Kikoff: The Fintech Powering Financial Security at Scale
Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.
We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.
Why Kikoff:
This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.
As the Staff GRC Engineer, you will report to the Lead of Security and be the first dedicated hire establishing Kikoff's Trust & Assurance function within Security. You will own the design, operation, and attestation of the cybersecurity controls that external auditors, regulators, and B2B customers rely on.
The function is engineering-led, with a strong emphasis on automation, code-backed control operations, and AI-assisted evidence workflows. You will partner closely with the SOX Manager in the CFO org as a cybersecurity control owner, while owning the cyber compliance program end-to-end for SOC 2 and PCI.
You will lead three connected work streams: security compliance (SOC 2, PCI, and IT general controls supporting SOX), customer assurance (questionnaires, trust portal, sub-processor inventory), and third-party risk management.
What You Will Do- Own Kikoff's SOC 2 Type II program end-to-end, including scoping, control design, evidence collection, walkthroughs, and external auditor management.
- Maintain Kikoff's PCI DSS self-attestation, including annual SAQ completion, scope analysis to ensure cardholder data remains with our payment processors, payment-vendor oversight, and monitoring product and engineering changes that could expand scope.
- Serve as the cybersecurity control owner for IT general controls supporting the SOX program, partnering with the SOX Manager on logical access, change management, and related areas.
- Operationalize the GLBA Safeguards Rule technical controls across the program elements.
- Source and steward the substantive cybersecurity content behind SEC Regulation S-K Item 106 disclosures, working with Legal on language and with the SOX Manager on disclosure controls.
- Own the customer and vendor security questionnaire pipeline, including reusable evidence libraries and a self-serve trust portal.
- Design and operate the internal cybersecurity control testing and continuous monitoring program in partnership with Security Engineering.
- Build policy-as-code, compliance-as-code, and AI-driven evidence automation that scales with the engineering organization.
- Serve as the primary cybersecurity audit contact for SOC 2, PCI, and customer-driven cyber assessments.
- 7+ years of experience in security compliance, GRC, or technical audit, with a primary focus on cloud-native environments.
- Has owned at least one SOC 2 Type II cycle end-to-end, including design, evidence, walkthroughs, and auditor defense.
- Hands-on experience with PCI DSS, including SAQ environments and tokenization-driven scope reduction.
- Able to read and modify code, infrastructure-as-code, and IAM policies. Comfortable working in Git-based engineering workflows and shipping changes through CI/CD.
- Understanding of cloud infrastructure and modern AI-native technologies.
- Demonstrated experience managing external auditors and translating control requirements into engineering deliverables.
- Excellent written communication, with the ability to produce auditor-ready documentation and engineering-ready specifications.
- Comfortable operating across functional boundaries, including Engineering, Legal, and Finance.
- Prior experience as a control owner supporting SOX IT general controls audits in a pre-IPO or newly public company.
- Experience building or operating AI- or LLM-driven GRC automation, including custom agents, MCP servers, or evidence-collection pipelines.
- Background in IPO readiness or newly public company environments.
- Familiarity with ISO 27001, ISO 42001, FedRAMP, CMMC 2.x, or NIST 800-53.
Equal Employment Opportunity Statement
Kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.
Please reference the following for more information.
Skills Required
- 7+ years of experience in security compliance, GRC, or technical audit with focus on cloud-native environments
- Owned at least one SOC 2 Type II cycle end-to-end (scoping, control design, evidence, walkthroughs, auditor defense)
- Hands-on experience with PCI DSS, including SAQ environments and tokenization scope reduction
- Ability to read and modify code, infrastructure-as-code, and IAM policies
- Comfortable working in Git-based engineering workflows and shipping changes through CI/CD
- Understanding of cloud infrastructure and modern AI-native technologies
- Experience managing external auditors and translating control requirements into engineering deliverables
- Excellent written communication to produce auditor-ready documentation and engineering-ready specifications
- Ability to operate across functional boundaries (Engineering, Legal, Finance) and serve as primary audit contact
- Operational ownership of SOC 2, PCI, and customer-driven cyber assessments and assurance workflows
- Prior experience as a SOX IT control owner in pre-IPO/newly public company environments
- Experience building or operating AI-/LLM-driven GRC automation, custom agents, or evidence-collection pipelines
- Background in IPO readiness or newly public company environments
- Familiarity with ISO 27001, FedRAMP, CMMC 2.x, or NIST 800-53
Kikoff Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Kikoff and has not been reviewed or approved by Kikoff.
-
Healthcare Strength — Employer-paid employee medical, dental, and vision premiums are highlighted across postings and benefits pages. This materially lowers out-of-pocket costs and signals strong core coverage.
-
Wellbeing & Lifestyle Benefits — Daily meals, snacks, fitness benefits, and substantial commuter support are prominently offered. These perks can meaningfully enhance day-to-day experience, especially for in-office or hybrid roles.
-
Retirement Support — A 401(k) with company matching is included in the package. The presence of matching adds long-term financial value even as specific formulas are not publicly detailed.
Kikoff Insights
What We Do
Kikoff is a personal finance platform that offers the simplest credit-building solution out there: $0 fees, 0% interest, and no credit pull. Your credit score is the foundation of your financial health – yet most people don’t have the credit score they deserve. That’s why Kikoff built the most accessible and affordable credit-building solution – it’s also the fastest growing and the top-rated credit building mobile app. Kikoff works whether you’re new to credit or looking for an extra boost. Building credit is just the start; Kikoff is building a personal finance platform designed to help consumers achieve financial wellness. Driven by the co-founders’ and team’s personal experiences, Kikoff’s mission is to provide refreshingly fair, effective, and simple pathways to meet your financial goals. Kikoff is a Series B company and has raised over $42 million in total funding. Investors include Portage Ventures, Lightspeed Venture Partners, GGV, Coatue, Core Innovation Capital, and basketball star Stephen Curry. Kikoff was founded in 2019 and is headquartered in San Francisco, California.
Why Work With Us
We are building an organization that maximizes growth and learning; we are invested in helping you grow and achieve what you want in your career. Our principles include a bias towards action, work in public, first principles thinking, intellectual honesty and extreme ownership.









