SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 337,700 - 387,200 / annual
Kikoff is a profitable, pre-IPO fintech company on a mission to empower financial security at scale. With record revenue growth in 2025 and a unicorn valuation, the company has built a suite of products helping millions of people build credit, access liquidity, and save money.
This role owns the Detection & Response pillar for Kikoff's security program—defining how the company sees what's happening across its environment, how quickly it detects problems, and how well it responds. You will own and dictate the detection and response roadmap, define detection strategy, decide what gets built versus bought, and drive the program from having tools to having proven coverage. This is not a SOC analyst seat; you're building detection capability for a fintech handling sensitive financial data with real ownership from day one.
Key responsibilities include:
**Own the Pillar**: Manage the D&R roadmap end-to-end covering telemetry strategy, detection engineering, alert quality, response process, and coverage metrics. Decide detection architecture—what to log, where it lands, what to build in-house, and where partner tools fit. Set the bar for signal quality by eliminating noisy alerts, tuning what remains, and making on-call sustainable.
**Build Detection**: Design and maintain detection coverage across AWS (CloudTrail, GuardDuty, VPC flow), endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD. Write detections as code—versioned, tested, and mapped to real threats against a consumer fintech. Build audit logging and telemetry pipelines for visibility at scale, including data access monitoring and detections for AI/agentic activity. Threat model what attackers actually do to companies like Kikoff, not generic MITRE checklists.
**Run Response**: Own the incident response lifecycle from triage through postmortem and remediation tracking. Level up the incident process in incident.io with runbooks, severity definitions, escalation paths, and tabletop exercises. Lead technical investigations, including insider risk and unauthorized access cases.
**Enable the Team**: Build and run the InfoSec on-call rotation with real runbooks. Automate response where safe—enrichment, containment actions, ticket hygiene. Be the calm, technical voice engineers trust during incidents.
**Requirements:**
- 6+ years in security with meaningful detection engineering and incident response experience in cloud-native environments (AWS strongly preferred)
- Hands-on experience writing detections: SIEM rules or detection-as-code pipelines, with ownership of false positive rates
- Led real incidents, not just participated in them
- Strong command of cloud-native logging and detection surfaces
- Experience with EDR at fleet scale and identity-based detection
- Fluency in at least one automation language (Python, Go, Ruby, or similar)
- Comfortable in a fintech regulated environment
**Bonus:** Experience standing up detection programs from scratch, detections for AI/LLM and agentic system abuse, insider threat and unauthorized access investigation, or consumer fintech/financial services background.