hirly

Kikoff

Staff Detection & Response Engineer

San Francisco

See how you match this job — and similar ones. Free.

Upload your resume and hirly scores it against this role at Kikoff first, then against similar open jobs, and shows where you fit and why.

PDF or DOCX, up to 12MB. No sign-up to see your matches.

Get past the screening software and onto a recruiter's desk

hirly rewrites your resume for this job — matching the keywords and skills in the posting, moving your most relevant experience to the top, and writing a cover letter to fit. About 30 seconds.

  • Keywords matched to this posting
  • Fit score before you apply
  • Cover letter included

Matched against 2.3M live jobs from 200,000+ employers in 200+ countries.

Tailor my resume for this job →

hirly's read of this role

Seniority
Lead / management
Stated salary
$337,700 – $387,200 per year
Country
US
Work mode
On-site / unstated
First seen by hirly
21 Sept 2026

Derived automatically from the posting. Upload your resume above to see how the role scores against it.

the posting

  • Kikoff: The Fintech Powering Financial Security at Scale
  • Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.
  • We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.

Why Kikoff:

This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.

Kikoff protects millions of customers and their financial data. This role owns the Detection & Response pillar: how we see what's happening across our environment, how fast we know when something is wrong, and how well we respond when it is.

You will own and dictate the detection and response roadmap. You define the detection strategy, decide what gets built versus bought, and drive the program from "we have tools" to "we have coverage we can prove." This isn't a SOC analyst seat. You're building the detection capability for a fintech handling sensitive financial data, and you'll have real ownership from day one.

In This Role, You Will

Own the Pillar

Own the D&R roadmap end to end: telemetry strategy, detection engineering, alert quality, response process, and the metrics that prove coverage

Decide our detection architecture. What we log, where it lands, what we build in-house, and where our partner tools fits.

Set the bar for signal quality. Kill noisy alerts, tune what stays, and make on-call sustainable

Build Detection

Design and maintain detection coverage across AWS (CloudTrail, GuardDuty, VPC flow), endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD

Write detections as code: versioned, tested, mapped to real threats against a consumer fintech

Build the audit logging and telemetry pipelines that give us visibility at scale, including data access monitoring and detections for AI/agentic activity in our environment

Threat model what an attacker actually does to a company like ours, and detect for that, not for a generic MITRE checklist

Run Response

Own the incident response lifecycle: triage, containment, forensics, postmortem, remediation tracking

Level up our incident process in incident.io : runbooks, severity definitions, escalation paths, tabletop exercises

Lead technical investigations, including insider risk and unauthorized access cases

Enable the Team

Build and run the InfoSec on-call rotation with real runbooks, not tribal knowledge

Automate response where it's safe: enrichment, containment actions, ticket hygiene

Be the calm, technical voice in an incident who engineers trust

Qualifications

6+ years in security with meaningful detection engineering and incident response experience in cloud-native environments (AWS strongly preferred)

You've written detections yourself: SIEM rules, or detection-as-code pipelines, and you've owned the false positive rate that came with them

Hands-on incident response experience. You've led real incidents, not just participated in them

Strong command of Cloud Native logging and detection surfaces

Experience with EDR at fleet scale and identity-based detection

Fluency in at least one language for automation (Python, Go, Ruby, or similar)

Comfortable in a fintech regulated environment

Bonus Points

You've stood up a detection program from scratch or near-scratch

Detections for AI/LLM and agentic system abuse

Insider threat and unauthorized access investigation experience

Consumer fintech or financial services background

Base Range

$337,700 — $387,200 USD

Equal Employment Opportunity Statement

Kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

Please reference the following for more information .

Original posting on Kikoff's site ↗

Browse similar roles

Want this one?

Upload your resume and hirly rewrites it for this job and writes the cover letter — in about thirty seconds, before you sign up.

Tailor my resume for this job