InternFlow

Greenhouse ·

full-time

Lead Security Compliance Engineer

Klaviyo · Boston, MA

Klaviyo is a company providing an AI-first B2C CRM platform that enables brands to manage consumer relationships. The Lead Security Compliance Engineer role involves managing trust and compliance programs, including audit operations, continuous control monitoring, and the development of security policies and standards. The person in this position will act as the primary owner for multiple compliance domains, driving internal and external audits from scoping through to evidence delivery. Day-to-day responsibilities include designing security controls, automating compliance workflows, and building pipelines to monitor control health. While the role does not involve direct reports, it requires providing technical leadership, mentoring team members, and guiding partner teams on control design best practices. This position is well-suited for a security professional with deep expertise in frameworks such as NIST CSF and CIS, who is comfortable navigating modern SaaS architectures and possesses a strong aptitude for security automation and risk analysis. Candidates should be prepared to define strategy, manage cross-functional relationships, and improve security posture through technical implementation and policy governance.

security compliancesaas securityaudit managementnist csfsecurity automationrisk analysiscontrol designinformation security

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you’re a close but not exact match with the description, we hope you’ll still consider applying. Want to learn more about life at Klaviyo? Visit klaviyo.com/careers to see how we empower creators to own their own destiny. At Klaviyo, we're on a mission to empower creators to own their destiny. Our AI-first B2C CRM platform empowers 176,000+ brands in 80+ countries to cultivate relationships with hundreds of millions of consumers. We love solving hard problems and look for people who specialize in certain areas while being passionate about building, owning, and scaling solutions end-to-end, overcoming any obstacle in their way. We are a team of ambitious, customer-obsessed peers who are insatiably curious and meticulous in our craft. We push each other to grow beyond our comfort zone, learn new things, and work hard to ensure each day is better than the last. As a Lead Security Trust & Compliance Engineer at Klaviyo, you'll be the primary owner of two or more of our Trust & Compliance programs — compliance operations & audits, continuous control monitoring, security policies & standards, security education & awareness, and customer trust operations among them. You'll set the strategy for the programs you own, run our audits end to end, engineer the controls and evidence pipelines that make them sustainable, and raise the technical bar for the practitioners around you. You won't have direct reports, but you will tactically lead the team on your programs: delegating work, setting teammates up to succeed, and mentoring analysts on their technical growth and career goals. This is your opportunity to take a leading role in cybersecurity, applying and deepening your expertise in security automation, risk analysis, control design, audit management, modern SaaS platform architectures, and many domains of information security (just about all of them!) What you'll be doing Own internal and external audits and examinations end to end from scoping and readiness through fieldwork and evidence delivery; act as our primary point of contact for auditors and assessors, and develop action plans to correct findings and exceptions Identify gaps against frameworks we do not yet meet, define the strategy to close them, and drive the implementation when Klaviyo takes on a new certification or regulation Own security policies and standards end to end — author and maintain the policy, standard, and procedure hierarchy, decompose standards into testable requirements mapped to frameworks, and run the review, ratification, and exception management Determine control design and implementation details for net-new controls, provide technical guidance to partner teams on control design best practices, and diagnose deficiencies by reviewing system configurations, technical documentation, security tool data, and occasionally application code Define control health metrics and build the pipelines behind them from the systems we already run, so control health is a live signal rather than a quarterly assertion Automate and streamline our Security Trust & Compliance workflows — control testing, continuous control monitoring, evidence collection, identity governance, and security Q&As for employees and customers — with a penchant for creating excellent self-service experiences, and define new approaches, systems, and tools for the team where none exist yet Proactively identify internal and external risks and opportunities relevant to our Trust & Compliance programs, and propose the plans to address them We'd love to hear from you if you have most of the following: In-depth understanding of multiple security and privacy frameworks — such as NIST CSF 2.0, CIS Critical Security Controls, CSA STAR, ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 1, SOC 2, PCI, HIPAA, SOX ITGCs, GDPR, CCPA, and CPRA — including the ability to identify gaps against a framework that is new to the organization, define the strategy, and execute the implementation A track record of personally owning security and privacy compliance audit programs end to end, including acting as the primary interface to internal and external auditors through scoping, walkthroughs, and findings resolution Experience writing policies and standards that are precise enough to test and clear enough for engineers to follow, including ownership of the review and exception processes around them Deep experience designing, assessing, and continuously monitoring modern security and privacy controls, including determining control design for net-new controls and diagnosing deficiencies from system configurations, technical documentation, security tool data, and application code Experi

RoleLead Security Compliance Engineer
CompanyKlaviyo
LocationBoston, MA
CompensationNot disclosed
Posted2026-09-22
DeadlineRolling

Typical process for this type of role

A general guide — the exact steps for this specific listing may vary; check the original posting for details.

  1. 1ApplicationSubmit your resume through the apply link.
  2. 2ScreeningRecruiter reviews your background against the role.
  3. 3AssessmentA technical test, assignment, or coding round, depending on the role.
  4. 4Interview(s)One or more rounds with the hiring team.
  5. 5OfferOffer letter with compensation and start date.

Before you apply

0/4

About Klaviyo

Klaviyo, Inc. is an AI-first B2C CRM platform founded in 2012 and headquartered in Boston. The company provides a unified solution that integrates marketing automation, customer service, analytics, and a data platform to help businesses manage customer relationships. By centralizing behavioral, transactional, and engagement data, Klaviyo enables brands to deliver personalized, omnichannel campaigns across email, SMS, WhatsApp, and mobile push notifications. The platform utilizes AI agents to automate marketing tasks, resolve customer service inquiries, and optimize campaign performance. Klaviyo currently serves over 205,000 brands across more than 100 countries, processing billions of events and managing billions of customer profiles daily to support business growth.

All jobs and hiring details at Klaviyoklaviyo.com

More at Klaviyo

Other jobs at Klaviyo

See all 32 openings at Klaviyo

Explore Related Placements


// similar opportunities

You might also like

Lead Security Compliance Engineer

Klaviyo

Klaviyo logo
Denver, COfull-time
Any GraduateGreenhouseSecurity Compliance# Security Automation# Risk Analysis# Control Design# Audit Management+7 more

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. ...

Apply now →

Security Compliance Lead

Asana

Asana logo
San Franciscofull-time
HybridAny GraduateGreenhouseSecurity Compliance# FedRAMP# GRC# SOC 2# ISO 27001+3 more

Role Overview As a Security Risk and Compliance Lead you will play a hands-on role in maturing and operating Asana's compliance and certification programme—with...

Hybrid schedule with mandatory in‑office days Monday, Tuesday, Thursday

Apply now →

Senior Security Engineer

Mixpanel

London, UK (Hybrid)full-time
Greenhouse

About Mixpanel Mixpanel is the leading product intelligence and analytics platform, trusted by more than 29,000 companies to help understand how people use the ...

Apply now →

Product Security Engineer - Lead Engineer

Japan Dev

Japan Dev logo
Unspecifiedfull-time
Any GraduateJapandev

Product Security Engineer - Lead Engineer...

0-1 year experience eligible.

Apply now →

Security Risk & Compliance, Agent Security

Anthropic

San Francisco, CA | New York City, NYfull-time
Greenhouse

About Anthropic Anthropic’s mission is to create reliable, interpretable, and steerable AI systems. We want AI to be safe and beneficial for our users and for s...

Apply now →

Lead Security Engineer

Encord

Encord logo
Londonfull-time
Arbeitnow

About us Encord is the universal data layer for AI that helps 300+ AI teams train and run models on the right data. Our platform indexes, curates, annotates, an...

Apply now →