Klaviyo

Senior Security Compliance Engineer

Klaviyo$120K — $180K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years of experience in security compliance or GRC engineering with a focus on automation.
  • Familiarity with cloud-native web application security best practices, especially in AWS and Kubernetes.
  • Experience with compliance automation platforms like Drata, Vanta, and HyperProof.
  • Hands-on experience with compliance programs for SOC 2, ISO 27001, PCI, and SOX ITGCs.
  • Proficiency in programming or scripting languages (e.g. Python, Go, SQL) for automating compliance workflows.

Responsibilities

  • Design and maintain automated compliance workflows using scripting and APIs.
  • Build continuous control monitoring capabilities for real-time compliance visibility.
  • Collaborate with Security Risk team to integrate compliance findings into risk management workflows.
  • Implement compliance automation platforms and ensure integration with internal systems.
  • Serve as an advisor to Engineering and Product teams on compliance requirements for architecture decisions.

Benefits

  • Comprehensive health, welfare, and well-being benefits based on eligibility.
  • Participation in company’s annual cash bonus plan and equity options.
  • Potential for sign-on payments in addition to salary.
  • Opportunity for professional development by engaging with cross-functional teams.
Full Job Description
An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.

About this role

We're seeking a highly motivated SeniorSecurity Compliance Engineer to serve as a trusted advisor and hands-on engineer within our Security Trust & Compliance team. You'll design, build, and optimize automated solutions that streamline compliance operations, strengthen continuous control monitoring, and integrate GRC tooling across Klaviyo's systems. You'll partner closely with cross-functional teams, such as Engineering, IT, Security, Legal, Internal Audit, and more. You'll help Klaviyo scale securely, sustainably deliver more value for our customers, and bolster their trust in us.

As a Senior Security Compliance Engineer, you'll focus primarily on:
  • Compliance operations & audits (for SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs)
  • Continuous control monitoring
  • GRC automation & tooling (e.g. compliance automation platforms, API integrations, scripted evidence collection and control validation)

How you'll have an impact
  • Design, develop, and maintain automated compliance workflows using scripting, APIs, and GRC tooling to streamline evidence collection, control validation, and audit readiness across SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs
  • Build and improve continuous control monitoring capabilities that provide real-time visibility into Klaviyo's compliance posture and proactively surface control gaps
  • Partner with the Security Risk team to streamline end-to-end Security Compliance-to-Risk operations, ensuring compliance findings and control observations flow efficiently into risk management workflows
  • Implement and customize compliance automation platforms (e.g. Drata, Vanta, Anecdotes) and integrate them with Klaviyo's internal systems, CI/CD pipelines, and cloud infrastructure
  • Serve as a trusted advisor to Engineering and Product teams, embedding compliance-by-design into architecture decisions and helping teams understand and meet security control requirements
  • Identify and drive high-value opportunities to use AI and automation to eliminate toil, improve compliance operations, and scale our programs alongside Klaviyo's growth

Who you are
  • 3-5 years of experience in security compliance, GRC engineering, security engineering, or a closely related field with a strong emphasis on automation and scalable processes
  • Understanding of modern cloud-native web application architectures and related security best practices, especially in the context of AWS, Kubernetes, and AI
  • Experience implementing and operating Compliance Automation platforms, such as Drata, Vanta, Anecdotes, HyperProof, etc.
  • Hands-on experience executing compliance programs for SOC 2, ISO 27001, ISO 27017, PCI, and/or SOX ITGCs
  • Proficiency in one or more programming/scripting languages (e.g. Python, Go, SQL) with hands-on experience building automation for compliance workflows, integrating REST APIs, and working with GRC tooling
  • Experience applying GRC Engineering principles and values in practice, especially with regard to automation, systems + design thinking, and threat-informed GRC

Everyone on our team must have
  • A strong bias toward evidence, logic, math, and reason when communicating risk (instead of fear, uncertainty, and doubt)
  • A strong bias toward "guardrails, not gates" and "paved security roads" philosophies (instead of rigid "centralized command-and-control" processes and operating styles)
  • Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
  • Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineers
  • Strong alignment with Klaviyo's core values

Ideally, you may also have any of the following:
  • Experience implementing Identity Governance tools and processes, such as for user access reviews (UARs) and just-in-time access (JITA)
  • Experience working in security operations, security engineering, and/or security architecture roles
  • Experience with additional compliance frameworks such as ISO 27018, HIPAA, GDPR, CCPA, or NIS2


Massachusetts Applicants:It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicant's job-related skills, relevant experience, education or training, and work location.

In addition to base salary, our total compensation package may include participation in the company's annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility.

Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.

Base Pay Range For US Locations:

$120,000-$180,000 USD

This role may require up to 10% travel for purposes such as new hire onboarding, client or partner work if applicable, team meetings, and industry events. Travel is coordinated in advance.

About Klaviyo

Klaviyo is a cloud-based marketing automation platform that helps eCommerce businesses create personalized experiences across email, social media, and other channels. The platform offers a range of features, including email marketing, SMS marketing, list segmentation, A/B testing, and more. Klaviyo's mission is to help businesses grow by providing them with the tools they need to build strong relationships with their customers.
Learn more about Klaviyo
Size
500 employees
Industry
Founded
2012

Similar Jobs

More Jobs at Klaviyo

More Information Technology Jobs

Find similar Senior Security Compliance Engineer jobs: