Avatar for Klaviyo
Klaviyo
Actively Hiring
Klaviyo is the AI-first CRM built for B2C brands
  • B2B
  • Public Stage
    Publicly traded company
  • Top Investors
    This company has received a significant amount of investment from top investors
  • +3

Lead Security Compliance Engineer

  • $140k – $210k
  • |
  • |Full Time
Posted: 1 day ago• Recruiter recently active
Job Location
Visa Sponsorship

Not Available

RelocationNot Allowed
Hiring contact
Danica Balslev
Employee
image

About the job

At Klaviyo, we're on a mission to empower creators to own their destiny. Our AI-first B2C CRM platform empowers 176,000+ brands in 80+ countries to cultivate relationships with hundreds of millions of consumers. We love solving hard problems and look for people who specialize in certain areas while being passionate about building, owning, and scaling solutions end-to-end, overcoming any obstacle in their way. We are a team of ambitious, customer-obsessed peers who are insatiably curious and meticulous in our craft. We push each other to grow beyond our comfort zone, learn new things, and work hard to ensure each day is better than the last.

As a Lead Security Trust & Compliance Engineer at Klaviyo, you'll be the primary owner of two or more of our Trust & Compliance programs — compliance operations & audits, continuous control monitoring, security policies & standards, security education & awareness, and customer trust operations among them. You'll set the strategy for the programs you own, run our audits end to end, engineer the controls and evidence pipelines that make them sustainable, and raise the technical bar for the practitioners around you. You won't have direct reports, but you will tactically lead the team on your programs: delegating work, setting teammates up to succeed, and mentoring analysts on their technical growth and career goals. This is your opportunity to take a leading role in cybersecurity, applying and deepening your expertise in security automation, risk analysis, control design, audit management, modern SaaS platform architectures, and many domains of information security (just about all of them!)

What you'll be doing

  • Own internal and external audits and examinations end to end from scoping and readiness through fieldwork and evidence delivery; act as our primary point of contact for auditors and assessors, and develop action plans to correct findings and exceptions
  • Identify gaps against frameworks we do not yet meet, define the strategy to close them, and drive the implementation when Klaviyo takes on a new certification or regulation
  • Own security policies and standards end to end — author and maintain the policy, standard, and procedure hierarchy, decompose standards into testable requirements mapped to frameworks, and run the review, ratification, and exception management
  • Determine control design and implementation details for net-new controls, provide technical guidance to partner teams on control design best practices, and diagnose deficiencies by reviewing system configurations, technical documentation, security tool data, and occasionally application code
  • Define control health metrics and build the pipelines behind them from the systems we already run, so control health is a live signal rather than a quarterly assertion
  • Automate and streamline our Security Trust & Compliance workflows — control testing, continuous control monitoring, evidence collection, identity governance, and security Q&As for employees and customers — with a penchant for creating excellent self-service experiences, and define new approaches, systems, and tools for the team where none exist yet
  • Proactively identify internal and external risks and opportunities relevant to our Trust & Compliance programs, and propose the plans to address them

We'd love to hear from you if you have most of the following:

  • In-depth understanding of multiple security and privacy frameworks — such as NIST CSF 2.0, CIS Critical Security Controls, CSA STAR, ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 1, SOC 2, PCI, HIPAA, SOX ITGCs, GDPR, CCPA, and CPRA — including the ability to identify gaps against a framework that is new to the organization, define the strategy, and execute the implementation
  • A track record of personally owning security and privacy compliance audit programs end to end, including acting as the primary interface to internal and external auditors through scoping, walkthroughs, and findings resolution
  • Experience writing policies and standards that are precise enough to test and clear enough for engineers to follow, including ownership of the review and exception processes around them
  • Deep experience designing, assessing, and continuously monitoring modern security and privacy controls, including determining control design for net-new controls and diagnosing deficiencies from system configurations, technical documentation, security tool data, and application code
  • Experience with GRC engineering and security automation in general, especially applying AI and automation to eliminate toil
  • Knowledge of various enterprise SaaS applications, cloud infrastructure such as AWS and Kubernetes, modern software engineering practices/tools, databases, operating systems, secure network design, and other technology relevant to cybersecurity
  • Experience owning programs against defined KPIs and SLAs, including setting quarterly strategy, planning the work, and reporting on progress
  • A track record of mentoring practitioners, delegating effectively, and driving technical direction without formal authority
  • Excellent interpersonal and communication skills and the ability to form relationships with internal and external teams.

Bonus points if you have any of the following:

  • Familiarity with modern compliance automation or trust management platforms (Drata, Vanta, Anecdotes, HyperProof, etc.)
  • Experience with SQL, building tools with REST APIs, and Python
  • Infrastructure-as-code or policy-as-code experience (Terraform, OPA/Rego, Conftest)
  • Building with agentic AI tooling (MCP, agent skills, evals and guardrails) and/or governing AI controls against ISO 42001 or NIST AI RMF
  • Experience implementing Identity Governance tools and processes, such as for user access reviews (UARs) and just-in-time access (JITA)
  • Experience working in security operations, security engineering, and/or security architecture roles
  • Relevant certifications, such as CISA, CISSP, or CCSP

Everyone on our team needs to have the following:

  • Ability to effectively prioritize and execute tasks in a high-pressure environment
  • Solutions oriented mindset
  • Excellent verbal and written communication
  • Working collaboratively inside and outside your direct team
  • Strong alignment with Klaviyo’s core values

About the company

Klaviyo company logo

Klaviyo

Actively Hiring
Klaviyo is the AI-first CRM built for B2C brands1001-5000 Employees
Company Size
1001-5000
Company Type
SaaS
Company Type
Enterprise Software Company
Company Type
Email Marketing
Company Type
Analytics
  • B2B
  • Public Stage
    Publicly traded company
  • Top Investors
    This company has received a significant amount of investment from top investors
  • 4.6
    Highly rated
    Klaviyo is highly rated on Glassdoor, with 4.6 out of 5 stars
  • 4.5
    Work / Life Balance
    Employees rate Klaviyo 4.5/5 on Glassdoor for work / life balance
  • 4.6
    Strong Leadership
    Employees rate Klaviyo 4.6/5 on Glassdoor for faith in leadership
Learn more about Klaviyo image

Funding

AMOUNT RAISED
$678.5M
FUNDED OVER
5 rounds
Rounds
D
$320000000
Series D - Apr 2021+4

Perks

Healthcare benefits
401k plan & match
16 Weeks Paid Parental Leave
Equity benefits
Unlimited PTO
Company meals
Wellness Benefits
Commuter benefits
Professional development

Founders

Ed Hallen
Founder
Boulder
image
Andrew Bialecki
Founder
Boston
image
View the team image

Similar Jobs

Archesys company logo
Archesys
Improving the government services that impact everyday lives
tribe.ai company logo
tribe.ai
We embed elite AI engineers to ship real, production-grade AI for enterprises
Pattern Labs company logo
Pattern Labs
An Adventure in Unstructured Autonomous Mobility
Boom Supersonic company logo
Boom Supersonic
Building the world's fastest civil aircraft using supersonic technology
Boom Supersonic company logo
Boom Supersonic
Building the world's fastest civil aircraft using supersonic technology
Boom Supersonic company logo
Boom Supersonic
Building the world's fastest civil aircraft using supersonic technology