×
Register Here to Apply for Jobs or Post Jobs. X

Lead Security Compliance Engineer

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: Klaviyo Inc.
Full Time position
Listed on 2026-09-24
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 140000 - 210000 USD Yearly USD 140000.00 210000.00 YEAR
Job Description & How to Apply Below

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you are a close but not exact match with the description, we hope you will still consider applying.

Want to learn more about life at Klaviyo? Visit  to see how we empower creators to own their own destiny.

At Klaviyo, we are on a mission to empower creators to own their destiny. Our AI-first B2C CRM platform empowers 176,000+ brands in 80+ countries to cultivate relationships with hundreds of millions of consumers. We love solving hard problems and look for people who specialize in certain areas while being passionate about building, owning, and scaling solutions end-to-end, overcoming any obstacle in their way.

We are a team of ambitious, customer-obsessed peers who are insatiably curious and meticulous in our craft. We push each other to grow beyond our comfort zone, learn new things, and work hard to ensure each day is better than the last.

As a Lead Security Trust & Compliance Engineer at Klaviyo, you will be the primary owner of two or more of our Trust & Compliance programs - compliance operations & audits, continuous control monitoring, security policies & standards, security education & awareness, and customer trust operations among them. You will set the strategy for the programs you own, run our audits end to end, engineer the controls and evidence pipelines that make them sustainable, and raise the technical bar for the practitioners around you.

You will not have direct reports, but you will tactically lead the team on your programs: delegating work, setting teammates up to succeed, and mentoring analysts on their technical growth and career goals. This is your opportunity to take a leading role in cybersecurity, applying and deepening your expertise in security automation, risk analysis, control design, audit management, modern SaaS platform architectures, and many domains of information security (just about all of them!)

What you'll be doing
  • Own internal and external audits and examinations end to end from scoping and readiness through fieldwork and evidence delivery; act as our primary point of contact for auditors and assessors, and develop action plans to correct findings and exceptions
  • Identify gaps against frameworks we do not yet meet, define the strategy to close them, and drive the implementation when Klaviyo takes on a new certification or regulation
  • Own security policies and standards end to end - author and maintain the policy, standard, and procedure hierarchy, decompose standards into testable requirements mapped to frameworks, and run the review, ratification, and exception management
  • Determine control design and implementation details for net-new controls, provide technical guidance to partner teams on control design best practices, and diagnose deficiencies by reviewing system configurations, technical documentation, security tool data, and occasionally application code
  • Define control health metrics and build the pipelines behind them from the systems we already run, so control health is a live signal rather than a quarterly assertion
  • Automate and streamline our Security Trust & Compliance workflows - control testing, continuous control monitoring, evidence collection, identity governance, and security Q&A for employees and customers - with a penchant for creating excellent self-service experiences, and define new approaches, systems, and tools for the team where none exist yet
  • Proactively identify internal and external risks and opportunities relevant to our Trust & Compliance programs, and propose the plans to address them
We'd love to hear from you if you have most of the following:
  • In-depth understanding of multiple security and privacy frameworks — such as NIST CSF 2.0, CIS Critical Security Controls, CSA STAR, ISO 27001, ISO 27002, ISO 27017, ISO 27018, ISO 27701, ISO 42001, SOC 1, SOC 2, PCI, HIPAA, SOX ITGCs, GDPR, CCPA, and CPRA — including the ability to identify gaps against a framework that is new to the organization, define the strategy, and execute the implementation
  • A track record of personally owning security and privacy compliance audit programs end to end, including acting as the primary interface to internal and external auditors through scoping, walkthroughs, and findings…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary