Staff Detection & Response Engineer

Posted 14 Days Ago
Be an Early Applicant
San Francisco, CA, USA
Hybrid
338K-387K Annually
Senior level
Fintech • Software • Financial Services
Join our user-focused team on a mission to help people reach financial goals & protect privacy.
The Role
Own Kikoff’s detection and response program for a fintech environment. Responsibilities include setting the security telemetry and detection roadmap, building detection-as-code coverage across AWS, endpoints, identity, SaaS, and CI/CD, improving alert quality, managing incident response, leading investigations, creating runbooks and on-call processes, and automating safe response actions. The role also includes audit logging, insider-risk investigations, incident postmortems, and detection of AI or agentic system abuse.
Summary Generated by Built In

Kikoff: The Fintech Powering Financial Security at Scale
Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.
We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.


Why Kikoff:

This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.

Kikoff protects millions of customers and their financial data. This role owns the Detection & Response pillar: how we see what's happening across our environment, how fast we know when something is wrong, and how well we respond when it is.

You will own and dictate the detection and response roadmap. You define the detection strategy, decide what gets built versus bought, and drive the program from "we have tools" to "we have coverage we can prove." This isn't a SOC analyst seat. You're building the detection capability for a fintech handling sensitive financial data, and you'll have real ownership from day one.

In This Role, You WillOwn the Pillar
  • Own the D&R roadmap end to end: telemetry strategy, detection engineering, alert quality, response process, and the metrics that prove coverage
  • Decide our detection architecture. What we log, where it lands, what we build in-house, and where our partner tools fits.
  • Set the bar for signal quality. Kill noisy alerts, tune what stays, and make on-call sustainable
Build Detection
  • Design and maintain detection coverage across AWS (CloudTrail, GuardDuty, VPC flow), endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD
  • Write detections as code: versioned, tested, mapped to real threats against a consumer fintech
  • Build the audit logging and telemetry pipelines that give us visibility at scale, including data access monitoring and detections for AI/agentic activity in our environment
  • Threat model what an attacker actually does to a company like ours, and detect for that, not for a generic MITRE checklist
Run Response
  • Own the incident response lifecycle: triage, containment, forensics, postmortem, remediation tracking
  • Level up our incident process in incident.io: runbooks, severity definitions, escalation paths, tabletop exercises
  • Lead technical investigations, including insider risk and unauthorized access cases
Enable the Team
  • Build and run the InfoSec on-call rotation with real runbooks, not tribal knowledge
  • Automate response where it's safe: enrichment, containment actions, ticket hygiene
  • Be the calm, technical voice in an incident who engineers trust
Qualifications
  • 6+ years in security with meaningful detection engineering and incident response experience in cloud-native environments (AWS strongly preferred)
  • You've written detections yourself: SIEM rules, or detection-as-code pipelines, and you've owned the false positive rate that came with them
  • Hands-on incident response experience. You've led real incidents, not just participated in them
  • Strong command of Cloud Native logging and detection surfaces
  • Experience with EDR at fleet scale and identity-based detection
  • Fluency in at least one language for automation (Python, Go, Ruby, or similar)
  • Comfortable in a fintech regulated environment
Bonus Points
  • You've stood up a detection program from scratch or near-scratch
  • Detections for AI/LLM and agentic system abuse
  • Insider threat and unauthorized access investigation experience
  • Consumer fintech or financial services background

Base Range
$337,700—$387,200 USD

Equal Employment Opportunity Statement

Kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

Please reference the following for more information.

Skills Required

  • 6+ years of experience in security, including meaningful detection engineering and incident response experience in cloud-native environments
  • Experience writing SIEM rules or detection-as-code pipelines and managing false-positive rates
  • Hands-on incident response experience leading real security incidents
  • Strong command of cloud-native logging and detection surfaces
  • Experience with endpoint detection and response at fleet scale and identity-based detection
  • Fluency in at least one automation language, such as Python, Go, or Ruby
  • Comfort working in a regulated fintech environment
  • AWS experience
  • Experience establishing a detection program from scratch or near-scratch
  • Experience detecting AI, LLM, or agentic system abuse
  • Insider threat and unauthorized access investigation experience
  • Consumer fintech or financial services experience

Kikoff Compensation & Benefits Highlights

The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kikoff and has not been reviewed or approved by Kikoff.

  • Healthcare Strength — Health coverage is presented as comprehensive, with medical, dental, and vision included and the full premium cost covered for employees in recent postings. Employer materials and listings consistently cite health insurance as a core benefit.
  • Leave & Time Off Breadth — Time off is described as 20 days of accrued PTO plus company‑paid holidays. This provides a clear baseline of paid leave beyond standard holidays.
  • Wellbeing & Lifestyle Benefits — Everyday perks include commuter benefits, catered office meals, and a fitness benefit policy. These additions contribute to daily convenience and lifestyle support.

Kikoff Insights

Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Francisco, CA
165 Employees
Year Founded: 2019

What We Do

Kikoff is a personal finance platform that offers the simplest credit-building solution out there: $0 fees, 0% interest, and no credit pull. Your credit score is the foundation of your financial health – yet most people don’t have the credit score they deserve. That’s why Kikoff built the most accessible and affordable credit-building solution – it’s also the fastest growing and the top-rated credit building mobile app. Kikoff works whether you’re new to credit or looking for an extra boost. Building credit is just the start; Kikoff is building a personal finance platform designed to help consumers achieve financial wellness. Driven by the co-founders’ and team’s personal experiences, Kikoff’s mission is to provide refreshingly fair, effective, and simple pathways to meet your financial goals. Kikoff is a Series B company and has raised over $42 million in total funding. Investors include Portage Ventures, Lightspeed Venture Partners, GGV, Coatue, Core Innovation Capital, and basketball star Stephen Curry. Kikoff was founded in 2019 and is headquartered in San Francisco, California.

Why Work With Us

We are building an organization that maximizes growth and learning; we are invested in helping you grow and achieve what you want in your career. Our principles include a bias towards action, work in public, first principles thinking, intellectual honesty and extreme ownership.

Gallery

Gallery

Similar Jobs

Hybrid
4 Locations
1579 Employees
171K-303K Annually
In-Office
2 Locations
276 Employees
205K-256K Annually

Robinhood Logo Robinhood

Security Engineer

Fintech • Cryptocurrency
In-Office
3 Locations
5002 Employees
217K-255K Annually

Suno (suno.com) Logo Suno (suno.com)

Staff Detection & Response Engineer

Information Technology • Internet of Things
In-Office
4 Locations
144 Employees
277K-364K Annually

Similar Companies Hiring

Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel Thumbnail
Aerospace • Hardware • Robotics • Software
Marina Del Rey, California
60 Employees
Blee Thumbnail
Artificial Intelligence • Marketing Tech • Software
New York, New York
30 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account