CybersecurityJobs.io
← Back to all jobs

Job Description

The Senior Security Engineer, Application Security will lead Kikoff’s Application Security pillar by shaping the AppSec roadmap and delivering practical security systems that protect customers while keeping engineering speed safe by default.

Responsibilities

  • Own and execute the application security roadmap, including secure SDLC, code review, threat modeling, vulnerability management, and the pentest and bug bounty programs.
  • Set the standard for secure code at Kikoff and build enforcement tooling, including SAST, SCA, secrets scanning, and dependency policies integrated into CI.
  • Define how AI-generated code is reviewed and gated, including controls for a codebase where agents act as contributors.
  • Deliver “paved road” security patterns in the frameworks engineers use, including authn/authz libraries, input validation, and safe defaults for common implementation patterns.
  • Drive security for authentication and session services, covering MFA design, account recovery, session management, and defenses against credential stuffing and account takeover.
  • Secure APIs and mobile applications, including authorization models, rate limiting, abuse controls, certificate pinning, and secure storage on device.
  • Secure AI features shipped to customers, including prompt injection defenses, tool permission boundaries, and data exposure controls for LLM-backed flows.
  • Run penetration testing and bug bounty programs by triaging findings, driving remediation, and closing the loop with engineering teams.
  • Build vulnerability management suitable for audit readiness, including defined SLAs, tracked remediation, and evidence aligned to PCI-DSS, SOC 2, and IPO-readiness control expectations.
  • Perform threat modeling for new products and major features before release.
  • Act as the security engineer product teams turn to during design reviews, delivering clear answers, fast turnaround, and actionable fixes.
  • Stand up and run a security champions program to scale AppSec beyond a single security owner.
  • Build internal tooling, including AI-assisted review and triage, to expand the team’s security coverage.

Requirements

  • 6+ years in security engineering with hands-on application security experience, including secure code review, threat modeling, vulnerability triage, and remediation at scale.
  • Ability to write production code, with fluency in at least one of Ruby, Python, Go, or TypeScript, and comfort reading all of them.
  • Experience designing and shipping authentication and authorization systems, including OAuth/OIDC, session management, MFA, and account recovery.
  • Hands-on experience with modern AppSec tooling and the judgment to evaluate results, including SAST, SCA, DAST, secrets scanning, and CI/CD integration.
  • Experience securing REST and GraphQL APIs as well as native mobile applications.
  • Experience running or building a pentest or bug bounty program.
  • Comfort operating in a fintech-regulated environment with PCI-DSS, SOC 2, or similar requirements.

Technologies

  • Ruby, Python, Go, TypeScript
  • SAST, SCA, secrets scanning, CI/CD, DAST
  • OAuth/OIDC, REST, GraphQL
  • PCI-DSS, SOC 2

Bonus Points

  • Securing LLM-backed product features or agentic workloads in production.
  • Fraud and abuse defense experience, including bot detection, credential stuffing mitigation, and device signals.
  • Experience creating security champions or developer education programs from scratch.
  • Supply chain security depth, including dependency provenance, artifact signing, and build integrity.
  • Consumer fintech or financial services background.

Location

San Francisco, CA (onsite)

Compensation

USD 268,000 - 321,000 per year

Similar Jobs