Skip to content

Open nowPosted 3 days agoWe saw it 80 min after it went up

Senior Security Engineer, Application Security

Kikoff48 open roles

Pay
$268,000 – $321,000 a year
Where
San Francisco
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineer, Application SecurityKikoff · San Francisco
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Kikoff's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market. Kikoff postings stay open a median of 26 days.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 3 days ago

Kikoff median: 26 days open

The posting

Kikoff: The Fintech Powering Financial Security at Scale Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money. We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.

Why Kikoff:

This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.

About the Role

Kikoff exists to help millions of people build credit. That only works if the products they use are safe. This role helps shape the Application Security pillar at Kikoff: how code gets written, reviewed, shipped, and defended across our web, mobile, and API surfaces.

You will drive and help shape the application security roadmap. You define the strategy, sequence the work, and drive it to done. Engineers ship fast here, and increasingly with AI agents writing code alongside them. Your job is to make that speed safe by default.

In This Role, You Will

Drive the Pillar

  • Drive the application security roadmap: secure SDLC, code review, threat modeling, vulnerability management, and the pentest and bug bounty programs.
  • Set the standard for what secure code looks like at Kikoff and build the tooling that enforces it: SAST, SCA, secrets scanning, and dependency policy wired into CI with signal engineers trust.
  • Decide how AI-generated code gets reviewed and gated. Design the controls for a codebase where agents are contributors.

Build & Secure

  • Build paved roads into the frameworks engineers use: authn/authz libraries, input validation, safe defaults for common patterns, so the secure way is the only way most engineers encounter.
  • Own security for our authentication and session layer: MFA design, account recovery, session management, and defenses against credential stuffing and account takeover.
  • Secure our APIs and mobile apps: authorization models, rate limiting, abuse controls, certificate pinning, and secure storage on device.
  • Secure the AI features we ship to customers: prompt injection defenses, tool permission boundaries, and data exposure controls for LLM-backed flows.

Prove It

  • Run the penetration testing and bug bounty programs. Triage, drive remediation, and close the loop with engineering.
  • Build vulnerability management that holds up in front of auditors: defined SLAs, tracked remediation, and evidence that stands on its own for PCI-DSS, SOC 2, and IPO-readiness controls.
  • Threat model new products and major features before they ship, not after.

Enable Engineering

  • Be the security engineer product engineers actually want in their design reviews. Clear answers, fast turnaround, real fixes.
  • Stand up and run a security champions program so AppSec scales past one person.
  • Build internal tooling, including AI-assisted review and triage, that multiplies the team's reach.

Qualifications

  • 6+ years in security engineering with deep, hands-on application security experience: secure code review, threat modeling, vulnerability triage, and remediation at scale
  • You write production code. Fluency in at least one of Ruby, Python, Go, or TypeScript, and comfort reading all of them
  • You have designed and shipped authentication and authorization systems, not just reviewed them. OAuth/OIDC, session management, MFA, account recovery
  • Hands-on with modern AppSec tooling and the judgment to know when it is wrong: SAST, SCA, DAST, secrets scanning, CI/CD integration
  • Experience securing REST/GraphQL APIs and native mobile applications
  • You have run or built a pentest or bug bounty program
  • Comfortable in a fintech regulated environment: PCI-DSS, SOC 2, or similar

Bonus Points

  • Securing LLM-backed product features or agentic workloads in production
  • Fraud and abuse defense: bot detection, credential stuffing mitigation, device signals
  • Security champions or developer education programs you started, not inherited
  • Supply chain security depth: dependency provenance, artifact signing, build integrity
  • Consumer fintech or financial services background

Base Range

$268,000—$321,000 USD

Equal Employment Opportunity Statement

Kikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.

Please reference the following for more information.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Kikoff's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Kikoff's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Kikoff's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.