (CA)

On-site
USD 244,000 - 292,000
Senior HRBP
Senior HRBP

Kikoff Inc. • San Francisco (CA)

On-site
USD 170,000 - 210,000
Full medical coverage for employees
50% coverage for dependents
RSUs