Staff Detection & Response Engineer

Kikoff

San Francisco (CA)

On-site

USD 338,000 - 387,000

Full time

46 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Kikoff in San Francisco is seeking a Senior Security Engineer to own the Detection & Response pillar for our fintech environment. You will shape the detection strategy across AWS, endpoints, identity, SaaS, and CI/CD, and lead incident response lifecycle from triage to remediation, working with on-call playbooks and runbooks.

You will write detections as code, reduce false positives, and build scalable telemetry pipelines.

Qualifications

  • 6+ years in security with detection engineering and incident response in cloud-native environments (AWS preferred).
  • You've written detections yourself: SIEM rules or detection-as-code pipelines, and you've owned the false positive rate that came with them.
  • Hands-on incident response experience leading real incidents, not just participation.
  • Strong command of cloud-native logging and detection surfaces.
  • Experience with EDR at fleet scale and identity-based detection.
  • Fluency in automation languages (Python, Go, Ruby or similar).
  • Comfortable in a fintech regulated environment.

Responsibilities

  • Own the incident response lifecycle: triage, containment, forensics, postmortem, remediation tracking.
  • Lead technical investigations, including insider risk and unauthorized access cases.
  • Design and maintain detection coverage across AWS, endpoints, identity, SaaS and CI/CD; write detections as code.
  • Build audit logging and telemetry pipelines for scalable visibility, including data access monitoring.
  • Develop runbooks, escalation paths, and tabletop exercises to improve incident response.

Skills

Security engineering
Incident response
Cloud-native logging
EDR
Automation with Python/Go/Ruby
Fintech/regulatory experience

Tools

SentinelOne EDR
Okta
AWS CloudTrail
GuardDuty
SIEM
Detection-as-code

Job description

Kikoff: The Fintech Powering Financial Security at Scale

Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.

We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.

Why Kikoff

This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.

Kikoff protects millions of customers and their financial data. This role owns the Detection & Response pillar: how we see what's happening across our environment, how fast we know when something is wrong, and how well we respond when it is.

You will own and dictate the detection and response roadmap. You define the detection strategy, decide what gets built versus bought, and drive the program from 'we have tools' to 'we have coverage we can prove.' This isn't a SOC analyst seat. You're building the detection capability for a fintech handling sensitive financial data, and you'll have real ownership from day one.

In This Role, You Will
Own the Pillar
  • Own the D&R roadmap end to end: telemetry strategy, detection engineering, alert quality, response process, and the metrics that prove coverage
  • Decide our detection architecture. What we log, where it lands, what we build in-house, and where our partner tools fits.
  • Set the bar for signal quality. Kill noisy alerts, tune what stays, and make on-call sustainable
Build Detection
  • Design and maintain detection coverage across AWS (CloudTrail, GuardDuty, VPC flow), endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD
  • Write detections as code: versioned, tested, mapped to real threats against a consumer fintech
  • Build the audit logging and telemetry pipelines that give us visibility at scale, including data access monitoring and detections for AI/agentic activity in our environment
  • Threat model what an attacker actually does to a company like ours, and detect for that, not for a generic MITRE checklist
Run Response
  • Own the incident response lifecycle: triage, containment, forensics, postmortem, remediation tracking
  • Level up our incident process in incident.io: runbooks, severity definitions, escalation paths, tabletop exercises
  • Lead technical investigations, including insider risk and unauthorized access cases
Enable the Team
  • Build and run the InfoSec on-call rotation with real runbooks, not tribal knowledge
  • Automate response where it's safe: enrichment, containment actions, ticket hygiene
  • Be the calm, technical voice in an incident who engineers trust
Qualifications
  • 6+ years in security with meaningful detection engineering and incident response experience in cloud-native environments (AWS strongly preferred)
  • You've written detections yourself: SIEM rules, or detection-as-code pipelines, and you've owned the false positive rate that came with them
  • Hands-on incident response experience. You've led real incidents, not just participated in them
  • Strong command of Cloud Native logging and detection surfaces
  • Experience with EDR at fleet scale and identity-based detection
  • Fluency in at least one language for automation (Python, Go, Ruby, or similar)
  • Comfortable in a fintech regulated environment
Bonus Points
  • You've stood up a detection program from scratch or near-scratch
  • Detections for AI/LLM and agentic system abuse
  • Insider threat and unauthorized access investigation experience
  • Consumer fintech or financial services background
Base Range

$337,700 - $387,200 USD

Equal Employment Opportunity Statement

Kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class. Please reference the following for more information.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Engineering Manager, Infrastructure
Engineering Manager, Infrastructure

Kikoff • San Francisco (CA)

Hybrid
USD 307,000 - 352,000
Hybrid work model
IT Systems Engineer
IT Systems Engineer

Cacheflow • San Francisco (CA)

On-site
USD 190,000 - 240,000
Staff Infrastructure Engineer
Staff Infrastructure Engineer

Socket.dev • San Francisco (CA)

On-site
USD 307,000 - 352,000
Growth Marketer
Growth Marketer

Kikoff • San Francisco (CA)

On-site
USD 120,000 - 145,000
Equity
Benefits
Bank Secrecy Act (BSA) Officer & AML/Sanctions Team Lead
Bank Secrecy Act (BSA) Officer & AML/Sanctions Team Lead

Kikoff • San Francisco (CA)

On-site
USD 120,000 - 200,000
Bank Secrecy Act (BSA) Officer & AML/Sanctions Team Lead
Bank Secrecy Act (BSA) Officer & AML/Sanctions Team Lead

Portage Ventures GP Inc. • San Francisco (CA)

On-site
USD 120,000 - 200,000
Equity
Comprehensive benefits
Engineering Manager: New Initiative
Engineering Manager: New Initiative

Kikoff • San Francisco (CA)

On-site
USD 307,000 - 352,000
Senior Machine Learning Engineer
Senior Machine Learning Engineer

Kikoff • San Francisco (CA)

On-site
USD 244,000 - 292,000
Senior Security Engineer, Data Security
Senior Security Engineer, Data Security

JobCubby • San Francisco (CA), Northern (KY)

Hybrid
USD 268,000 - 321,000
Bank Secrecy Act (BSA) Officer & AML/Sanctions Team Lead
Bank Secrecy Act (BSA) Officer & AML/Sanctions Team Lead

Kikoff • Phoenix (OR)

Hybrid
USD 120,000 - 200,000
Equity
Comprehensive benefits
Hybrid work schedule (SF or Phoenix)