Full-Time

Lead Security Risk Analyst

Updated on 4/17/2025

Klaviyo

Klaviyo

1,001-5,000 employees

Marketing automation for e-commerce businesses

Compensation Overview

$140k - $210k/yr

+ Annual Cash Bonus + Variable Compensation + Equity + Sign-on Payments + Health Benefits + Welfare Benefits + Wellbeing Benefits

Senior, Expert

San Francisco, CA, USA

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
SQL
Tableau
AWS
Risk Management
Amazon Quicksight
Requirements
  • Extensive experience conducting security risk assessments (including vendor/third-party and internal/first-party), collaborating on risk treatment strategies, and influencing risk treatment prioritization across various business units (Engineering, IT, Finance, Legal, etc.)
  • Thorough understanding of cloud-native web application architectures, security threats, and security best practices, especially in the context of AWS and Kubernetes
  • Experience using data visualization tools and SQL to build and operationalize security metrics (e.g. Apache Superset, Tableau, Domo, Amazon QuickSight)
  • Experience with scalable approaches to threat modeling, secure design reviews, and risk assessment methods that balance rigor and efficiency (e.g. Mozilla’s Rapid Risk Assessment)
  • Experience with security automation and process streamlining, ideally in the context of security risk management
  • A strong bias toward evidence, logic, math, and reason when communicating risk (instead of fear, uncertainty, and doubt)
  • A strong bias toward “guardrails, not gates” and “paved security roads” philosophies (instead of rigid “centralized command-and-control” thinking)
  • Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
  • Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineering teams
  • Strong alignment with Klaviyo’s core values
Responsibilities
  • Lead and execute Risk program maturity projects that introduce more rigorous, streamlined, and automated approaches to risk management
  • Spearhead the optimization and automation of third-party risk assessments, significantly reducing time-to-completion and establishing capabilities for continuous risk monitoring at scale
  • Partner with other departments and teams to drive mutual understanding of security risks they own and how to prioritize managing those risks in support of Klaviyo’s goals
  • Create, tune, and operationalize business-relevant security metrics (KPIs, KRIs, KCIs) that demonstrably improve security outcomes across Klaviyo
  • Review new products, product features, and internal business projects to guide teams toward secure paths forward and away from accruing new security debt
  • Collaboratively define and enable teams about security policies and standards that clearly establish Klaviyo’s risk tolerance bar
Desired Qualifications
  • Experience building tools with REST APIs and Python
  • Experience with data engineering tools (e.g. dbt, Airflow, Airbyte) or data lake platforms (e.g. Snowflake, Databricks)
  • Experience with cyber risk quantification (CRQ) tools and frameworks (e.g. FAIR, RiskLens, Safe Security, etc.)
  • Experience with modern GRC platforms or modern 3rd party risk management tools

Klaviyo provides marketing automation and customer data management tools specifically designed for e-commerce businesses. Their platform allows companies to collect, store, and analyze customer data, which helps in creating personalized marketing campaigns. Businesses can use Klaviyo to implement automated marketing strategies such as email marketing, SMS campaigns, and tailored product recommendations, all aimed at improving customer engagement and retention. Unlike many competitors, Klaviyo operates on a subscription-based model, where clients pay based on the number of contacts and services needed, ensuring a consistent revenue stream. The company's goal is to empower e-commerce businesses to strengthen customer relationships through data-driven marketing, while also offering partnerships with agencies to enhance the platform's effectiveness.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Boston, Massachusetts

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • Klaviyo's AI-powered Email AI enhances content creation efficiency for marketers.
  • The K:Partners Program amplifies partner success and Klaviyo's market reach.
  • Recognition as a top SMS marketing platform boosts Klaviyo's industry credibility.

What critics are saying

  • Increased competition from AI-driven platforms threatens Klaviyo's market share.
  • Privacy regulations like CPRA may impact Klaviyo's data processing capabilities.
  • Economic downturns could reduce demand for Klaviyo's subscription services.

What makes Klaviyo unique

  • Klaviyo integrates seamlessly with e-commerce platforms like WooCommerce for real-time insights.
  • The platform offers AI-driven tools for personalized email and SMS marketing campaigns.
  • Klaviyo's subscription model provides scalable marketing solutions for growing e-commerce businesses.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Health Savings Account/Flexible Spending Account

401(k) Company Match

Paid Holidays

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

0%
Klaviyo
Apr 2nd, 2025
WooCommerce abandoned cart emails: strategies to get shoppers back to your store

Klaviyo's Data Platform seamlessly integrates with WooCommerce, ensuring real-time customer insights power every marketing channel - email, SMS, and mobile.

Klaviyo
Mar 24th, 2025
Build better customer relationships with automated SMS conversations, mobile in-app messaging, and custom objects

This month, Klaviyo Inc. is proud to announce three new features designed to help marketers personalize even further, and across more channels.

Top Growth Marketing
Mar 21st, 2025
Klaviyo AI: How to Leverage It to Make Better Content

In early 2024, Klaviyo announced Email AI - their AI-powered feature that can help you streamline email content creation.

Klaviyo
Mar 11th, 2025
Introducing the K:Partners program: multiply your impact, accelerate your growth

At Klaviyo, Klaviyo Inc. is taking that to the next level with the launch of the K:Partners Program - an evolution designed to empower its partners, accelerate success, and amplify the value Klaviyo Inc. deliver together.

The Manila Times
Mar 8th, 2025
Best SMS Marketing Platforms (2025): Klaviyo Named Top SMS Marketing Service by Expert Consumers

Expert Consumers has recognized Klaviyo as the top SMS marketing platform for 2025