SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: USD 140,000 - 210,000 / annual
Klaviyo is seeking a Security Compliance Engineer to own and lead multiple Trust & Compliance programs at the company. This is a senior individual contributor role without direct reports, but with significant tactical leadership responsibilities including delegating work, mentoring analysts, and setting technical direction.
You will own internal and external audits end-to-end, from scoping and readiness through fieldwork and evidence delivery, serving as the primary point of contact for auditors and assessors. You'll develop action plans to correct findings and manage the audit lifecycle.
Key responsibilities include:
- Identifying gaps against compliance frameworks and defining strategies to close them when Klaviyo adopts new certifications or regulations
- Owning security policies and standards end-to-end: authoring and maintaining the policy hierarchy, decomposing standards into testable requirements mapped to frameworks, and managing review and exception processes
- Determining control design for new controls, providing technical guidance to partner teams, and diagnosing deficiencies through system configurations, technical documentation, security tool data, and application code review
- Defining control health metrics and building automated pipelines to make control health a live signal rather than a quarterly assertion
- Automating and streamlining Security Trust & Compliance workflows including control testing, continuous monitoring, evidence collection, identity governance, and security Q&As
- Proactively identifying internal and external risks and opportunities relevant to Trust & Compliance programs
You'll work across multiple security and privacy frameworks including NIST CSF 2.0, CIS Critical Security Controls, ISO 27001/27002/27017/27018/27701/42001, SOC 1/2, PCI, HIPAA, SOX ITGCs, GDPR, CCPA, and CPRA. The role requires deep technical knowledge of modern SaaS architectures, cloud infrastructure (AWS, Kubernetes), security automation, and GRC engineering.
Klaviyo is an AI-first B2C CRM platform serving 176,000+ brands in 80+ countries. The company values ambitious, customer-obsessed peers who are curious and meticulous in their craft.
Travel up to 10% may be required for onboarding, team meetings, and industry events.
REQUIREMENTS:
- In-depth understanding of multiple security and privacy frameworks (NIST CSF 2.0, CIS Controls, ISO 27001/27002/27017/27018/27701/42001, SOC 1/2, PCI, HIPAA, SOX, GDPR, CCPA, CPRA) with ability to identify gaps, define strategy, and execute implementation
- Track record of personally owning security and privacy compliance audit programs end-to-end, including serving as primary interface to internal and external auditors
- Experience writing precise, testable policies and standards with clear ownership of review and exception processes
- Deep experience designing, assessing, and continuously monitoring modern security and privacy controls
- Experience with GRC engineering and security automation, especially applying AI to eliminate toil
- Knowledge of enterprise SaaS applications, AWS, Kubernetes, modern software engineering practices, databases, operating systems, and secure network design
- Experience owning programs against defined KPIs and SLAs, including quarterly strategy and progress reporting
- Track record of mentoring practitioners, delegating effectively, and driving technical direction without formal authority
- Excellent interpersonal and communication skills
BONUS:
- Familiarity with compliance automation platforms (Drata, Vanta, Anecdotes, HyperProof)
- SQL, REST APIs, and Python experience
- Infrastructure-as-code or policy-as-code experience (Terraform, OPA/Rego, Conftest)
- Agentic AI tooling experience (MCP, agent skills, evals, guardrails)
- Identity Governance tools and processes (UARs, JITA)
- Security operations, security engineering, or security architecture background
- Relevant certifications (CISA, CISSP, CCSP)