Staff Detection & Response Engineer

Kikoff

$337K — $387K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 6+ years in security with detection engineering and incident response in cloud-native environments (AWS preferred)
  • Experience writing detections: SIEM rules and detection-as-code pipelines with ownership of false positive rates
  • Hands-on incident response experience leading real incidents
  • Strong command of Cloud Native logging and detection surfaces
  • Familiarity with EDR at fleet scale and identity-based detection
  • Fluency in at least one automation language (Python, Go, Ruby, etc.)
  • Comfortable in a regulated fintech environment

Responsibilities

  • Own the Detection & Response (D&R) roadmap from strategy to execution
  • Decide on detection architecture, including logging strategies and tool integration
  • Ensure high signal quality by managing alert noise and tuning detection
  • Design and maintain coverage across various environments including AWS and endpoints
  • Write coded detections mapped to real threats instead of generic frameworks
  • Build telemetry and audit logging pipelines for enhanced visibility
  • Manage the full incident response lifecycle from triage to remediation

Benefits

  • Opportunity to lead and shape a critical security function within a fintech
  • Real ownership from day one in shaping detection capabilities
  • Engagement with advanced cloud environments and security challenges
  • Collaboration with a technically-skilled team in a dynamic industry
  • Focus on automation and efficiency in incident response processes
Full Job Description
Kikoff protects millions of customers and their financial data. This role owns the Detection & Response pillar: how we see what's happening across our environment, how fast we know when something is wrong, and how well we respond when it is.

You will own and dictate the detection and response roadmap. You define the detection strategy, decide what gets built versus bought, and drive the program from "we have tools" to "we have coverage we can prove." This isn't a SOC analyst seat. You're building the detection capability for a fintech handling sensitive financial data, and you'll have real ownership from day one.
In This Role, You Will
Own the Pillar
  • Own the D&R roadmap end to end: telemetry strategy, detection engineering, alert quality, response process, and the metrics that prove coverage
  • Decide our detection architecture. What we log, where it lands, what we build in-house, and where our partner tools fits.
  • Set the bar for signal quality. Kill noisy alerts, tune what stays, and make on-call sustainable
Build Detection
  • Design and maintain detection coverage across AWS (CloudTrail, GuardDuty, VPC flow), endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD
  • Write detections as code: versioned, tested, mapped to real threats against a consumer fintech
  • Build the audit logging and telemetry pipelines that give us visibility at scale, including data access monitoring and detections for AI/agentic activity in our environment
  • Threat model what an attacker actually does to a company like ours, and detect for that, not for a generic MITRE checklist
Run Response
  • Own the incident response lifecycle: triage, containment, forensics, postmortem, remediation tracking
  • Level up our incident process in incident.io: runbooks, severity definitions, escalation paths, tabletop exercises
  • Lead technical investigations, including insider risk and unauthorized access cases
Enable the Team
  • Build and run the InfoSec on-call rotation with real runbooks, not tribal knowledge
  • Automate response where it's safe: enrichment, containment actions, ticket hygiene
  • Be the calm, technical voice in an incident who engineers trust
Qualifications
  • 6+ years in security with meaningful detection engineering and incident response experience in cloud-native environments (AWS strongly preferred)
  • You've written detections yourself: SIEM rules, or detection-as-code pipelines, and you've owned the false positive rate that came with them
  • Hands-on incident response experience. You've led real incidents, not just participated in them
  • Strong command of Cloud Native logging and detection surfaces
  • Experience with EDR at fleet scale and identity-based detection
  • Fluency in at least one language for automation (Python, Go, Ruby, or similar)
  • Comfortable in a fintech regulated environment
Bonus Points
  • You've stood up a detection program from scratch or near-scratch
  • Detections for AI/LLM and agentic system abuse
  • Insider threat and unauthorized access investigation experience
  • Consumer fintech or financial services background


Base Range

$337,700-$387,200 USD

Similar Jobs

More Jobs at Kikoff

More Information Technology Jobs

Find similar Staff Detection & Response Engineer jobs: