Klaviyo
Senior Manager - Security Risk Engineering
Boston, MA · Senior
Sponsorship not specified$180k-$270kDetected 29 days ago
PythonExpressSQLCloud PlatformsRESTMachine LearningData EngineeringLLMsCybersecurityComplianceStakeholder ManagementAuditingOnboardingCustomer SuccessCadenceZero TrustHIPAALeadershipMentoringInternal Audit
About the role
- Quantify risk in financial terms - expected loss, probability, and cost of remediation versus acceptance - so leadership can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels
- Set and continuously refine the risk cadence: weekly risk huddles with business functions, monthly risk reviews, and a quarterly Enterprise Risk Committee, connecting day-to-day execution to GSS and Klaviyo-level objectives
- Unlock third-party risk automation through a tiered vendor model - fast-tracking low-risk vendors while ensuring high-risk vendors receive deep due diligence, business reviews, and continuous monitoring
Responsibilities
- Visit klaviyo.com/careers to see how we empower creators to own their own destiny.
- Build the risk intelligence and automation capability - partnering closely with the team's risk intelligence lead, whose remit is risk intelligence and building automations using AI - to surface a continuously updated, quantified view of risk posture drawn from the live security tool estate (vulnerability, endpoint, third-party, data movement, and cyber risk quantification sources)
- You will operate as a credible, hands-on risk authority who can challenge and partner with engineering and security teams while maintaining independence from first-line delivery.
- You will build a team that thinks like risk engineers rather than traditional analysts - automating repeatable assessment, instrumenting controls, and applying AI as foundational infrastructure.
- You will partner with Engineering, Product, GTS, Legal, Audit, Finance, and the wider GSS organization to make risk legible across the business and to move Klaviyo's risk posture measurably forward.
- Own the risk register and taxonomy, establishing a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that aggregation, prioritisation, and reporting become meaningful
- Partner with Legal and Internal Audit on regulatory horizon scanning and on audit findings affecting systems and processes, tracking findings through to closure
- Maintain authoritative risk materials for GSS leadership, monthly KPI updates, and quarterly Board contributions - accurate, succinct, and decision-ready - translating high-severity findings into clear business impact
- Experience building and tracking security KPIs and metrics to measure success and drive continuous improvement
Requirements
- Working knowledge of security frameworks - NIST, ISO 27001, SOC 2, ISO 42001, PCI DSS, CIS Controls - and how they translate into credible control requirements and delivery plans
Nice to have
- Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability
- Experience in a regulated or high-trust environment (e.g. SOC 2, ISO 27001, ISO 42001, HIPAA, GDPR) and familiarity with the regulatory expectations affecting technology and cybersecurity risk
- Exposure to AI governance, model risk, or responsible-AI program work
- Familiarity with operational resilience and third-party risk beyond cybersecurity alone
- Experience with Python, SQL, and REST APIs to build automated data ingestion pipelines, query security telemetry, and programmatically orchestrate risk reporting
- Hands-on experience in SecOps, AppSec, or Security Architecture - with a focus on threat modeling, Zero Trust architecture, and data governance
- Experience working with security and risk tooling in cloud infrastructure, hosting, and platform contexts
- Massachusetts Applicants:
Compensation
- This role may require up to 10% travel for purposes such as new hire onboarding, client or partner work if applicable, team meetings, and industry events.
- Travel is coordinated in advance.
- We're Klaviyo (pronounced clay-vee-oh).
- We empower creators to own their destiny by making first-party data accessible and actionable like never before.
- We see limitless potential for the technology we're developing to nurture personalized experiences in ecommerce and beyond.
- To reach our goals, we need our own crew of remarkable creators-ambitious and collaborative teammates who stay focused on our north star: delighting our customers.
- Our salary range reflects the cost of labor across various U.S. geographic markets.
Benefits
- If you're ready to do the best work of your career, where you'll be welcomed as your whole self from day one and supported with generous benefits, we hope you
- The base salary offered for this position is determined by several factors, including the applicant's job-related skills, relevant experience, education or training, and work location.
Company info
- An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services.
- This is achieved by providing a robust and secure technology foundation to do great work.
- We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.
- The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts.
- The STAR team is highly collaborative and cross-functional, working closely with various functions within the GSS team (namely Security Product and Development and Security Intelligence Operations), Global Technology Solutions (GTS) team and the broader Klaviyo organization.
- At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day.
Apply directly at Klaviyo →Create a free account for alerts like thisView Klaviyo immigration profile
This listing is sourced directly from Klaviyo's careers page and normalized into a canonical job model.