Senior Security Engineer, Application Security

Kikoff

• $268K — $321K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security engineering with extensive application security experience: secure code review, threat modeling, and vulnerability management.
  • Proficient in production coding, with fluency in at least one of Ruby, Python, Go, or TypeScript.
  • Proven experience in designing and implementing authentication and authorization systems, including OAuth/OIDC and MFA.
  • Skilled in using modern application security tools such as SAST, SCA, DAST, and CI/CD integration.
  • Experience securing REST/GraphQL APIs and native mobile applications.
  • Familiarity with managing pentest or bug bounty programs.
  • Comfortable operating within a regulated fintech environment, such as PCI-DSS or SOC 2.

Responsibilities

  • Drive the application security roadmap, focusing on secure SDLC, code reviews, and vulnerability management.
  • Set standards for secure coding practices and develop tooling to enforce them.
  • Determine review processes for AI-generated code and establish controls for security.
  • Create frameworks that facilitate secure engineering practices for teams.
  • Oversee security measures for authentication and session management systems.
  • Ensure security for APIs and mobile applications, including authorization and abuse controls.
  • Run penetration testing and bug bounty programs, managing triage and remediation efforts.

Benefits

  • Flexible work environment with a focus on maintaining work-life balance.
  • Opportunities for professional growth and training in the latest security technologies.
  • Participation in impactful projects to enhance security at a rapidly growing fintech.
  • Collaborative culture with a focus on scalable security practices.
Full Job Description
About the Role

Kikoff exists to help millions of people build credit. That only works if the products they use are safe. This role helps shape the Application Security pillar at Kikoff: how code gets written, reviewed, shipped, and defended across our web, mobile, and API surfaces.

You will drive and help shape the application security roadmap. You define the strategy, sequence the work, and drive it to done. Engineers ship fast here, and increasingly with AI agents writing code alongside them. Your job is to make that speed safe by default.
In This Role, You Will
Drive the Pillar
  • Drive the application security roadmap: secure SDLC, code review, threat modeling, vulnerability management, and the pentest and bug bounty programs.
  • Set the standard for what secure code looks like at Kikoff and build the tooling that enforces it: SAST, SCA, secrets scanning, and dependency policy wired into CI with signal engineers trust.
  • Decide how AI-generated code gets reviewed and gated. Design the controls for a codebase where agents are contributors.
Build & Secure
  • Build paved roads into the frameworks engineers use: authn/authz libraries, input validation, safe defaults for common patterns, so the secure way is the only way most engineers encounter.
  • Own security for our authentication and session layer: MFA design, account recovery, session management, and defenses against credential stuffing and account takeover.
  • Secure our APIs and mobile apps: authorization models, rate limiting, abuse controls, certificate pinning, and secure storage on device.
  • Secure the AI features we ship to customers: prompt injection defenses, tool permission boundaries, and data exposure controls for LLM-backed flows.
Prove It
  • Run the penetration testing and bug bounty programs. Triage, drive remediation, and close the loop with engineering.
  • Build vulnerability management that holds up in front of auditors: defined SLAs, tracked remediation, and evidence that stands on its own for PCI-DSS, SOC 2, and IPO-readiness controls.
  • Threat model new products and major features before they ship, not after.
Enable Engineering
  • Be the security engineer product engineers actually want in their design reviews. Clear answers, fast turnaround, real fixes.
  • Stand up and run a security champions program so AppSec scales past one person.
  • Build internal tooling, including AI-assisted review and triage, that multiplies the team's reach.
Qualifications
  • 6+ years in security engineering with deep, hands-on application security experience: secure code review, threat modeling, vulnerability triage, and remediation at scale
  • You write production code. Fluency in at least one of Ruby, Python, Go, or TypeScript, and comfort reading all of them
  • You have designed and shipped authentication and authorization systems, not just reviewed them. OAuth/OIDC, session management, MFA, account recovery
  • Hands-on with modern AppSec tooling and the judgment to know when it is wrong: SAST, SCA, DAST, secrets scanning, CI/CD integration
  • Experience securing REST/GraphQL APIs and native mobile applications
  • You have run or built a pentest or bug bounty program
  • Comfortable in a fintech regulated environment: PCI-DSS, SOC 2, or similar
Bonus Points
  • Securing LLM-backed product features or agentic workloads in production
  • Fraud and abuse defense: bot detection, credential stuffing mitigation, device signals
  • Security champions or developer education programs you started, not inherited
  • Supply chain security depth: dependency provenance, artifact signing, build integrity
  • Consumer fintech or financial services background


Base Range

$268,000-$321,000 USD

Similar Jobs

More Jobs at Kikoff

  • Senior Security Engineer, Application Security
    $268K — $321K *
    San Francisco, CA 94112 (San Francisco County)
    Finance & Insurance
    In-Person
  • Product Designer
    $100K — $200K *
    San Francisco, CA 94112 (San Francisco County)
    Consumer Technology
    In-Person
  • Senior Director - FP&A
    $250K — $275K *
    San Francisco, CA 94112 (San Francisco County)
    Finance & Insurance
    In-Person
  • Staff Data Scientist, Grant
    $265K — $306K *
    San Francisco, CA 94112 (San Francisco County)
    Finance & Insurance
    In-Person
  • Revenue Accountant
    $120K — $130K *
    San Francisco, CA 94112 (San Francisco County)
    Finance & Insurance
    In-Person

More Finance & Insurance Jobs

Find similar Senior Security Engineer, Application Security jobs: