About The Position

Kikoff is a profitable, pre-IPO fintech company focused on empowering financial security. This role is crucial for ensuring the safety of Kikoff's products, including web, mobile, and API surfaces. The engineer will drive the application security roadmap, defining strategy and ensuring secure development practices, especially with the increasing use of AI in code generation. The goal is to make rapid development safe by default.

Requirements

  • 6+ years in security engineering with deep, hands-on application security experience: secure code review, threat modeling, vulnerability triage, and remediation at scale.
  • Ability to write production code.
  • Fluency in at least one of Ruby, Python, Go, or TypeScript, and comfort reading all of them.
  • Experience designing and shipping authentication and authorization systems (OAuth/OIDC, session management, MFA, account recovery).
  • Hands-on experience with modern AppSec tooling (SAST, SCA, DAST, secrets scanning, CI/CD integration) and the judgment to use them effectively.
  • Experience securing REST/GraphQL APIs and native mobile applications.
  • Experience running or building a pentest or bug bounty program.
  • Comfort working in a fintech regulated environment (PCI-DSS, SOC 2, or similar).

Nice To Haves

  • Securing LLM-backed product features or agentic workloads in production.
  • Fraud and abuse defense: bot detection, credential stuffing mitigation, device signals.
  • Experience starting security champions or developer education programs.
  • Supply chain security depth: dependency provenance, artifact signing, build integrity.
  • Consumer fintech or financial services background.

Responsibilities

  • Drive the application security roadmap, including secure SDLC, code review, threat modeling, vulnerability management, and pentest/bug bounty programs.
  • Set standards for secure code and build tooling (SAST, SCA, secrets scanning, dependency policy) integrated into CI.
  • Define processes for reviewing and gating AI-generated code and design controls for codebases with AI contributors.
  • Build secure frameworks and libraries for engineers (e.g., authn/authz, input validation) to ensure secure practices are the default.
  • Own security for the authentication and session layer, including MFA, account recovery, and defenses against credential stuffing.
  • Secure APIs and mobile apps with authorization models, rate limiting, abuse controls, certificate pinning, and secure storage.
  • Secure AI features by implementing prompt injection defenses, tool permission boundaries, and data exposure controls for LLM-backed flows.
  • Run penetration testing and bug bounty programs, triaging vulnerabilities and driving remediation with engineering.
  • Build vulnerability management processes with defined SLAs and evidence for compliance (PCI-DSS, SOC 2, IPO-readiness).
  • Perform threat modeling for new products and major features.
  • Act as a security engineering resource for product engineers during design reviews, providing clear guidance and fast turnaround.
  • Establish and run a security champions program to scale AppSec efforts.
  • Build internal tooling, including AI-assisted review and triage, to enhance team efficiency.

Benefits

  • Competitive salary and equity
  • Comprehensive health, dental, and vision insurance
  • 401(k) plan
  • Generous PTO
  • Professional development opportunities
  • Opportunity to work with serial entrepreneurs in a fast-growing fintech startup
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service