
Overview
Kin is looking for a Senior Security Engineer to run security operations at our fully cloud-based company. As a remote-first organization with employees spread across more than 35 states, our endpoints and identity management are our front line.
This is a hands-on role where you will own endpoint detection and cloud security, tune out the noise, lock down AWS, and build security champions across Kin.
Responsibilities
- Security Operations: Own and tune our EDR/MDR stack, building detection policies, runbooks, and automation to keep escalations focused on real threats.
- Incident Response: Lead incident response end to end (investigation, containment, and remediation) from compromised laptops to cloud and identity incidents.
- Endpoint Security: Own endpoint security across managed and BYOD devices, setting device posture standards, hardening baselines, and governing data access.
- Identity & Access Management: Define security requirements for our identity program, partner with IT to implement SSO controls, shape our RBAC model, and drive access reviews.
- Cloud Security: Build and remediate security controls across AWS infrastructure, Google Workspace, identity, and data protection.
- Security Enablement: Serve as the front door for security across Kin, turning around tickets and questions quickly to foster a proactive security culture.
- Risk Management: Conduct threat modeling across systems, processes, and vendor implementations to deliver actionable risk assessments.
What We're Looking For
- 5+ years of experience in security operations, detection and response, or security engineering
- Hands-on experience running a modern EDR program, writing response runbooks, and leading investigations
- Endpoint security expertise across managed and BYOD fleets, including MDM and hardening baselines
- Identity and access management depth (RBAC, SSO, access reviews)
- AWS security experience (IAM, network controls, logging, configuration management) with direct remediation capabilities
- Comfort working in infrastructure-as-code environments and automating security tasks
- Threat modeling experience across systems, processes, or vendor implementations
- Strong communication skills to explain security risks to non-technical audiences
Bonus Qualifications
- Terraform and CI/CD pipeline experience
- Zero trust networking experience
- Working knowledge of NIST, ISO 27001, SOC 2, and SOX compliance
- Experience securing a fully remote workforce
- Google Workspace security administration experience
- Relevant security certifications (AWS Certified Security Specialty, GCIH, GCIA)
Timezone overlap
UTC-8β-4
Benefits
Equity, RSUs, 401k, Health, Dental, Vision, Mental health, PTO, Parental leave, Learning, Bonus, Unlimited PTO, Wellness, Equipment
Open to
US
Sign in to track applications and earn points.