layiq
worthy; deserving; fitting; suitable.
A role, opportunity, or path that merits attention, time, and pursuit.
Loading LAYIQ…Job opportunity
Kikoff
San Francisco
Source: Kikoff careers · View original posting
From Kikoff's posting. “We” and “our” refer to the employer.
Kikoff: The Fintech Powering Financial Security at Scale
Kikoff is a profitable, pre-IPO fintech company on a mission to empower everyone to achieve financial security. With record revenue growth in 2025 and a unicorn valuation, we've built a suite of products that help millions of people build credit, access liquidity, and save money.
We're scaling fast. Join us if you want to build something meaningful and help millions of people move forward financially.
This is a consumer fintech startup, and you will be working with serial entrepreneurs who have built strong consumer brands and innovative products. We value extreme ownership, clear communication, a strong sense of craftsmanship, and the desire to create lasting work and work relationships. Yes, you can build an exciting business AND have real-life real-customer impact.
Kikoff exists to help millions of people build credit. That only works if the products they use are safe. This role helps shape the Application Security pillar at Kikoff: how code gets written, reviewed, shipped, and defended across our web, mobile, and API surfaces.
You will drive and help shape the application security roadmap. You define the strategy, sequence the work, and drive it to done. Engineers ship fast here, and increasingly with AI agents writing code alongside them. Your job is to make that speed safe by default.
In This Role, You Will
Drive the Pillar
Drive the application security roadmap: secure SDLC, code review, threat modeling, vulnerability management, and the pentest and bug bounty programs.
Set the standard for what secure code looks like at Kikoff and build the tooling that enforces it: SAST, SCA, secrets scanning, and dependency policy wired into CI with signal engineers trust.
Decide how AI-generated code gets reviewed and gated. Design the controls for a codebase where agents are contributors.
Build & Secure
Build paved roads into the frameworks engineers use: authn/authz libraries, input validation, safe defaults for common patterns, so the secure way is the only way most engineers encounter.
Own security for our authentication and session layer: MFA design, account recovery, session management, and defenses against credential stuffing and account takeover.
Secure our APIs and mobile apps: authorization models, rate limiting, abuse controls, certificate pinning, and secure storage on device.
Secure the AI features we ship to customers: prompt injection defenses, tool permission boundaries, and data exposure controls for LLM-backed flows.
Prove It
Run the penetration testing and bug bounty programs. Triage, drive remediation, and close the loop with engineering.
Build vulnerability management that holds up in front of auditors: defined SLAs, tracked remediation, and evidence that stands on its own for PCI-DSS, SOC 2, and IPO-readiness controls.
Threat model new products and major features before they ship, not after.
Enable Engineering
Be the security engineer product engineers actually want in their design reviews. Clear answers, fast turnaround, real fixes.
Stand up and run a security champions program so AppSec scales past one person.
Build internal tooling, including AI-assisted review and triage, that multiplies the team's reach.
LAYIQ is an independent job-discovery service. This listing does not imply a partnership with or endorsement by the employer. Review the original posting for current details and availability.
Employer posted: