Klaviyo Lead Security Compliance Engineer at Klaviyo owns Trust & Compliance programs including audits, security policies, and control design. This role leads audit management end-to-end and mentors analysts on technical growth.
Responsibilities
Own internal and external audits and examinations end to end from scoping and readiness through fieldwork and evidence delivery; act as our primary point of contact for auditors and assessors, and develop action plans to correct findings and exceptions
Identify gaps against frameworks we do not yet meet, define the strategy to close them, and drive the implementation when Klaviyo takes on a new certification or regulation
Own security policies and standards end to end — author and maintain the policy, standard, and procedure hierarchy, decompose standards into testable requirements mapped to frameworks, and run the review, ratification, and exception management
Determine control design and implementation details for net-new controls, provide technical guidance to partner teams on control design best practices, and diagnose deficiencies by reviewing system configurations, technical documentation, security tool data, and occasionally application code
Define control health metrics and build the pipelines behind them from the systems we already run, so control health is a live signal rather than a quarterly assertion
Automate and streamline our Security Trust & Compliance workflows — control testing, continuous control monitoring, evidence collection, identity governance, and security Q&As for employees and customers — with a penchant for creating excellent self-service experiences, and define new approaches, systems, and tools for the team where none exist yet
Proactively identify internal and external risks and opportunities relevant to our Trust & Compliance programs, and propose the plans to address them
We'd love to hear from you if you have most of the following:
In-depth understanding of multiple security and privacy frameworks — such as NIST CSF 2.0, CIS Critical Security Controls, CSA STAR, ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 1, SOC 2, PCI, HIPAA, SOX ITGCs, GDPR, CCPA, and CPRA — including the ability to identify gaps against a framework that is new to the organization, define the strategy, and execute the implementation
A track record of personally owning security and privacy compliance audit programs end to end, including acting as the primary interface to internal and external auditors through scoping, walkthroughs, and findings resolution
Experience writing policies and standards that are precise enough to test and clear enough for engineers to follow, including ownership of the review and exception processes around them
Deep experience designing, assessing, and continuously monitoring modern security and privacy controls, including determining control design for net-new controls and diagnosing deficiencies from system configurations, technical documentation, security tool data, and application code
Qualification
Experience with SQLBuilding with agentic AI tooling (MCPRelevant certifications
Preferred
Familiarity with modern compliance automation or trust management platforms (Drata, Vanta, Anecdotes, HyperProof, etc.)
Experience with SQL, building tools with REST APIs, and Python
Infrastructure-as-code or policy-as-code experience (Terraform, OPA/Rego, Conftest)
Building with agentic AI tooling (MCP, agent skills, evals and guardrails) and/or governing AI controls against ISO 42001 or NIST AI RMF
Experience implementing Identity Governance tools and processes, such as for user access reviews (UARs) and just-in-time access (JITA)
Experience working in security operations, security engineering, and/or security architecture roles
Relevant certifications, such as CISA, CISSP, or CCSP