Senior Security Engineer, Data Security

Kikoff

$268K — $321K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security engineering with hands-on data security experience
  • Strong knowledge of AWS security tools such as IAM and KMS
  • Experience with modern data stacks like Snowflake
  • Proficient in designing access control systems including RBAC
  • Fluent in an automation language like Python or Go
  • Comfortable working within regulated environments
  • Familiar with infrastructure-as-code using tools like Terraform

Responsibilities

  • Own the end-to-end data security roadmap for Kikoff
  • Set access control strategies for humans, services, and AI agents
  • Drive least-privilege access at scale
  • Design tokenization and field-level protection for sensitive data
  • Build role-based access controls with audit visibility
  • Secure data flows between cloud storage and application services
  • Create audit logging and monitoring solutions for compliance

Benefits

  • Work with a mission-driven team focused on building trust in financial data
  • Opportunity to shape and define data security practices as the company scales
  • Access to advanced tools and technologies for data security implementation
  • Collaborate with engineering and compliance teams to create robust security solutions
  • Engage in a fast-paced startup environment that encourages innovation and ownership
Full Job Description
About the Role

Kikoff exists to help millions of people build credit. That only works if they trust us with their financial data. This role owns the Data Security pillar at Kikoff: how data is classified, accessed, encrypted, moved, and audited across our entire stack.

You will own and dictate the data security roadmap. You define the strategy, sequence the work, and drive it to done. Your work will be felt by every engineer at Kikoff and every customer we serve, and it will shape how we handle sensitive data as we scale.
In This Role, You Will
Own the Pillar
  • Own the data security roadmap end to end: classification, access controls, encryption, tokenization, and data flow security across AWS, Snowflake, and our internal pipelines.
  • Set the strategy for how humans, services, and AI agents access sensitive data. You decide what good looks like and build towards it.
  • Drive least-privilege access at scale, including brokered access patterns for our data warehouse and production databases rather than standing credentials.
Build & Secure
  • Design and ship tokenization and field-level protection for our most sensitive data
  • Build column-level and role-based access controls across Snowflake and RDS, with audit visibility into who touched what and why
  • Secure data flows between cloud storage, pipelines, and application services so the secure path is the default path
  • Define and enforce access controls for AI agents to guarantee least privilege permissions and proper audibility.
Prove It
  • Build audit logging and data access monitoring that holds up in front of auditors and regulators, not just dashboards
  • Support data mapping and privacy engineering work for new markets and regulatory regimes (GLBA, LGPD, state privacy laws)
  • Partner with Legal and Compliance on data handling requirements, and translate them into infrastructure, not policy docs
Enable Engineering
  • Give engineers paved roads for handling sensitive data: reusable patterns, clear guidance, fast answers
  • Threat model new data flows before they ship, not after
Qualifications
  • 6+ years in security engineering with deep, hands-on data security experience: encryption, tokenization, access control design, key management
  • Strong command of AWS security primitives (IAM, KMS, S3 security, VPC controls)
  • Experience securing a modern data stack: Snowflake or a comparable warehouse, plus relational databases in production
  • You've designed and shipped access control systems, not just configured them. Row/column-level security, ABAC/RBAC, access brokering
  • Fluency in at least one language for automation (Python, Go, Ruby, or similar)
  • Comfortable in a regulated environment
  • Hands-on with infrastructure-as-code (Terraform or Pulumi)
Bonus Points
  • Experience securing data access for AI/LLM systems and agentic workloads
  • Tokenization at scale in fintech or payments
  • Audit logging and data access monitoring you built yourself, not bought
  • Privacy engineering depth: data mapping, retention, deletion pipelines, cross-border transfer controls
  • Consumer fintech or financial services background


Base Range

$268,000-$321,000 USD

Similar Jobs

More Jobs at Kikoff

More Information Technology Jobs

Find similar Senior Security Engineer, Data Security jobs: