At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If youre a close but not exact match with the description, we hope youll still consider applying. Want to learn more about life at Klaviyo? Visit careers.klaviyo.com to see how we empower creators to own their own destiny.
Klaviyo is building a world where creators are empowered to own their destiny. In support of this, our Security Risk & Trust team is focused on empowering our fellow Klaviyos to securely deliver value to and foster trust with our customers. We do this by building and leading highly efficient and effective security governance, risk management, compliance, and trust programs.
Were seeking a highly motivated and collaborative Senior Security Risk Analyst who will help us accelerate our evolution in these key programs. Partnering closely with our Engineering, IT, Security, Leadership, and other teams, youll build tools and processes that foster a culture of disciplined risk decision making, informed by an evidence-based understanding of our assets, weaknesses, threats, and safeguards. You will help evolve our risk management practices to be transparent and centered around quantitative risk models. With a knack for communicating nuanced security topics to technical and non-technical audiences, youll help grow security consciousness across all of Klaviyo to the betterment of our customers.
What youll be doing
- Enhance existing risk management tools and processes to create a data driven, seamless, and excellent user experience for risk / asset owners
- Consult with partner teams to proactively identify potential risks and co-create controls and mitigation plans with them
- Streamline and automate third-party risk assessments, speeding up time-to-completion and enabling continuous re-assessments at scale
- Mentor junior team members to help them reach their full potential and achieve their development goals
- Contribute to Risk & Trust operations, such as performing third-party risk assessments, user access reviews, facilitating internal and external audits (SOC 2 Type II, ISO 27001, SOX ITGCs, etc.), continuously monitoring controls, responding to customer security questionnaires, fulfilling employees security service requests, etc.
- Then build and implement tooling that automates repetitive toil to free up our teams time
Wed love to hear from you if you have:
- Experience designing, building, or implementing security controls, especially in AWS
- Experience doing security risk assessments, architecture reviews, or threat modeling
- Knowledge of security best practices for SaaS, IaaS, IAM, networks, or containers
- Excellent ability to plan, prioritize, and execute work cross functionally and on time
- Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike
- Strong alignment with Klaviyos core values
Bonus points if you have any of the following:
- Experience with data query languages, writing code, or integrating with web APIs
- Experience implementing FAIR or cyber risk quantification (CRQ) processes or tools
- Experience with business intelligence or data analytics platforms (Tableau, Domo, etc.)
The pay range for this role is listed below. Sales roles are also eligible for variable compensation and hourly non-exempt roles are eligible for overtime in accordance with applicable law. This role is eligible for benefits, including: medical, dental and vision coverage, health savings accounts, flexible spending accounts, 401(k), flexible paid time off and company-paid holidays and a culture of learning that includes a learning allowance and access to a professional coaching service for all employees.
Get to Know Klaviyo
Were Klaviyo (pronounced clay-vee-oh). We empower creators to own their destiny by making first-party data accessible and actionable like never before. We see limitless potential for the technology were developing to nurture personalized experiences in ecommerce and beyond. To reach our goals, we need our own crew of remarkable creatorsambitious and collaborative teammates who stay focused on our north star: delighting our customers. If youre ready to do the best work of your career, where youll be welcomed as your whole self from day one and supported with generous benefits, we hope youll join us.
Klaviyo is committed to a policy of equal opportunity and non-discrimination. We do not discriminate on the basis of race, ethnicity, citizenship, national origin, color, religion or religious creed, age, sex (including pregnancy), gender identity, sexual orientation, physical or mental disability, veteran or active military status, marital status, criminal record, genetics, retaliation, sexual harassment or any other characteristic protected by applicable law.