Full-Time

Lead Security Risk Analyst

Updated on 1/21/2025

Klaviyo

Klaviyo

1,001-5,000 employees

Marketing automation for e-commerce businesses

Consumer Software
Consumer Goods

Compensation Overview

$140k - $210kAnnually

Senior, Expert

San Francisco, CA, USA

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
SQL
Tableau
AWS
Risk Management
Amazon Quicksight
Requirements
  • Experience doing security risk assessments, co-creating risk treatment strategies, and influencing risk treatment prioritization across diverse business units (Engineering, IT, Finance, Legal, etc.)
  • Thorough understanding of cloud-native web application architectures, security threats, and security best practices, especially in the context of AWS and Kubernetes
  • Experience using data visualization tools and SQL to build and operationalize security metrics (e.g. Apache Superset, Tableau, Domo, Amazon QuickSight)
  • Experience with scalable approaches to threat modeling, secure design reviews, and risk assessment methods that balance rigor and efficiency (e.g. Mozilla’s Rapid Risk Assessment)
  • Experience with security automation and process streamlining, ideally in the context of security risk management
  • A strong bias toward evidence, logic, math, and reason when communicating risk (instead of fear, uncertainty, and doubt)
  • A strong bias toward 'guardrails, not gates' and 'paved security roads' philosophies (instead of rigid 'centralized command-and-control' thinking)
  • Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
  • Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineering teams
  • Strong alignment with Klaviyo’s core values
Responsibilities
  • Lead and execute new Risk program maturity projects that introduce more rigorous, streamlined, and automated approaches to risk management
  • Partner with other departments and teams to drive mutual understanding of security risks they own and how to prioritize managing those risks in support of Klaviyo’s goals
  • Create, tune, and operationalize business relevant security metrics (KPIs, KRIs, KCIs) that demonstrably improve security outcomes across Klaviyo
  • Review new products, product features, and internal business projects to guide teams toward secure paths forward and away from accruing new security debt
  • Collaboratively define and enable teams about security policies and standards that clearly establish Klaviyo’s risk tolerance bar
Desired Qualifications
  • Experience building tools with REST APIs and Python
  • Experience with data engineering tools (e.g. dbt, Airflow, Airbyte) or data lake platforms (e.g. Snowflake, Databricks)
  • Experience with cyber risk quantification (CRQ) tools and frameworks (e.g. FAIR, RiskLens, Safe Security, etc.)

Klaviyo offers marketing automation and customer data management tools tailored for e-commerce businesses. Their platform enables companies to collect and analyze customer information to create personalized marketing campaigns, including email and SMS outreach. Unlike competitors, Klaviyo integrates seamlessly with various e-commerce tools and provides partner programs that connect businesses with expert agencies for additional support. The goal of Klaviyo is to help e-commerce businesses build stronger customer relationships through effective, data-driven marketing.

Company Stage

IPO

Total Funding

$757.3M

Headquarters

Boston, Massachusetts

Founded

2012

Growth & Insights
Headcount

6 month growth

-1%

1 year growth

0%

2 year growth

-3%
Simplify Jobs

Simplify's Take

What believers are saying

  • Klaviyo's AI-driven personalization aligns with the growing trend in email marketing.
  • The rise of zero-party data collection enhances Klaviyo's personalized marketing capabilities.
  • Klaviyo's integration of SMS and email campaigns boosts customer engagement rates.

What critics are saying

  • Emerging AI-driven marketing platforms could erode Klaviyo's market share.
  • Privacy regulations may increase compliance costs for Klaviyo.
  • Economic downturns could reduce marketing budgets, impacting Klaviyo's revenue.

What makes Klaviyo unique

  • Klaviyo integrates natively with customer data sources for seamless marketing automation.
  • The platform offers personalized marketing through AI-driven email and SMS campaigns.
  • Klaviyo's subscription model allows businesses to scale marketing efforts efficiently.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Health Savings Account/Flexible Spending Account

401(k) Company Match

Paid Holidays

Professional Development Budget