SlipstreamJobsFresh Startup & VC-Backed Jobs

Lead Security Compliance Engineer

Klaviyo - Denver, CO, United States - In-office - posted 2026-09-22

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: USD 140,000 - 210,000 / annual

Klaviyo is seeking a Security Compliance Engineer to own and lead multiple Trust & Compliance programs including compliance operations & audits, continuous control monitoring, security policies & standards, security education & awareness, and customer trust operations. You will be the primary owner of two or more compliance programs, setting strategy, running audits end-to-end, engineering controls and evidence pipelines, and raising the technical bar for practitioners. While you won't have direct reports, you will tactically lead the team on your programs by delegating work, mentoring analysts on technical growth and career goals, and driving technical direction without formal authority. Key responsibilities include: - Own internal and external audits and examinations end-to-end from scoping through evidence delivery; serve as primary contact for auditors and assessors - Identify gaps against compliance frameworks and define strategy to close them when Klaviyo adopts new certifications or regulations - Author and maintain the policy, standard, and procedure hierarchy; decompose standards into testable requirements mapped to frameworks - Determine control design for net-new controls and provide technical guidance on control design best practices - Define control health metrics and build pipelines from existing systems to make control health a live signal - Automate and streamline Security Trust & Compliance workflows including control testing, continuous monitoring, evidence collection, identity governance, and security Q&As - Proactively identify internal and external risks and opportunities relevant to Trust & Compliance programs Klaviyo is an AI-first B2C CRM platform empowering 176,000+ brands in 80+ countries. The company values ambitious, customer-obsessed peers who are insatiably curious and meticulous in their craft. Requirements: - In-depth understanding of multiple security and privacy frameworks (NIST CSF 2.0, CIS Critical Security Controls, CSA STAR, ISO 27001/27002/27017/27018/27701/42001, SOC 1/2, PCI, HIPAA, SOX ITGCs, GDPR, CCPA, CPRA) with ability to identify gaps, define strategy, and execute implementation - Track record of personally owning security and privacy compliance audit programs end-to-end, including acting as primary interface to internal and external auditors - Experience writing precise, testable policies and standards; ownership of review and exception processes - Deep experience designing, assessing, and continuously monitoring modern security and privacy controls; diagnosing deficiencies from system configurations, technical documentation, security tool data, and application code - Experience with GRC engineering and security automation, especially applying AI and automation to eliminate toil - Knowledge of enterprise SaaS applications, cloud infrastructure (AWS, Kubernetes), modern software engineering practices, databases, operating systems, secure network design - Experience owning programs against defined KPIs and SLAs; setting quarterly strategy, planning work, and reporting progress - Track record of mentoring practitioners, delegating effectively, and driving technical direction without formal authority - Excellent interpersonal and communication skills; ability to form relationships with internal and external teams Bonus qualifications: - Familiarity with modern compliance automation or trust management platforms (Drata, Vanta, Anecdotes, HyperProof) - Experience with SQL, REST APIs, and Python - Infrastructure-as-code or policy-as-code experience (Terraform, OPA/Rego, Conftest) - Building with agentic AI tooling and/or governing AI controls against ISO 42001 or NIST AI RMF - Experience implementing Identity Governance tools and processes (UARs, JITA) - Background in security operations, security engineering, or security architecture - Relevant certifications (CISA, CISSP, CCSP)

Similar roles