×
Register Here to Apply for Jobs or Post Jobs. X

Lead Security Governance & Risk Engineer

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: Triwill Group
Full Time position
Listed on 2026-07-22
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 156000 - 234000 USD Yearly USD 156000.00 234000.00 YEAR
Job Description & How to Apply Below

About the role

The Lead Security Governance & Risk Engineer is a senior, hands‑on role where security governance meets risk engineering. You will own the parts of the risk programme that turn policy and standards into measured, monitored, and automated risk decisions. Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third‑party risk register, lead AI risk governance and ISO 42001 readiness, and build the automation that gives Klaviyo a continuously updated, quantified view of its risk posture.

How

you’ll have an impact
  • Operate and maintain the risk register and taxonomy. Run the technology and third‑party risk register on a consistent standard so that risks aggregate, prioritize, and report meaningfully across the business.
  • Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and risk criteria, maintain the consolidated AI risk register against the K:

    AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions. Drive ISO/IEC 42001 readiness toward the certification target, working with the Trust & Compliance and ARIA teams.
  • Drive third‑party risk automation and risk scoring. Contribute vendor and application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.
  • Perform the hands‑on risk quantification. Apply cyber risk quantification (expected loss, probability, and cost of remediation versus acceptance) so leadership and the Technology Risk Committee can make rational investment and risk‑acceptance decisions rather than relying on qualitative severity labels.
  • Support the risk governance cadence. Contribute to weekly risk huddles, monthly risk reviews, and the quarterly Technology Risk Committee, preparing accurate, succinct, decision‑ready risk materials and translating high‑severity findings into clear business impact.
  • Operate as a second line of defense. Provide independent oversight, credible challenge, and guidance to first‑line teams, apply consistent risk taxonomies and reporting standards, and escalated risks that exceed established tolerance.
  • Partner cross‑functionally and close the loop. Work with Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings affecting systems and processes, tracking findings and remediation through to closure with clear ownership.
Who you are
  • 7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high‑growth organization, including hands‑on risk engineering or quantitative risk work.
  • Strong command of cyber risk quantification, able to express risk in financial and business terms rather than qualitative severity ratings alone.
  • Hands‑on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems and to automate risk reporting.
  • Experience building and running a technology and/or third‑party risk register and taxonomy, with the tooling and process automation behind it.
  • Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls) and how they translate into credible control requirements.
  • Hands‑on familiarity with modern risk and security tooling: third‑party risk platforms, cyber risk quantification, vulnerability management, and endpoint and data‑security telemetry, with a clear point of view on where AI augments versus replaces human judgement.
  • Experience authoring and maintaining security policies and standards, with a governance mindset that ties policy to the risk it reduces and to operational controls.
  • Able to operate independently as a second line of defense while engaging credibly with senior engineers, architects, and security teams.
  • Proficiency discussing complex, nuanced topics with technical and non‑technical audiences alike, and translating technical risk into clear business impact.
  • Excellent ability to plan, prioritize, and execute work cross‑functionally and on time.
Nice to have
  • Experien…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary