← Back to results

Senior Security Engineer, Application Security

Shape the Application Security pillar at Kikoff, ensuring safe code practices in a fast-paced fintech environment.

Location
San Francisco, United States
Compensation
$268k–$321k/yr
Level
senior
Type
full time

Posted by employer 23 hours ago

First seen on Joblaze 13 hours ago

Last verified on the company career page 13 hours ago

Apply at Kikoff → Save job Scanned from kikoff.com

What you'll build

  • Drive the application security roadmap
  • Set the standard for secure code
  • Own security for authentication and session layer
  • Secure APIs and mobile apps
  • Run penetration testing and bug bounty programs

Must have

  • 6+ years in security engineering
  • Fluency in at least one of Ruby, Python, Go, or TypeScript
  • Designed and shipped authentication and authorization systems
  • Hands-on with modern AppSec tooling
  • Experience securing REST/GraphQL APIs and mobile applications

Nice to have

  • Securing LLM-backed product features
  • Fraud and abuse defense experience
  • Started security champions or developer education programs
  • Supply chain security depth
  • Consumer fintech or financial services background

AI in the day-to-day

Your job is to make that speed safe by default with AI agents writing code alongside engineers.

Requirements

Experience
6+ years

Not disclosed in this posting: work arrangement, visa sponsorship.

Joblaze summary

In this role, the Senior Security Engineer focuses on enhancing application security by driving the security roadmap, ensuring safe coding practices, and managing vulnerability assessments across Kikoff's products. Proficiency in secure coding, threat modeling, and familiarity with tools like SAST and DAST are essential, along with experience in programming languages such as Ruby, Python, Go, or TypeScript. This position is ideal for seasoned security professionals with a strong background in fintech and a hands-on approach to application security. The team emphasizes collaboration and clear communication, aiming to integrate security seamlessly into the development process.

Joblaze insights

  • Listed today — first seen on Joblaze September 30, 2026. Last confirmed on Kikoff's careers page September 30, 2026.
  • Salary band is above the typical range for Security roles (median ~$170,000).
  • Starts above 89% of 96 comparable senior security roles in United States that list Python we track (median $172,200 across 43 companies). See Python salary trends
  • Python appears in 40.2% of 316 comparable senior security roles in United States; MFA appears in 0.9% of 316 comparable senior security roles in United States.

Quick facts

What's the salary range?
Kikoff lists $268,000–$321,000 for this role.
How much experience is required?
At least 6 years of relevant experience for this Senior Security Engineer, Application Security role.
What's the tech stack?
Joblaze extracted these technologies from the posting: DAST, Go, MFA, OAuth, OIDC, Python.
What seniority level is this role?
Kikoff targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Senior Security Engineer, Application Security role at Kikoff.

From the original posting

Kikoff: The Fintech Powering Financial Security at Scale
Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.
We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.

About the Role

Kikoff exists to help millions of people build credit. That only works if the products they use are safe. This role helps shape the Application Security pillar at Kikoff: how code gets written, reviewed, shipped, and defended across our web, mobile, and API surfaces.

You will drive and help shape the application security roadmap. You define the strategy, sequence the work, and drive it to done. Engineers ship fast here, and increasingly with AI agents writing code alongside them. Your job is to make that speed safe by default.

In This Role, You Will

Drive the Pillar

  • Drive the application security roadmap: secure SDLC, code review, threat modeling, vulnerability management, and the pentest and bug bounty programs.
  • Set the standard for what secure code looks like at Kikoff and build the tooling that enforces it: SAST, SCA, secrets scanning, and dependency policy wired into CI with signal engineers trust.
  • Decide how AI-generated code gets reviewed and gated. Design the controls for a codebase where agents are contributors.

Build & Secure

  • Build paved roads into the frameworks engineers use: authn/authz libraries, input validation, safe defaults for common patterns, so the secure way is the only way most engineers encounter.
  • Own security for our authentication and session layer: MFA design, account recovery, session management, and defenses against credential stuffing and account takeover.
  • Secure our APIs and mobile apps: authorization models, rate limiting, abuse controls, certificate pinning, and secure storage on device.
  • Secure the AI features we ship to customers: prompt injection defenses, tool permission boundaries, and data exposure controls for LLM-backed flows.

Prove It

  • Run the penetration testing and bug bounty programs. Triage, drive remediation, and close the loop with engineering.
  • Build vulnerability management that holds up in front of auditors: defined SLAs, tracked remediation, and evidence that stands on its own for PCI-DSS, SOC 2, and IPO-readiness controls.
  • Threat model new products and major features before they ship, not after.

Enable Engineering

  • Be the security engineer product engineers actually want in their design reviews. Clear answers, fast turnaround, real fixes.
  • Stand up and run a security champions program so AppSec scales past one person.
  • Build internal tooling, including AI-assisted review and triage, that multiplies the team's reach.

Qualifications

  • 6+ years in security engineering with deep, hands-on application security experience: secure code review, threat modeling, vulnerability triage, and remediation at scale
  • You write production code. Fluency in at least one of Ruby, Python, Go, or TypeScript, and comfort reading all of them
  • You have designed and shipped authentication and authorization systems, not just reviewed them. OAuth/OIDC, session management, MFA, account recovery
  • Hands-on with modern AppSec tooling and the judgment to know when it is wrong: SAST, SCA, DAST, secrets scanning, CI/CD integration
  • Experience securing REST/GraphQL APIs and native mobile applications
  • You have run or built a pentest or bug bounty program
  • Comfortable in a fintech regulated environment: PCI-DSS, SOC 2, or similar

Bonus Points

  • Securing LLM-backed product features or agentic workloads in production
  • Fraud and abuse defense: bot detection, credential stuffing mitigation, device signals
  • Security champions or developer education programs you started, not inherited
  • Supply chain security depth: dependency provenance, artifact signing, build integrity
  • Consumer fintech or financial services background

Base Range
$268,000—$321,000 USD

Equal Employment Opportunity Statement

Standard company text repeated across Kikoff's postings is omitted here.

Similar positions

Kikoff
Opal
Application Security Engineer
Opal · San Francisco
K2 Space
Kaizen Labs
Senior Security Engineer
Kaizen Labs · New York, NY
K2 Space