Lead Security Governance & Risk EngineerActive$234K

The opportunity

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements.

What you'll do

  • Operate and maintain the risk register and taxonomy. Run the technology and: third-party risk register on a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that risks aggregate, prioritise, and report meaningfully across the business.

  • Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk: assessment methodology and risk criteria, maintain the consolidated AI risk register against the K:AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions. Drive ISO/IEC 42001 readiness (Clauses 6.1 and 8.2/8.3) toward the certification target, working with the Trust & Compliance and ARIA teams.

  • Drive third-party risk automation and risk scoring. Contribute vendor and: application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.

  • Perform the hands-on risk quantification. Apply cyber risk quantification: (expected loss, probability, and cost of remediation versus acceptance) so leadership and the Technology Risk Committee can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels.

  • Support the risk governance cadence. Contribute to weekly risk huddles,: monthly risk reviews, and the quarterly Technology Risk Committee (CIO, CISO, CTO), preparing accurate, succinct, decision-ready risk materials and translating high-severity findings into clear business impact.

  • Operate as a second line of defense. Provide independent oversight, credible: challenge, and guidance to first-line teams, apply consistent risk taxonomies and reporting standards, and escalate risks that exceed established tolerance.

What they're looking for

  • Partner cross-functionally and close the loop. Work with Engineering,: Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings affecting systems and processes, tracking findings and remediation through to closure with clear ownership.
  • + years of experience in information security, technology risk, cyber risk,: or operational risk within a large, complex, or high-growth organization, including hands-on risk engineering or quantitative risk work.
  • Strong command of cyber risk quantification, able to express risk in: financial and business terms (FAIR, riskquant, or similar) rather than qualitative severity ratings alone.
  • Hands-on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems and to automate risk reporting.