Full-Time

Lead Security Risk Analyst

Posted on 10/8/2024

Klaviyo

Klaviyo

1,001-5,000 employees

Marketing automation for e-commerce businesses

Compensation Overview

$140k - $210k/yr

+ Annual Cash Bonus + Variable Compensation + Equity + Sign-on Payments + Health Benefits + Welfare Benefits + Wellbeing Benefits

Senior, Expert

Boston, MA, USA

Category
Cybersecurity
IT & Security
Required Skills
Kubernetes
SQL
Tableau
AWS
Risk Management
Amazon Quicksight
Requirements
  • Extensive experience conducting security risk assessments (including vendor/third-party and internal/first-party), collaborating on risk treatment strategies, and influencing risk treatment prioritization across various business units (Engineering, IT, Finance, Legal, etc.)
  • Thorough understanding of cloud-native web application architectures, security threats, and security best practices, especially in the context of AWS and Kubernetes
  • Experience using data visualization tools and SQL to build and operationalize security metrics (e.g. Apache Superset, Tableau, Domo, Amazon QuickSight)
  • Experience with scalable approaches to threat modeling, secure design reviews, and risk assessment methods that balance rigor and efficiency (e.g. Mozilla’s Rapid Risk Assessment)
  • Experience with security automation and process streamlining, ideally in the context of security risk management
  • A strong bias toward evidence, logic, math, and reason when communicating risk (instead of fear, uncertainty, and doubt)
  • A strong bias toward “guardrails, not gates” and “paved security roads” philosophies (instead of rigid “centralized command-and-control” thinking)
  • Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
  • Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineering teams
  • Strong alignment with Klaviyo’s core values
Responsibilities
  • Lead and execute Risk program maturity projects that introduce more rigorous, streamlined, and automated approaches to risk management
  • Spearhead the optimization and automation of third-party risk assessments, significantly reducing time-to-completion and establishing capabilities for continuous risk monitoring at scale
  • Partner with other departments and teams to drive mutual understanding of security risks they own and how to prioritize managing those risks in support of Klaviyo’s goals
  • Create, tune, and operationalize business-relevant security metrics (KPIs, KRIs, KCIs) that demonstrably improve security outcomes across Klaviyo
  • Review new products, product features, and internal business projects to guide teams toward secure paths forward and away from accruing new security debt
  • Collaboratively define and enable teams about security policies and standards that clearly establish Klaviyo’s risk tolerance bar
Desired Qualifications
  • Experience building tools with REST APIs and Python
  • Experience with data engineering tools (e.g. dbt, Airflow, Airbyte) or data lake platforms (e.g. Snowflake, Databricks)
  • Experience with cyber risk quantification (CRQ) tools and frameworks (e.g. FAIR, RiskLens, Safe Security, etc.)
  • Experience with modern GRC platforms or modern 3rd party risk management tools

Klaviyo provides marketing automation and customer data management tools specifically designed for e-commerce businesses. Their platform allows companies to collect, store, and analyze customer data, which helps in creating personalized marketing campaigns. Businesses can use Klaviyo to implement marketing automations like email marketing, SMS campaigns, and personalized product recommendations, all aimed at improving customer engagement and retention. Unlike many competitors, Klaviyo operates on a subscription-based model, where clients pay based on the number of contacts and services needed, ensuring a steady revenue stream while allowing businesses to scale their marketing efforts. The goal of Klaviyo is to empower e-commerce businesses to foster stronger customer relationships through data-driven strategies.

Company Size

1,001-5,000

Company Stage

IPO

Headquarters

Boston, Massachusetts

Founded

2012

Simplify Jobs

Simplify's Take

What believers are saying

  • Recognition as top SMS marketing platform strengthens brand reputation and attracts more clients.
  • Participation in high-profile conferences increases visibility among potential investors and partners.
  • AI-driven content creation tools enhance email marketing capabilities for personalized engagement.

What critics are saying

  • Increased competition from companies like Domaine threatens Klaviyo's market share.
  • Economic downturns could reduce marketing budgets, affecting Klaviyo's subscription-based revenue.
  • AI-powered features may face scrutiny over data privacy concerns, impacting user trust.

What makes Klaviyo unique

  • Klaviyo integrates seamlessly with platforms like WooCommerce and Kluvos for enhanced functionality.
  • The K:Partners Program empowers partners to deliver enhanced value and boost market reach.
  • Klaviyo's AI-driven content creation tools enhance personalized and efficient customer engagement.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Health Savings Account/Flexible Spending Account

401(k) Company Match

Paid Holidays

Professional Development Budget

Growth & Insights and Company News

Headcount

6 month growth

↑ 0%

1 year growth

↑ 0%

2 year growth

↑ 0%
Stock Titan
Apr 21st, 2025
BigCommerce and Feedonomics Announce Winners of Americas Region Customer and Partner Awards to Honor Exceptional Contributions and Results in Ecommerce

Among technology partners, Klaviyo was named Tech Partner of the Year, while Power Digital secured Feedonomics Partner of the Year.

Klaviyo
Apr 2nd, 2025
WooCommerce abandoned cart emails: strategies to get shoppers back to your store

Klaviyo's Data Platform seamlessly integrates with WooCommerce, ensuring real-time customer insights power every marketing channel - email, SMS, and mobile.

Klaviyo
Mar 24th, 2025
Build better customer relationships with automated SMS conversations, mobile in-app messaging, and custom objects

This month, Klaviyo Inc. is proud to announce three new features designed to help marketers personalize even further, and across more channels.

Top Growth Marketing
Mar 21st, 2025
Klaviyo AI: How to Leverage It to Make Better Content

In early 2024, Klaviyo announced Email AI - their AI-powered feature that can help you streamline email content creation.

Klaviyo
Mar 11th, 2025
Introducing the K:Partners program: multiply your impact, accelerate your growth

At Klaviyo, Klaviyo Inc. is taking that to the next level with the launch of the K:Partners Program - an evolution designed to empower its partners, accelerate success, and amplify the value Klaviyo Inc. deliver together.

INACTIVE