SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 268,000 - 321,000 / annual
Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, the company has built a suite of products helping millions of people build credit, access liquidity, and save money.
In this role, you will drive the application security pillar at Kikoff, shaping how code gets written, reviewed, shipped, and defended across web, mobile, and API surfaces. You will own the application security roadmap, define strategy, sequence work, and ensure that fast-shipping engineers maintain security by default—increasingly alongside AI agents writing code.
Key responsibilities include:
**Drive the Pillar**: Own the application security roadmap covering secure SDLC, code review, threat modeling, vulnerability management, and pentest/bug bounty programs. Set the standard for secure code at Kikoff and build tooling (SAST, SCA, secrets scanning, dependency policy) integrated into CI with signals engineers trust. Design controls for AI-generated code review and gating in a codebase where agents are contributors.
**Build & Secure**: Build paved roads into engineer frameworks—authn/authz libraries, input validation, safe defaults—so the secure way is the only way. Own security for the authentication and session layer: MFA design, account recovery, session management, and defenses against credential stuffing and account takeover. Secure APIs and mobile apps with authorization models, rate limiting, abuse controls, certificate pinning, and secure device storage. Secure AI features shipped to customers: prompt injection defenses, tool permission boundaries, and data exposure controls for LLM-backed flows.
**Prove It**: Run penetration testing and bug bounty programs; triage, drive remediation, and close the loop with engineering. Build vulnerability management that holds up in front of auditors with defined SLAs, tracked remediation, and evidence for PCI-DSS, SOC 2, and IPO-readiness controls. Threat model new products and major features before they ship.
**Enable Engineering**: Be the security engineer product engineers want in design reviews—clear answers, fast turnaround, real fixes. Stand up and run a security champions program to scale AppSec. Build internal tooling, including AI-assisted review and triage, that multiplies the team's reach.
**Requirements:**
- 6+ years in security engineering with deep, hands-on application security experience: secure code review, threat modeling, vulnerability triage, and remediation at scale
- Write production code; fluency in at least one of Ruby, Python, Go, or TypeScript, and comfort reading all of them
- Have designed and shipped authentication and authorization systems, not just reviewed them (OAuth/OIDC, session management, MFA, account recovery)
- Hands-on with modern AppSec tooling and judgment to know when it is wrong (SAST, SCA, DAST, secrets scanning, CI/CD integration)
- Experience securing REST/GraphQL APIs and native mobile applications
- Have run or built a pentest or bug bounty program
- Comfortable in a fintech regulated environment (PCI-DSS, SOC 2, or similar)
**Bonus Points:**
- Securing LLM-backed product features or agentic workloads in production
- Fraud and abuse defense: bot detection, credential stuffing mitigation, device signals
- Security champions or developer education programs you started, not inherited
- Supply chain security depth: dependency provenance, artifact signing, build integrity
- Consumer fintech or financial services background