Lead Security Risk Analyst, Klaviyo

$132-198k

SQL
AWS
Kubernetes
Python
Airflow
Snowflake
REST API
dbt
Senior and Expert level
Denver

1+ day a week in office

Klaviyo

Intelligent marketing automation powered by customer data

Open for applications

Klaviyo

Intelligent marketing automation powered by customer data

1001+ employees

B2BMarketingContenteCommerce

Open for applications

$132-198k

SQL
AWS
Kubernetes
Python
Airflow
Snowflake
REST API
dbt
Senior and Expert level
Denver

1+ day a week in office

1001+ employees

B2BMarketingContenteCommerce

Company mission

To give online brands direct ownership of their consumer data and interactions, empowering them to turn transactions with customers into long-term relationships—at scale.

Role

Who you are

  • Experience doing security risk assessments, co-creating risk treatment strategies, and influencing cross-functional risk treatment prioritization
  • Thorough understanding of cloud-native web application architectures, security threats, and security best practices, especially in the context of AWS and Kubernetes
  • Experience using data visualization tools and SQL to build and operationalize security metrics (e.g. Apache Superset)
  • Experience with scalable approaches to threat modeling, secure design reviews, and risk assessment methods that balance rigor and efficiency (e.g. Mozilla’s Rapid Risk Assessment)
  • Experience with security automation and process streamlining, ideally in the context of security risk management
  • A strong bias toward evidence, logic, math, and reason when communicating risk (instead of fear, uncertainty, and doubt)
  • A strong bias toward “guardrails, not gates” and “paved security roads” philosophies (instead of rigid “centralized command-and-control” thinking)
  • Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
  • Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineering teams
  • Strong alignment with Klaviyo’s core values

Desirable

  • Experience building tools with REST APIs and Python
  • Experience with data engineering tools (e.g. dbt, Airflow, Airbyte) or data lake platforms (e.g. Snowflake, Databricks)
  • Experience with cyber risk quantification (CRQ) tools and frameworks (e.g. FAIR, RiskLens, Safe Security, etc.)

What the job involves

  • We’re seeking a highly motivated Lead Security Risk Analyst who will help us continue to evolve our Risk function by using engineering principles and data-driven strategies to precisely identify, understand, communicate, and prioritize mitigation of risk
  • This role will start out primarily focused on a subset of our Risk programs: internal security risk management (risk discovery, assessment, and governance) and security metrics (analysis, curation, reporting)
  • You’ll partner closely with Engineering, IT, Security, Leadership, and basically every other team at Klaviyo to create a holistic view of risk based on high quality data about our assets, weaknesses, threats, and safeguards (controls)
  • You’ll help your fellow Klaviyos identify, understand, prioritize, and manage risks that they own
  • You will help evolve our risk management practices to be transparent and centered around evidence-based risk models
  • Through all of this, you’ll help Klaviyo scale securely and sustainably deliver value for our customers
  • Lead and execute new Risk program maturity projects that introduce more rigorous, streamlined, and automated approaches to risk management
  • Collaborate with your partner teams and risk owners to help them understand and prioritize risk treatment plans
  • Create, tune, and operationalize highly effective security metrics (KPIs, KRIs, KCIs) that demonstrably improve security outcomes across Klaviyo
  • Perform security reviews of new products, product features, and internal business projects to steer teams toward secure paths forward and away from accruing new security debt
  • Collaboratively define and enable teams about security policies and standards that clearly establish Klaviyo’s risk tolerance bar

Our take

Klaviyo is a marketing firm helping growth-focused eCommerce brands drive more sales with super-targeted, highly relevant email, Facebook and Instagram marketing campaigns. From personalised newsletters to automated emails when customers abandon their shopping carts, the marketing automation platform makes it easy for businesses to capture, store, analyze, and predictively use their own data to drive measurable, high-value outcomes.

Klaviyo's CEO, Bialecki, believes that the main problem with e-mail marketing today is that there is a divide between two kinds of tools: analytics tools that help you understand what people are doing on a website, such as what products they are considering, and messaging tools that send them a marketing e-mail. Operating primarily within the retail and eCommerce industry, Klaviyo aims to solve this by offering a tool that brings together analytics and messaging. This allows companies to bring all of their first-party data into a single platform to get a deep understanding of their customers and then activate that data to deliver highly-targeted, personalised communications through email and SMS. In the process, Klaviyo's customers get a deep understanding of their consumers.

Klaviyo is a fast-growing company mainly due to its business model - the firm offers a concrete ROI for Klaviyo’s clients if the software persuades customers to make purchases by treating different types of customers differently. An IPO in 2023 has led to Klaviyo's release of Klaviyo AI, which empowers businesses to unlock revenue-driving opportunities and deliver exceptional customer experiences across channels. Still in its early days of public listing, it will be interesting to see how Klaviyo fares in the years to come.

Freddie headshot

Freddie

Company Specialist

Insights

Top investors

Some candidates hear
back within 2 weeks

46% female employees

4% employee growth in 12 months

Company

Employee endorsements

Opportunities to learn

"Not only we have a good stipend to spend on learning but we also have development days every quarter, where we can switch off and focus on the areas..."

Funding (last 2 of 6 rounds)

Aug 2022

$100m

LATE VC

May 2021

$320m

SERIES D

Total funding: $778.5m

Company benefits

  • Private health care cover
  • All full time employees receive equity
  • Commuting allowance for when you do travel to the office,
  • A very generous education allowance every year for you to spend on learning and development.
  • Free books policy - if you’re better off for having read it (or listened to it—audiobooks are covered too!) we’ll pay for it.
  • Generous and flexible PTO policy
  • Participation in Klaviyo ESPP

Company values

  • We always put our customers first.
  • We are owners.
  • We strive to make the world more equitable.
  • We are ambitious.
  • We are always learning.
  • We collaborate radically.
  • We are remarkable.

Company HQ

Financial District, Boston, MA

Founders

Previously CTO at RockTech, Senior Engineer at Performable, Lead Engineer at Applied Predictive Technologies and an SDET Intern at Microsoft

Ed Hallen

(Chief Product Officer)

Currently an Advisor at Team Engine. Previously worked in Enterprise Business Development at Google, Summer Associate at Accel-KKR and Principal at Applied Predictive Technologies.

Salary benchmarks

We don't have enough data yet to provide salary benchmarks for this role.

Submit your salary to help other candidates with crowdsourced salary estimates.

Diversity & Inclusion at Klaviyo

Katelyn Nnake headshot

Katelyn Nnake (Director of Diversity, Equity & Inclusion)

  • At Klaviyo one of our key values is "we strive to make the world more equitable"
  • In 2023 over 75% of Klaviyos participated in a Klaviyo Resource Group

Share this job

View 133 more jobs at Klaviyo