Klaviyo

Klaviyo

Lead Security Governance & Risk Engineer

Boston, MA

Sponsorship not specified$156k-$234kDetected 7 days ago
PythonExpressSQLKubernetesData VisualizationCybersecurityComplianceAuditingOnboardingCustomer SuccessHIPAALeadershipInternal AuditCISSP

About the role

  • This is a role for an engineer who thinks like a risk professional: someone who automates repeatable assessment, instruments controls, quantifies risk in financial terms, and treats AI as foundational infrastructure rather than an afterthought.
  • Run the technology and third-party risk register on a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that risks aggregate, prioritise, and report meaningfully across the business.
  • Contribute to weekly risk huddles, monthly risk reviews, and the quarterly Technology Risk Committee (CIO, CISO, CTO), preparing accurate, succinct, decision-ready risk materials and translating high-severity findings into clear business impact.

Responsibilities

  • Operate and maintain the risk register and taxonomy.
  • Lead AI risk governance and ISO 42001 readiness.
  • Maintain the AI risk assessment methodology and risk criteria, maintain the consolidated AI risk register against the K:AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions.
  • Drive ISO/IEC 42001 readiness (Clauses 6.1 and 8.2/8.3) toward the certification target, working with the Trust & Compliance and ARIA teams.
  • Drive third-party risk automation and risk scoring. Contribute vendor and application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.
  • Perform the hands-on risk quantification.
  • Support the risk governance cadence.
  • Partner cross-functionally and close the loop. Work with Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings affecting systems and processes, tracking findings and remediation through to closure with clear ownership.
  • You will own the parts of the risk programme that turn policy and standards into measured, monitored, and automated risk decisions.
  • This role may require up to 10% travel for purposes such as new hire onboarding, client or partner work if applicable, team meetings, and industry events.

Requirements

  • 7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high-growth organization, including hands-on risk engineering or quantitative risk work.
  • Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls) and how they translate into credible control requirements.
  • Experience authoring and maintaining security policies and standards, with a governance mindset that ties policy to the risk it reduces and to operational controls.
  • Proficiency discussing complex, nuanced topics with technical and non-technical audiences alike, and translating technical risk into clear business impact.
  • Excellent ability to plan, prioritise, and execute work cross-functionally and on time.

Nice to have

  • Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability.
  • AI governance, model risk, or responsible-AI programme experience, and ISO 42001 readiness or certification work.
  • Experience in a regulated or high-trust environment (SOC 2, ISO 27000 series, ISO 42001, HIPAA, GDPR).
  • Experience securing web applications, Kubernetes clusters, and/or containers.
  • Massachusetts Applicants:
  • It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment.
  • An employer who violates this law shall be subject to criminal penalties and civil liability.
  • Travel is coordinated in advance.

Compensation

  • $156,000 - $234,000 USD

Company info

  • At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day.

This listing is sourced directly from Klaviyo's careers page and normalized into a canonical job model.