Klaviyo Logo

Klaviyo

Lead Security Risk Analyst

Job Posted 20 Days Ago Reposted 20 Days Ago
Hybrid
San Francisco, CA
140K-210K Annually
Senior level
Hybrid
San Francisco, CA
140K-210K Annually
Senior level
The Lead Security Risk Analyst will enhance the risk management function, focusing on risk assessments, metrics development, and secure project guidance while fostering cross-department collaboration to ensure effective risk mitigation.
The summary above was generated by AI

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you're a close but not exact match with the description, we hope you'll still consider applying. Want to learn more about life at Klaviyo? Visit careers.klaviyo.com to see how we empower creators to own their own destiny.
We're seeking a highly motivated Lead Security Risk Analyst who will help us continue to evolve our Risk function by using engineering principles and data-driven strategies to precisely identify, understand, communicate, and prioritize mitigation of risk. This role will start out primarily focused on a subset of our Risk programs: internal security risk management (risk discovery, assessment, and governance) and security metrics (analysis, curation, reporting)
You'll partner closely with Engineering, IT, Security, Leadership, and basically every other team at Klaviyo to create a holistic view of risk based on high quality data about our assets, weaknesses, threats, and safeguards (controls). You'll help your fellow Klaviyos identify, understand, prioritize, and manage risks that they own. You will help evolve our risk management practices to be transparent and centered around evidence-based risk models. Through all of this, you'll help Klaviyo scale securely and sustainably deliver value for our customers.
What you'll be doing

  • Lead and execute new Risk program maturity projects that introduce more rigorous, streamlined, and automated approaches to risk management
  • Partner with other departments and teams to drive mutual understanding of security risks they own and how to prioritize managing those risks in support of Klaviyo's goals
  • Create, tune, and operationalize business relevant security metrics (KPIs, KRIs, KCIs) that demonstrably improve security outcomes across Klaviyo
  • Review new products, product features, and internal business projects to guide teams toward secure paths forward and away from accruing new security debt
  • Collaboratively define and enable teams about security policies and standards that clearly establish Klaviyo's risk tolerance bar


We'd love to hear from you if you have most of the following:

  • Experience doing security risk assessments, co-creating risk treatment strategies, and influencing risk treatment prioritization across diverse business units (Engineering, IT, Finance, Legal, etc.)
  • Thorough understanding of cloud-native web application architectures, security threats, and security best practices, especially in the context of AWS and Kubernetes
  • Experience using data visualization tools and SQL to build and operationalize security metrics (e.g. Apache Superset, Tableau, Domo, Amazon QuickSight)
  • Experience with scalable approaches to threat modeling, secure design reviews, and risk assessment methods that balance rigor and efficiency (e.g. Mozilla's Rapid Risk Assessment)
  • Experience with security automation and process streamlining, ideally in the context of security risk management


Everyone on our team must have:

  • A strong bias toward evidence, logic, math, and reason when communicating risk (instead of fear, uncertainty, and doubt)
  • A strong bias toward "guardrails, not gates" and "paved security roads" philosophies (instead of rigid "centralized command-and-control" thinking)
  • Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
  • Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineering teams
  • Strong alignment with Klaviyo's core values


Bonus points if you have any of the following:

  • Experience building tools with REST APIs and Python
  • Experience with data engineering tools (e.g. dbt, Airflow, Airbyte) or data lake platforms (e.g. Snowflake, Databricks)
  • Experience with cyber risk quantification (CRQ) tools and frameworks (e.g. FAIR, RiskLens, Safe Security, etc.)


Massachusetts Applicants:
It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.
The pay range for this role is listed below. Some sales and success roles are also eligible for variable compensation and hourly non-exempt roles are eligible for overtime in accordance with applicable law. This role is eligible for benefits, including: medical, dental and vision coverage, health savings accounts, flexible spending accounts, 401(k), flexible paid time off and company-paid holidays and a culture of learning that includes a learning allowance and access to a professional coaching service for all employees.
Base Pay Range For US Locations:
$140,000 - $210,000 USD
Get to Know Klaviyo
We're Klaviyo (pronounced clay-vee-oh). We empower creators to own their destiny by making first-party data accessible and actionable like never before. We see limitless potential for the technology we're developing to nurture personalized experiences in ecommerce and beyond. To reach our goals, we need our own crew of remarkable creators-ambitious and collaborative teammates who stay focused on our north star: delighting our customers. If you're ready to do the best work of your career, where you'll be welcomed as your whole self from day one and supported with generous benefits, we hope you'll join us.
Klaviyo is committed to a policy of equal opportunity and non-discrimination. We do not discriminate on the basis of race, ethnicity, citizenship, national origin, color, religion or religious creed, age, sex (including pregnancy), gender identity, sexual orientation, physical or mental disability, veteran or active military status, marital status, criminal record, genetics, retaliation, sexual harassment or any other characteristic protected by applicable law.
IMPORTANT NOTICE: Our company takes the security and privacy of job applicants very seriously. We will never ask for payment, bank details, or personal financial information as part of the application process. All our legitimate job postings can be found on our official career site. Please be cautious of job offers that come from non-company email addresses (@klaviyo.com), instant messaging platforms, or unsolicited calls.
By clicking "Submit Application" you consent to Klaviyo processing your Personal Data in accordance with our Job Applicant Privacy Notice. If you do not wish for Klaviyo to process your Personal Data, please do not submit an application.

Top Skills

Airbyte
Airflow
Amazon Quicksight
Apache Superset
AWS
Databricks
Dbt
Domo
Kubernetes
Python
Snowflake
SQL
Tableau

Klaviyo San Francisco, California, USA Office

181 Fremont Street, Floor 21, San Francisco, CA , United States, 94105

Similar Jobs at Klaviyo

Yesterday
Hybrid
San Francisco, CA, USA
152K-228K Annually
Senior level
152K-228K Annually
Senior level
Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
The Senior Security Engineer leads incident response efforts, performs digital forensics, automates workflows, and collaborates to enhance security across cloud environments.
Top Skills: AWSAzureGCPGoPythonSnowflakeSplunk
Yesterday
Hybrid
San Francisco, CA, USA
152K-228K Annually
Senior level
152K-228K Annually
Senior level
Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
As a Senior Security Engineer, you will secure IT infrastructure focusing on Google Cloud Platform (GCP), implement security measures, and collaborate with teams for compliance and threat response.
Top Skills: Chronicle Security AnalyticsCloud Endpoint ProtectionCloud Key Management ServiceCloud Security Command CenterFirewallsGoogle Cloud IamGoogle Cloud Platform (Gcp)Intrusion Detection SystemsOrganization Policies
3 Days Ago
Hybrid
San Francisco, CA, USA
120K-180K Annually
Mid level
120K-180K Annually
Mid level
Consumer Web • eCommerce • Marketing Tech • Retail • Software • Analytics • Generative AI
As a Security Engineer in the Detection & Response Team at Klaviyo, you will develop and deploy detection mechanisms, perform attack path analysis, automate security processes, and support threat detection and incident response across cloud and corporate environments. Your role includes collaboration with cross-functional teams to enhance the infrastructure's security posture.

What you need to know about the San Francisco Tech Scene

San Francisco and the surrounding Bay Area attracts more startup funding than any other region in the world. Home to Stanford University and UC Berkeley, leading VC firms and several of the world’s most valuable companies, the Bay Area is the place to go for anyone looking to make it big in the tech industry. That said, San Francisco has a lot to offer beyond technology thanks to a thriving art and music scene, excellent food and a short drive to several of the country’s most beautiful recreational areas.

Key Facts About San Francisco Tech

  • Number of Tech Workers: 365,500; 13.9% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Google, Apple, Salesforce, Meta
  • Key Industries: Artificial intelligence, cloud computing, fintech, consumer technology, software
  • Funding Landscape: $50.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Sequoia Capital, Andreessen Horowitz, Bessemer Venture Partners, Greylock Partners, Khosla Ventures, Kleiner Perkins
  • Research Centers and Universities: Stanford University; University of California, Berkeley; University of San Francisco; Santa Clara University; Ames Research Center; Center for AI Safety; California Institute for Regenerative Medicine
By clicking Apply you agree to share your profile information with the hiring company.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account