SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Kin Insurance is seeking a Senior Security Engineer to own security operations at a fully cloud-based, remote-first insurance technology company. This is a hands-on role focused on endpoint detection and response, cloud security, and identity management across a distributed workforce of 35+ states.
You will own and tune the EDR/MDR stack, building detection policies, runbooks, and automation to keep the security team focused on real threats rather than noise. You'll lead incident response end-to-end—from investigation through containment—across compromised endpoints, cloud infrastructure, and identity systems. You'll manage endpoint security across both managed laptops and BYOD devices, setting device posture standards and hardening baselines.
Working directly in AWS, you'll build and remediate cloud security controls across IAM, networking, logging, and configuration management. You'll partner with IT to define identity and access control requirements, implement them in the SSO environment, and establish an access review cadence that removes stale permissions. You'll also serve as the front door for security across the company, answering security questions and tickets quickly enough that people bring issues to you early rather than working around the process.
Additionally, you'll conduct threat modeling across systems, processes, and vendor implementations, and instill a security-aware culture by educating the organization on real risks and helping non-technical teams make safer decisions independently.
Success in the first 6–12 months means detection tuning backed by runbooks, a clear device posture standard with predictable access reviews, and direct remediation of cloud vulnerabilities rather than documentation queues. You'll be trusted as an owner and proud of the progress made for both the company and the homeowners Kin serves.
Kin is a remote-first, profitable fintech company founded in 2016, serving customers in 14 states with recognition from Built In Chicago, Forbes (America's Best Startup Employers, Fintech 50), Inc. 5000, and Great Places to Work.
REQUIREMENTS:
Technical (Required):
- 5+ years in security operations, detection and response, or security engineering
- Hands-on experience running a modern EDR program: building and tuning detection logic, writing response runbooks, and leading investigations through to containment
- Endpoint security experience across managed and BYOD fleets, including device posture, hardening baselines, and MDM
- Identity and access management depth: defining access control requirements, designing RBAC models, and running access reviews in an SSO environment
- AWS security experience across IAM, network controls, logging, and configuration management, with a track record of remediating findings directly
- Comfort working in infrastructure-as-code environments and automating security tasks
- Threat modeling experience across systems, processes, or vendor implementations
Collaboration & Communication (Required):
- A record of fast, reliable responsiveness on security requests
- Experience working alongside IT on shared systems, setting security requirements
- A track record of holding teams accountable for security findings and driving remediation through to completion
- Ability to explain security risk to non-technical audiences in terms they can act on
Bonus:
- Terraform and CI/CD pipeline experience
- Zero trust networking experience, including designing or operating identity-aware and device-aware access controls
- Working knowledge of NIST, ISO 27001, SOC 2, and SOX, and how regulatory compliance translates into engineering requirements
- Experience securing a fully remote workforce
- Experience building security awareness or training programs for a non-technical audience
- Google Workspace security administration experience
- Security certifications such as AWS Certified Security Specialty, GCIH, or GCIA