← Back to results

Staff Detection & Response Engineer

Own the detection and response roadmap at Kikoff, a fintech startup, ensuring security for millions of customers' financial data.

Location
San Francisco, United States
Compensation
$337.7k–$387.2k/yr
Level
staff
Type
full time

Posted by employer 2 weeks ago

First seen on Joblaze 1 day ago

Last verified on the company career page 1 day ago

Apply at Kikoff → Save job Scanned from kikoff.com

What you'll build

  • Own the D&R roadmap end to end
  • Decide our detection architecture
  • Design and maintain detection coverage
  • Own the incident response lifecycle
  • Build and run the InfoSec on-call rotation

Must have

  • 6+ years in security
  • Meaningful detection engineering experience
  • Hands-on incident response experience
  • Strong command of Cloud Native logging
  • Experience with EDR at fleet scale
  • Fluency in at least one language for automation

Nice to have

  • You've stood up a detection program from scratch
  • Detections for AI/LLM and agentic system abuse
  • Insider threat and unauthorized access investigation experience
  • Consumer fintech or financial services background

Requirements

Experience
6+ years

Not disclosed in this posting: work arrangement, visa sponsorship.

Joblaze summary

The Staff Detection & Response Engineer at Kikoff is responsible for developing and managing the detection and response strategy to safeguard sensitive financial data. This role requires expertise in cloud-native environments, particularly AWS, and involves hands-on experience with detection engineering and incident response. Ideal candidates have over six years in security, with a strong background in building detection capabilities and leading incident responses. Kikoff's fast-paced fintech environment offers the chance to make a significant impact on financial security for millions.

Joblaze insights

  • Listed yesterday — first seen on Joblaze September 28, 2026. Last confirmed on Kikoff's careers page September 28, 2026.
  • Salary band is above the typical range for Security roles (median ~$170,000).
  • Starts above 94% of 33 comparable staff security roles in United States that list Python we track (median $200,000 across 20 companies). See Python salary trends
  • Python appears in 46.4% of 84 comparable staff security roles in United States; GuardDuty appears in 1.2% of 84 comparable staff security roles in United States.

Quick facts

What's the salary range?
Kikoff lists $337,700–$387,200 for this role.
How much experience is required?
At least 6 years of relevant experience for this Staff Detection & Response Engineer role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, CloudTrail, Go, GuardDuty, Okta, Python.
What seniority level is this role?
Kikoff targets staff-level candidates for this position.
Is this full-time or contract?
Full-time for this Staff Detection & Response Engineer role at Kikoff.

From the original posting

Kikoff: The Fintech Powering Financial Security at Scale
Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.
We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.

Kikoff protects millions of customers and their financial data. This role owns the Detection & Response pillar: how we see what's happening across our environment, how fast we know when something is wrong, and how well we respond when it is.

You will own and dictate the detection and response roadmap. You define the detection strategy, decide what gets built versus bought, and drive the program from "we have tools" to "we have coverage we can prove." This isn't a SOC analyst seat. You're building the detection capability for a fintech handling sensitive financial data, and you'll have real ownership from day one.

In This Role, You Will

Own the Pillar

  • Own the D&R roadmap end to end: telemetry strategy, detection engineering, alert quality, response process, and the metrics that prove coverage
  • Decide our detection architecture. What we log, where it lands, what we build in-house, and where our partner tools fits.
  • Set the bar for signal quality. Kill noisy alerts, tune what stays, and make on-call sustainable

Build Detection

  • Design and maintain detection coverage across AWS (CloudTrail, GuardDuty, VPC flow), endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD
  • Write detections as code: versioned, tested, mapped to real threats against a consumer fintech
  • Build the audit logging and telemetry pipelines that give us visibility at scale, including data access monitoring and detections for AI/agentic activity in our environment
  • Threat model what an attacker actually does to a company like ours, and detect for that, not for a generic MITRE checklist

Run Response

  • Own the incident response lifecycle: triage, containment, forensics, postmortem, remediation tracking
  • Level up our incident process in incident.io: runbooks, severity definitions, escalation paths, tabletop exercises
  • Lead technical investigations, including insider risk and unauthorized access cases

Enable the Team

  • Build and run the InfoSec on-call rotation with real runbooks, not tribal knowledge
  • Automate response where it's safe: enrichment, containment actions, ticket hygiene
  • Be the calm, technical voice in an incident who engineers trust

Qualifications

  • 6+ years in security with meaningful detection engineering and incident response experience in cloud-native environments (AWS strongly preferred)
  • You've written detections yourself: SIEM rules, or detection-as-code pipelines, and you've owned the false positive rate that came with them
  • Hands-on incident response experience. You've led real incidents, not just participated in them
  • Strong command of Cloud Native logging and detection surfaces
  • Experience with EDR at fleet scale and identity-based detection
  • Fluency in at least one language for automation (Python, Go, Ruby, or similar)
  • Comfortable in a fintech regulated environment

Bonus Points

  • You've stood up a detection program from scratch or near-scratch
  • Detections for AI/LLM and agentic system abuse
  • Insider threat and unauthorized access investigation experience
  • Consumer fintech or financial services background

Base Range
$337,700—$387,200 USD

Equal Employment Opportunity Statement

Standard company text repeated across Kikoff's postings is omitted here.

Similar positions

Kikoff
Product Manager
Kikoff · San Francisco, California, United States
Kikoff
Senior Product Manager
Kikoff · San Francisco, California, United States
Kikoff
Senior Product Designer
Kikoff · San Francisco, United States
Kikoff
Senior Manager, Business Development Enterprise
Kikoff · San Francisco, United States
Kikoff
Senior Frontend Engineer
Kikoff · San Francisco, United States