Staff Detection & Response Engineer
Kikoff · San Francisco · United States · On-site
Pay: USD 337,700 – 387,200 a year
Posted Sep 11, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Kikoff: The Fintech Powering Financial Security at Scale Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money. We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.
Why Kikoff:
This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.
Kikoff protects millions of customers and their financial data. This role owns the Detection & Response pillar: how we see what's happening across our environment, how fast we know when something is wrong, and how well we respond when it is.
You will own and dictate the detection and response roadmap. You define the detection strategy, decide what gets built versus bought, and drive the program from "we have tools" to "we have coverage we can prove." This isn't a SOC analyst seat. You're building the detection capability for a fintech handling sensitive financial data, and you'll have real ownership from day one.
In This Role, You Will
Own the Pillar
Own the D&R roadmap end to end: telemetry strategy, detection engineering, alert quality, response process, and the metrics that prove coverage
Decide our detection architecture. What we log, where it lands, what we build in-house, and where our partner tools fits.
Set the bar for signal quality. Kill noisy alerts, tune what stays, and make on-call sustainable
Build Detection
Design and maintain detection coverage across AWS (CloudTrail, GuardDuty, VPC flow), endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD
Write detections as code: versioned, tested, mapped to real threats against a consumer fintech
Build the audit logging and telemetry pipelines that give us visibility at scale, including data access monitoring and detections for AI/agentic activity in our environment
Threat model what an attacker actually does to a company like ours, and detect for that, not for a generic MITRE checklist
Run Response
Own the incident response lifecycle: triage, containment, forensics, postmortem, remediation tracking
Level up our incident process in incident.io : runbooks, severity definitions, escalation paths, tabletop exercises
Lead technical investigations, including insider risk and unauthorized access cases
Enable the Team
Build and run the InfoSec on-call rotation with real runbooks, not tribal knowledge
Automate response where it's safe: enrichment, containment actions, ticket hygiene
Be the calm, technical voice in…