{"schemaVersion":"jobsearcher.job.v1","id":"66a5e684bc91fa7f10e3a2ac","url":"https://jobsearcher.com/jobs/66a5e684bc91fa7f10e3a2ac","canonicalUrl":"https://jobsearcher.com/jobs/66a5e684bc91fa7f10e3a2ac","title":"Senior Security Engineer, Data Security","description":"Kikoff: The Fintech Powering Financial Security at Scale\nKikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.\nWe're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.\n\nWhy Kikoff:\n\nThis is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.\n\nAbout the Role\n\nKikoff exists to help millions of people build credit. That only works if they trust us with their financial data. This role owns the Data Security pillar at Kikoff: how data is classified, accessed, encrypted, moved, and audited across our entire stack.\n\nYou will own and dictate the data security roadmap. You define the strategy, sequence the work, and drive it to done. Your work will be felt by every engineer at Kikoff and every customer we serve, and it will shape how we handle sensitive data as we scale.\n\nIn This Role, You Will\nOwn the Pillar\nOwn the data security roadmap end to end: classification, access controls, encryption, tokenization, and data flow security across AWS, Snowflake, and our internal pipelines.\nSet the strategy for how humans, services, and AI agents access sensitive data. You decide what good looks like and build towards it.\nDrive least-privilege access at scale, including brokered access patterns for our data warehouse and production databases rather than standing credentials.\nBuild & Secure\nDesign and ship tokenization and field-level protection for our most sensitive data\nBuild column-level and role-based access controls across Snowflake and RDS, with audit visibility into who touched what and why\nSecure data flows between cloud storage, pipelines, and application services so the secure path is the default path\nDefine and enforce access controls for AI agents to guarantee least privilege permissions and proper audibility.\nProve It\nBuild audit logging and data access monitoring that holds up in front of auditors and regulators, not just dashboards\nSupport data mapping and privacy engineering work for new markets and regulatory regimes (GLBA, LGPD, state privacy laws)\nPartner with Legal and Compliance on data handling requirements, and translate them into infrastructure, not policy docs\nEnable Engineering\nGive engineers paved roads for handling sensitive data: reusable patterns, clear guidance, fast answers\nThreat model new data flows before they ship, not after\nQualifications\n6+ years in security engineering with deep, hands-on data security experience: encryption, tokenization, access control design, key management\nStrong command of AWS security primitives (IAM, KMS, S3 security, VPC controls)\nExperience securing a modern data stack: Snowflake or a comparable warehouse, plus relational databases in production\nYou've designed and shipped access control systems, not just configured them. Row/column-level security, ABAC/RBAC, access brokering\nFluency in at least one language for automation (Python, Go, Ruby, or similar)\nComfortable in a regulated environment\nHands-on with infrastructure-as-code (Terraform or Pulumi)\nBonus Points\nExperience securing data access for AI/LLM systems and agentic workloads\nTokenization at scale in fintech or payments\nAudit logging and data access monitoring you built yourself, not bought\nPrivacy engineering depth: data mapping, retention, deletion pipelines, cross-border transfer controls\nConsumer fintech or financial services background\n\nBase Range\n\n$268,000 - $321,000 USD\n\nEqual Employment Opportunity Statement\n\nKikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.\n\n.","company":"Kikoff","rawCompany":"kikoff","city":"Millbrae","state":"CA","isRemote":false,"isActive":false,"createdAt":"2026-09-11T09:16:08.707Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541511","title":"Custom Computer Programming Services","slug":"custom-computer-programming-services"},{"code":"513210","title":"Software Publishers","slug":"software-publishers"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Senior Security Engineer, Data Security","description":"Kikoff: The Fintech Powering Financial Security at Scale\nKikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.\nWe're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.\n\nWhy Kikoff:\n\nThis is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.\n\nAbout the Role\n\nKikoff exists to help millions of people build credit. That only works if they trust us with their financial data. This role owns the Data Security pillar at Kikoff: how data is classified, accessed, encrypted, moved, and audited across our entire stack.\n\nYou will own and dictate the data security roadmap. You define the strategy, sequence the work, and drive it to done. Your work will be felt by every engineer at Kikoff and every customer we serve, and it will shape how we handle sensitive data as we scale.\n\nIn This Role, You Will\nOwn the Pillar\nOwn the data security roadmap end to end: classification, access controls, encryption, tokenization, and data flow security across AWS, Snowflake, and our internal pipelines.\nSet the strategy for how humans, services, and AI agents access sensitive data. You decide what good looks like and build towards it.\nDrive least-privilege access at scale, including brokered access patterns for our data warehouse and production databases rather than standing credentials.\nBuild & Secure\nDesign and ship tokenization and field-level protection for our most sensitive data\nBuild column-level and role-based access controls across Snowflake and RDS, with audit visibility into who touched what and why\nSecure data flows between cloud storage, pipelines, and application services so the secure path is the default path\nDefine and enforce access controls for AI agents to guarantee least privilege permissions and proper audibility.\nProve It\nBuild audit logging and data access monitoring that holds up in front of auditors and regulators, not just dashboards\nSupport data mapping and privacy engineering work for new markets and regulatory regimes (GLBA, LGPD, state privacy laws)\nPartner with Legal and Compliance on data handling requirements, and translate them into infrastructure, not policy docs\nEnable Engineering\nGive engineers paved roads for handling sensitive data: reusable patterns, clear guidance, fast answers\nThreat model new data flows before they ship, not after\nQualifications\n6+ years in security engineering with deep, hands-on data security experience: encryption, tokenization, access control design, key management\nStrong command of AWS security primitives (IAM, KMS, S3 security, VPC controls)\nExperience securing a modern data stack: Snowflake or a comparable warehouse, plus relational databases in production\nYou've designed and shipped access control systems, not just configured them. Row/column-level security, ABAC/RBAC, access brokering\nFluency in at least one language for automation (Python, Go, Ruby, or similar)\nComfortable in a regulated environment\nHands-on with infrastructure-as-code (Terraform or Pulumi)\nBonus Points\nExperience securing data access for AI/LLM systems and agentic workloads\nTokenization at scale in fintech or payments\nAudit logging and data access monitoring you built yourself, not bought\nPrivacy engineering depth: data mapping, retention, deletion pipelines, cross-border transfer controls\nConsumer fintech or financial services background\n\nBase Range\n\n$268,000 - $321,000 USD\n\nEqual Employment Opportunity Statement\n\nKikoff Inc. is an equal opportunity employer. We are committed to complying with all federal, state, and local laws providing equal employment opportunities and considers qualified applicants without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, marital status, pregnancy, sex, gender expression or identity, sexual orientation, citizenship, or any other legally protected class.\n\n.","datePosted":"2026-09-11T09:16:08.707Z","dateModified":"2026-09-11T09:16:08.707Z","hiringOrganization":{"@type":"Organization","name":"Kikoff","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Millbrae","addressRegion":"CA","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"66a5e684bc91fa7f10e3a2ac"},"url":"https://jobsearcher.com/jobs/66a5e684bc91fa7f10e3a2ac"}}