Kikoff Logo

Kikoff

Staff Detection & Response Engineer

Posted 10 Days Ago
Be an Early Applicant
Hybrid
San Francisco, CA, USA
338K-387K Annually
Senior level
Hybrid
San Francisco, CA, USA
338K-387K Annually
Senior level
Own Kikoff’s detection and response program for a fintech environment. Responsibilities include setting the security telemetry and detection roadmap, building detection-as-code coverage across AWS, endpoints, identity, SaaS, and CI/CD, improving alert quality, managing incident response, leading investigations, creating runbooks and on-call processes, and automating safe response actions. The role also includes audit logging, insider-risk investigations, incident postmortems, and detection of AI or agentic system abuse.
The summary above was generated by AI

Kikoff: The Fintech Powering Financial Security at Scale
Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.
We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.


Why Kikoff:

This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.

Kikoff protects millions of customers and their financial data. This role owns the Detection & Response pillar: how we see what's happening across our environment, how fast we know when something is wrong, and how well we respond when it is.

You will own and dictate the detection and response roadmap. You define the detection strategy, decide what gets built versus bought, and drive the program from "we have tools" to "we have coverage we can prove." This isn't a SOC analyst seat. You're building the detection capability for a fintech handling sensitive financial data, and you'll have real ownership from day one.

In This Role, You WillOwn the Pillar
  • Own the D&R roadmap end to end: telemetry strategy, detection engineering, alert quality, response process, and the metrics that prove coverage
  • Decide our detection architecture. What we log, where it lands, what we build in-house, and where our partner tools fits.
  • Set the bar for signal quality. Kill noisy alerts, tune what stays, and make on-call sustainable
Build Detection
  • Design and maintain detection coverage across AWS (CloudTrail, GuardDuty, VPC flow), endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD
  • Write detections as code: versioned, tested, mapped to real threats against a consumer fintech
  • Build the audit logging and telemetry pipelines that give us visibility at scale, including data access monitoring and detections for AI/agentic activity in our environment
  • Threat model what an attacker actually does to a company like ours, and detect for that, not for a generic MITRE checklist
Run Response
  • Own the incident response lifecycle: triage, containment, forensics, postmortem, remediation tracking
  • Level up our incident process in incident.io: runbooks, severity definitions, escalation paths, tabletop exercises
  • Lead technical investigations, including insider risk and unauthorized access cases
Enable the Team
  • Build and run the InfoSec on-call rotation with real runbooks, not tribal knowledge
  • Automate response where it's safe: enrichment, containment actions, ticket hygiene
  • Be the calm, technical voice in an incident who engineers trust
Qualifications
  • 6+ years in security with meaningful detection engineering and incident response experience in cloud-native environments (AWS strongly preferred)
  • You've written detections yourself: SIEM rules, or detection-as-code pipelines, and you've owned the false positive rate that came with them
  • Hands-on incident response experience. You've led real incidents, not just participated in them
  • Strong command of Cloud Native logging and detection surfaces
  • Experience with EDR at fleet scale and identity-based detection
  • Fluency in at least one language for automation (Python, Go, Ruby, or similar)
  • Comfortable in a fintech regulated environment
Bonus Points
  • You've stood up a detection program from scratch or near-scratch
  • Detections for AI/LLM and agentic system abuse
  • Insider threat and unauthorized access investigation experience
  • Consumer fintech or financial services background

Base Range
$337,700$387,200 USD

Equal Employment Opportunity Statement

Kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

Please reference the following for more information.

HQ

Kikoff San Francisco, California, USA Office

We’re headquartered in the Financial District of San Francisco where public transit is just a short walk away at Embarcadero Station.

Similar Jobs

24 Days Ago
Hybrid
2 Locations
171K-303K Annually
Expert/Leader
171K-303K Annually
Expert/Leader
Automotive
Lead cross-functional initiatives to mature cloud and enterprise detection infrastructure, including telemetry pipelines, detection-as-code, logging, and scalable coverage. Design and tune detections for cloud, identity, endpoint, SaaS, CI/CD, and service-to-service threats. Conduct threat hunting, support incident response and on-call operations, apply threat intelligence and adversary emulation, mentor SOC engineers, and improve detection capabilities based on incident lessons learned.
Top Skills: Ci/CdDetection-As-CodeEdrIso 27001Mitre Att&CkNist CsfPythonSecurity Data LakesSIEMSoc 2Zero Trust Architecture
One Month Ago
In-Office
San Ramon, CA, USA
205K-256K Annually
Senior level
205K-256K Annually
Senior level
Software
Lead architecture and execution of detection and response capabilities across AWS and broader infrastructure. Build AI-augmented detection/triage pipelines, design SIEM/SOAR ingestion and alerting frameworks, drive incident response for high-impact events, close detection gaps, mentor engineers, and set team standards for responsible AI usage.
Top Skills: Ai/LlmAlerting PipelinesAmazon CloudwatchAmazon GuarddutyAthenaAws CloudtrailAws LambdaCi/CdDetection-As-CodeEcsEksIam AnalysisKotlinLlm AgentsMitre Att&CkPythonSIEMSoarTerraformTypescriptVpc Flow Logs
One Month Ago
In-Office
Menlo Park, CA, USA
217K-255K Annually
Senior level
217K-255K Annually
Senior level
Fintech • Cryptocurrency
Lead and execute incident response, build and tune global detection pipelines for cloud and Kubernetes, architect AI-native Autonomic Security Operations, analyze multi-language code for vulnerabilities, mentor engineers, and participate in on-call rotations.
Top Skills: Ai Agents/Agentic AiAutonomic Security Operations (Aso)BlockchainCloudDefiDetection EngineeringKubernetesRed TeamSoarSoar PlaybooksThreat HuntingThreat IntelligenceVulnerability Management

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account