SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 268,000 - 321,000 / annual
Kikoff is a profitable, pre-IPO fintech company on a mission to empower millions of people to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, the company has built a suite of products helping users build credit, access liquidity, and save money.
This Senior Security Engineer role owns the Data Security pillar at Kikoff, responsible for how data is classified, accessed, encrypted, moved, and audited across the entire stack. You will own and dictate the data security roadmap, define strategy, sequence work, and drive execution to completion. Your work will directly impact every engineer at Kikoff and every customer served, shaping how sensitive financial data is handled as the company scales.
Key responsibilities include:
**Own the Pillar**: Develop the complete data security roadmap covering classification, access controls, encryption, tokenization, and data flow security across AWS, Snowflake, and internal pipelines. Set strategy for how humans, services, and AI agents access sensitive data. Drive least-privilege access at scale, including brokered access patterns for data warehouses and production databases.
**Build & Secure**: Design and ship tokenization and field-level protection for sensitive data. Build column-level and role-based access controls across Snowflake and RDS with audit visibility. Secure data flows between cloud storage, pipelines, and application services. Define and enforce access controls for AI agents with proper auditability.
**Prove It**: Build audit logging and data access monitoring that satisfies auditors and regulators. Support data mapping and privacy engineering for new markets and regulatory regimes (GLBA, LGPD, state privacy laws). Partner with Legal and Compliance to translate data handling requirements into infrastructure solutions.
**Enable Engineering**: Provide engineers with paved roads for handling sensitive data through reusable patterns and clear guidance. Threat model new data flows before they ship.
Required qualifications: 6+ years in security engineering with deep hands-on data security experience (encryption, tokenization, access control design, key management). Strong command of AWS security primitives (IAM, KMS, S3, VPC). Experience securing modern data stacks (Snowflake or comparable warehouse, plus production relational databases). Proven track record designing and shipping access control systems (row/column-level security, ABAC/RBAC, access brokering). Fluency in automation languages (Python, Go, Ruby, or similar). Comfortable working in regulated environments. Hands-on with infrastructure-as-code (Terraform or Pulumi).
Bonus experience includes securing data access for AI/LLM systems and agentic workloads, tokenization at scale in fintech/payments, custom-built audit logging and data access monitoring, privacy engineering depth (data mapping, retention, deletion pipelines, cross-border controls), and consumer fintech or financial services background.