engineering
Posted 3 weeks agoSenior Security Compliance Engineer
at Klaviyo
Denver, United StatesOn-site
Responsibilities
- Design, develop, and maintain automated compliance workflows using scripting, APIs, and GRC tooling to streamline evidence collection, control validation, and audit readiness across SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs
- Build and improve continuous control monitoring capabilities that provide real-time visibility into Klaviyo’s compliance posture and proactively surface control gaps
- Implement and customize compliance automation platforms (e.g. Drata, Vanta, Anecdotes) and integrate them with Klaviyo’s internal systems, CI/CD pipelines, and cloud infrastructure
- Identify and drive high-value opportunities to use AI and automation to eliminate toil, improve compliance operations, and scale our programs alongside Klaviyo’s growth Who you are 3–5 years of
Requirements
- Our AI-first B2C CRM platform empowers 176,000+ brands in 80+ countries to cultivate relationships with hundreds of millions of consumers.
- We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment. About this role
- Compliance operations & audits (for SOC 2, ISO 27001, ISO 27017, PCI, and SOX ITGCs)
- GRC automation & tooling (e.g. compliance automation platforms, API integrations, scripted evidence collection and control validation)
- experience in security compliance, GRC engineering, security engineering, or a closely related field with a strong emphasis on automation and scalable processes
- Understanding of modern cloud-native web application architectures and related security best practices, especially in the context of AWS, Kubernetes, and AI •
- Experience implementing and operating Compliance Automation platforms, such as Drata, Vanta, Anecdotes, HyperProof, etc. Hands-on
- experience executing compliance programs for SOC 2, ISO 27001, ISO 27017, PCI, and/or SOX ITGCs
- Proficiency in one or more programming/scripting languages (e.g. Python, Go, SQL) with hands-on
- experience building automation for compliance workflows, integrating REST APIs, and working with GRC tooling •
- Experience applying GRC Engineering principles and values in practice , especially with regard to automation, systems + design thinking, and threat-informed GRC
- Everyone on our team must have
- Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
- Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineers
- Experience implementing Identity Governance tools and processes, such as for user access reviews (UARs) and just-in-time access (JITA) •
- Experience working in security operations, security engineering, and/or security architecture roles •
- Experience with additional compliance frameworks such as ISO 27018, HIPAA, GDPR, CCPA, or NIS2
Benefits
- Our salary range reflects the cost of labor across various U.S. geographic markets.
- The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations.
- The base salary offered for this position is determined by several factors, including the applicant’s job-related skills, relevant experience, education or training, and work location.
- In addition to base salary, our total compensation package may include participation in the company’s annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing
- Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.
- Base Pay Range For US Locations: $120,000 — $180,000 USD
Contact
- Want to learn more about life at Klaviyo? Visit klaviyo.com/careers to see how we empower creators to own their own destiny.
Additional details
- At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day.
- We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements.
- If you’re a close but not exact match with the description, we hope you’ll still consider applying.
- At Klaviyo, we're on a mission to empower creators to own their destiny.
- We love solving hard problems and look for people who specialize in certain areas while being passionate about building, owning, and scaling solutions end-to-end, overcoming any obstacle in their way.
- We are a team of ambitious, customer-obsessed peers who are insatiably curious and meticulous in our craft.
- We push each other to grow beyond our comfort zone, learn new things, and work hard to ensure each day is better than the last.
- An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services.
- This is achieved by providing a robust and secure technology foundation to do great work.
- You’ll design, build, and optimize automated solutions that streamline compliance operations, strengthen continuous control monitoring, and integrate GRC tooling across Klaviyo’s systems.