Lead Security Compliance EngineerNew$210K

The opportunity

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements.

What you'll do

  • Own internal and external audits and examinations end to end from scoping and: readiness through fieldwork and evidence delivery; act as our primary point of contact for auditors and assessors, and develop action plans to correct findings and exceptions

  • Identify gaps against frameworks we do not yet meet, define the strategy to: close them, and drive the implementation when Klaviyo takes on a new certification or regulation

  • Own security policies and standards end to end: author and maintain the policy, standard, and procedure hierarchy, decompose standards into testable requirements mapped to frameworks, and run the review, ratification, and exception management

  • Determine control design and implementation details for net-new controls,: provide technical guidance to partner teams on control design best practices, and diagnose deficiencies by reviewing system configurations, technical documentation, security tool data, and occasionally application code

  • Define control health metrics and build the pipelines behind them from the: systems we already run, so control health is a live signal rather than a quarterly assertion

  • Automate and streamline our Security Trust & Compliance workflows: control testing, continuous control monitoring, evidence collection, identity governance, and security Q&As for employees and customers — with a penchant for creating excellent self-service experiences, and define new approaches, systems, and tools for the team where none exist yet

What they're looking for

  • Proactively identify internal and external risks and opportunities relevant: to our Trust & Compliance programs, and propose the plans to address them
  • In-depth understanding of multiple security and privacy frameworks: such as NIST CSF 2.0, CIS Critical Security Controls, CSA STAR, ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 1, SOC 2, PCI, HIPAA, SOX ITGCs, GDPR, CCPA, and CPRA — including the ability to identify gaps against a framework that is new to the organization, define the strategy, and execute the implementation
  • A track record of personally owning security and privacy compliance audit: programs end to end, including acting as the primary interface to internal and external auditors through scoping, walkthroughs, and findings resolution
  • Experience writing policies and standards that are precise enough to test and: clear enough for engineers to follow, including ownership of the review and exception processes around them