Staff Detection & Response Engineer

Kikoff
San Francisco
Workplace: OnsiteFull timeUSD 337,700 - 387,200Function: Solutions Engineering & Sales EngineeringExperience: 6+ yearsSkills: ["Extreme ownership","Clear communication","Craftsmanship","Threat modeling","Incident leadership","Automation mindset","Incident triage","Forensics mindset","Runbook-driven operations"]

Own the Detection & Response pillar end to end—define the roadmap, detection strategy, and metrics that prove coverage. Build and maintain detection coverage across AWS, endpoints, identity, SaaS, and CI/CD, writing detections as code with strong signal quality. Lead the incident response lifecycle (triage through remediation), level up incident workflows in incident.io, and run technical investigations in a fintech environment handling sensitive financial data.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Kikoff
Kikoff
1 hour ago

Staff Detection & Response Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 1 hour agoStatus: Live

Job Summary

Own the Detection & Response pillar end to end—define the roadmap, detection strategy, and metrics that prove coverage. Build and maintain detection coverage across AWS, endpoints, identity, SaaS, and CI/CD, writing detections as code with strong signal quality. Lead the incident response lifecycle (triage through remediation), level up incident workflows in incident.io, and run technical investigations in a fintech environment handling sensitive financial data.
Location: San Francisco
Workplace: Onsite
Employment Type: Full time
Job Function: Solutions Engineering & Sales Engineering
Seniority: Mid level

Key Responsibilities

  • •Own the detection & response roadmap end to end, including telemetry strategy, detection engineering, alert quality, response process, and coverage metrics.
  • •Define detection architecture (what to log, where it lands, and which capabilities to build vs buy).
  • •Design and maintain detection coverage across AWS, endpoints (SentinelOne EDR), identity (Okta), SaaS, and CI/CD.
  • •Write detections as code and maintain versioned, tested detections mapped to real threats for a consumer fintech.
  • •Own the incident response lifecycle (triage, containment, forensics, postmortem, and remediation tracking) and lead technical investigations.

Pay and Benefits

Salary: USD 337,700 - 387,200

Key Requirements

  • •6+ years in security with detection engineering and incident response experience in cloud-native environments (AWS strongly preferred).
  • •Written detections yourself (SIEM rules or detection-as-code pipelines) and owned false-positive rate.
  • •Hands-on incident response experience leading real incidents.
  • •Strong command of cloud-native logging and detection surfaces.
  • •Fluency in at least one automation language (Python, Go, Ruby, or similar) and comfort in a regulated fintech environment.
Experience:6+ yearsCloud-nativeFintechFinancial servicesIncident responseDetection engineeringAI/LLMEndpoint security
Skills:Extreme ownershipClear communicationCraftsmanshipThreat modelingIncident leadershipAutomation mindsetIncident triageForensics mindsetRunbook-driven operations
Tech Stack:AWSCloudTrailGuardDutyVPC flowSentinelOneEDROktaCI/CDPythonGoRubySIEMIncident.ioMITRE

Company Brief

Kikoff
Kikoff provides a credit-building product that helps consumers build credit history and access affordable lines of credit through a mobile-first platform and educational tools to improve financial health.
Industry: Lending
Growth: Early Stage Startup
Headquarters: San Francisco, United States
Founded: 2019
Website