Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Lead Security Governance & Risk Engineer

$156k - $234k

Klaviyo

At Klaviyo, we value the unique backgrounds, experiences and perspectives each Klaviyo (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you’re a close but not exact match with the description, we hope you’ll still consider applying. Want to learn more about life at Klaviyo? Visit klaviyo.com/careers to see how we empower creators to own their own destiny.An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support Klaviyo's continued scalability and sustainable employee growth in a rapidly evolving environment.The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts. The STAR team is highly collaborative and cross-functional, working closely with various functions within the GSS team (namely Security Product and Development and Security Intelligence Operations), Global Technology Solutions (GTS) team and the broader Klaviyo organization.About the role:The Lead Security Governance & Risk Engineer is a senior, hands-on role at the point where security governance meets risk engineering. You will own the parts of the risk programme that turn policy and standards into measured, monitored, and automated risk decisions. Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 readiness, and build the automation that gives Klaviyo a continuously updated, quantified view of its risk posture.You will work alongside the Trust and Compliance team who are the custodians of our security policies and standards, making sure each one connects to a specific risk it reduces and is enforced through operational controls rather than living as a document. You will partner closely with Engineering, Product, GTS, Legal, Internal Audit, the ARIA team, and Finance to make risk legible across the business, and you will challenge first-line teams credibly while keeping your independence. This is a role for an engineer who thinks like a risk professional: someone who automates repeatable assessment, instruments controls, quantifies risk in financial terms, and treats AI as foundational infrastructure rather than an afterthought.​​How you’ll have an impact:Operate and maintain the risk register and taxonomy. Run the technology and third-party risk register on a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that risks aggregate, prioritise, and report meaningfully across the business.Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and risk criteria, maintain the consolidated AI risk register against the K:AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions. Drive ISO/IEC 42001 readiness (Clauses 6.1 and 8.2/8.3) toward the certification target, working with the Trust & Compliance and ARIA teams.Drive third-party risk automation and risk scoring. Contribute vendor and application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.Perform the hands-on risk quantification. Apply cyber risk quantification (expected loss, probability, and cost of remediation versus acceptance) so leadership and the Technology Risk Committee can make rational investment and risk-acceptance decisions rather than relying on qualitative severity labels.Support the risk governance cadence. Contribute to weekly risk huddles, monthly risk reviews, and the quarterly Technology Risk Committee (CIO, CISO, CTO), preparing accurate, succinct, decision-ready risk materials and translating high-severity findings into clear business impact.Operate as a second line of defense. Provide independent oversight, credible challenge, and guidance to first-line teams, apply consistent risk taxonomies and reporting standards, and escalate risks that exceed established tolerance.Partner cross-functionally and close the loop. Work with Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings affecting systems and processes, tracking findings and remediation through to closure with clear ownership.Who you are:7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high-growth organization, including hands-on risk engineering or quantitative risk work.Strong command of cyber risk quantification, able to express risk in financial and business terms (FAIR, riskquant, or similar) rather than qualitative severity ratings alone.Hands-on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems and to automate risk reporting.Experience building and running a technology and/or third-party risk register and taxonomy, with the tooling and process automation behind it.Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls) and how they translate into credible control requirements.Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, and endpoint and data-security telemetry, with a clear point of view on where AI augments versus replaces human judgement.Experience authoring and maintaining security policies and standards, with a governance mindset that ties policy to the risk it reduces and to operational controls.Able to operate independently as a second line of defense while engaging credibly with senior engineers, architects, and security teams.Proficiency discussing complex, nuanced topics with technical and non-technical audiences alike, and translating technical risk into clear business impact.Excellent ability to plan, prioritise, and execute work cross-functionally and on time.Nice to have:Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering-led, or AI-enabled risk capability.AI governance, model risk, or responsible-AI programme experience, and ISO 42001 readiness or certification work.Experience building metrics and dashboards (KPIs, KRIs, KCIs) using business intelligence or dashboarding tools like Tableau and so on.Experience in a regulated or high-trust environment (SOC 2, ISO 27000 series, ISO 42001, HIPAA, GDPR).Threat modeling or secure design reviews, and experience designing or implementing technical security controls in AWS.Experience securing web applications, Kubernetes clusters, and/or containers.Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor / Lead Implementer, an ISO 42001 / AI governance certification, or Open FAIR.Massachusetts Applicants:It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicant’s job-related skills, relevant experience, education or training, and work location.In addition to base salary, our total compensation package may include participation in the company’s annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility. Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.Base Pay Range For US Locations:$156,000—$234,000 USDThis role may require up to 10% travel for purposes such as new hire onboarding, client or partner work if applicable, team meetings, and industry events. Travel is coordinated in advance.Get to Know KlaviyoWe’re Klaviyo (pronounced clay-vee-oh). We empower creators to own their destiny by making first-party data accessible and actionable like never before. We see limitless potential for the technology we’re developing to nurture personalized experiences in ecommerce and beyond. To reach our goals, we need our own crew of remarkable creators—ambitious and collaborative teammates who stay focused on our north star: delighting our customers. If you’re ready to do the best work of your career, where you’ll be welcomed as your whole self from day one and supported with generous benefits, we hope you’ll join us.AI fluency at Klaviyo includes responsible use of AI (including privacy, security, bias awareness, and human-in-the-loop). We provide accommodations as needed. By participating in Klaviyo’s interview process, you acknowledge that you have read, understood, and will adhere to our Guidelines for using AI in the Klaviyo interview Process. For more information about how we process your personal data, see our Job Applicant Privacy Notice.Klaviyo is committed to a policy of equal opportunity and non-discrimination. We do not discriminate on the basis of race, ethnicity, citizenship, national origin, color, religion or religious creed, age, sex (including pregnancy), gender identity, sexual orientation, physical or mental disability, veteran or active military status, marital status, criminal record, genetics, retaliation, sexual harassment or any other characteristic protected by applicable law.IMPORTANT NOTICE: Our company takes the security and privacy of job applicants very seriously. We will never ask for payment, bank details, or personal financial information as part of the application process. All our legitimate job postings can be found on our official career site. Please be cautious of job offers that come from non-company email addresses (@klaviyo.com), instant messaging platforms, or unsolicited calls.By clicking "Submit Application" you consent to Klaviyo processing your Personal Data in accordance with our Job Applicant Privacy Notice. If you do not wish for Klaviyo to process your Personal Data, please do not submit an application.You can find our Job Applicant Privacy Notice here and here (FR).

Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Lead Security Governance & Risk Engineer in Boston, MA vacancy
  • Klaviyo seeks a Lead Security Governance & Risk Engineer to own risk decisions, automate risk reporting, and drive ISO 42001 readiness. You’ll quantify cyber and vendor risks, integrate with AI governance, and partner with Engineering, Legal, and Finance to make risk visible... 
    Suggested

    Klaviyo

    Boston, MA
    1 day ago
  •  ...States Digital Space LLC, based in Boston, MA, seeks a Governance, Risk, and Compliance Analyst II to lead day-to-day GRC operations and advance the risk...  ...program for AI/ML systems. You will work with Legal, Security, and Product teams to translate risk findings into governance... 
    Suggested

    United States Digital Space LLC

    Boston, MA
    2 days ago
  • $45k

     ...partnership model with shared risk and economics...  ...Data and Information Security is a core enabler of the...  ...work with the world's leading pharmaceutical partners...  ...up, and write the governance frameworks and policies...  ...protection as a first-class engineering discipline: encryption... 
    Suggested
    Full time
    Contract work
    Work at office
    Immediate start
    Remote work
    Flexible hours

    Alloy Therapeutics

    Waltham, MA
    a month ago
  •  ...seeking a Principal Information Security GRC Analyst to design,...  ...continuously improve our cybersecurity governance, risk, and compliance program. You will collaborate across Engineering, Product, IT, Legal, Privacy...  ...business growth. The role leads initiatives in cyber risk... 
    Suggested

    CarGurus

    Boston, MA
    3 days ago
  •  ...Corporation / John Hancock is seeking a senior AVP of AI to lead AI-enabled transformation across Corporate Functions in a hybrid...  ...assessment to value realization, with emphasis on security, governance, and responsible AI. The role combines strategic leadership with... 
    Suggested

    John Hancock

    Boston, MA
    14 hours ago
  • $124k - $280k

     ...Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance -...  ...standards.Responsibilities- Leading the development and implementation of...  ...stakeholders to support compliance and governance objectives- Promoting a culture of compliance... 
    Full time
    H1b

    PwC

    Boston, MA
    14 hours ago
  • $99k - $232k

     ...PrivacyManagement LevelManagerJob Description & SummaryThe OpportunityAs a Security Risk & Engineering - Tech and Cyber Risk & Compliance - Manager, you will play...  ...clients navigate these challenges.As a Manager, you will lead teams and manage client accounts, focusing on strategic... 
    Full time
    H1b

    PwC

    Boston, MA
    14 hours ago
  • PwC in Boston is seeking a Security Risk & Engineering Manager within Tech and Cyber Risk & Compliance to guide complex regulatory programs and lead client engagements. The role focuses on developing and implementing compliant strategies, mentoring staff, and delivering... 

    PwC

    Boston, MA
    1 day ago
  •  ...professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience...  ...certification in Claims, E&E, Benefits Engine, CRM, or UM - strongly preferred...  ...the world’s leading businesses, governments and other organizations build... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Boston, MA
    1 day ago
  •  ...across technology, operations, security, cloud, and industry-specific...  ...WORK:As an Oracle WMS Cloud Lead, you will design, configure,...  ...degree in Computer Science, Engineering or equivalent OR equivalent (...  ...world’s leading businesses, governments and other organizations build... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Boston, MA
    14 hours ago
  • $125k - $150k

     ...FullscriptWe’re an industry-leading health technology company on...  ...shape how privacy and data governance scale across a rapidly growing...  ...closely with Product, Engineering, Security, Data, Clinical, and Customer...  ...privacy posture, surface emerging risk areas to the Senior Director... 
    Full time

    Fullscript

    Boston, MA
    4 days ago
  •  ...delivering deep cloud, AI, and security expertise so clients can adopt...  ...Financials practitioner who leads the full functional workstream...  ...data quality prior to cutover Govern functional testing across SIT...  ...Manage Financials workstream risks and issues proactively - identify... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Boston, MA
    4 days ago
  •  ...Accenture is a global professional services company with leading capabilities in digital, cloud and security. Combining unmatched experience and specialized...  ...company that helps the world’s leading businesses, governments and other organizations build their digital core,... 
    Full time
    Work experience placement
    Live in
    Work at office
    Local area

    Accenture

    Boston, MA
    1 day ago
  • $115.2k - $158.4k

     ...IT Vendor Management Lead serves as the primary...  ...suppliers, driving vendor governance, contract and...  ...with product owners and engineering teams to align SaaS capabilities...  ..., operational, and risk objectives.Lead and...  ...Partner closely with IT, Security, Finance, Legal,... 
    Full time
    Contract work
    Temporary work
    Work at office
    Remote work
    Work from home
    Home office
    Monday to Friday

    Humana

    Boston, MA
    8 hours ago
  • $142.3k - $195.7k

     ...Offensive Tooling capability inside our Offensive Security organization, and we're looking for its founding engineer. As Lead, Offensive Security (AI & Tooling), you will...  ...OWASP Top 10 for LLM Applications, and the NIST AI Risk Management Framework.Model Context Protocol (... 
    Full time
    Temporary work
    For contractors
    Work at office
    Remote work
    Work from home
    Home office

    Humana

    Boston, MA
    3 days ago
  • $120k - $217.5k

     ...For:The State Street Cyber Security Architecture & Engineering team is seeking an...  ...chain security implementation/governance. The ideal candidate will...  ...etc, across the enterprise.Lead and grow the Software Supply...  ...on us to help them manage risk, respond to challenges, and... 
    Full time
    Temporary work
    Flexible hours

    State Street Bank

    Quincy, MA
    1 day ago
  • $110k - $207.5k

     ...Investment Management, you will lead a team of project managers and...  ...ensure adherence to relevant governance and oversight controls.We are...  ...services across asset classes, risk profiles, regions, and styles....  ...to define outcomes, secure alignment, and drive the involved... 
    Full time
    Temporary work
    Remote work
    Flexible hours
    Shift work

    State Street Bank

    Quincy, MA
    2 days ago
  • $172.5k - $225k

    Circle (NYSE: CRCL) is one of the world’s leading internet financial platform companies,...  ...help Circle shape the economic model, governance framework, and feature design of a...  ...cross-functionally with Product, Business, Engineering, Data, Treasury, Legal, and Policy teams... 
    Flexible hours

    Circle

    Boston, MA
    4 days ago
  • $174k - $210k

     ...Istari Istari is a digital engineering software company...  ...customers to simply and securely integrate their models...  ...Partnerships Lead The Strategic Partnerships...  ...solutions for complex government programs. Successful candidates...  ...impact, program risk reduction, and operational... 
    Permanent employment
    For contractors
    Remote work
    Home office
    Flexible hours

    Tari Labs

    Cambridge, MA
    1 day ago
  • $146.2k - $261.4k

     ...RAND's Center on AI, Security, and Technology (CAST)...  ...the Global and Emerging Risks (GER) Division...  ...analysis projects, and leading multidisciplinary teams...  ...of policy researchers, engineers, and scientists. Your...  ...directly by relevant government agencies, and the results... 
    Fixed term contract
    Work experience placement
    Remote work
    Work from home

    RAND

    Boston, MA
    14 hours ago
  • $201k - $251k

     ...its cloud compliance and security capabilities to support government cloud offerings and customers...  ...Compliance Program Lead to build and lead our authorization...  ...partners with Product, Engineering, Cloud Services, Security...  ..., milestone tracking, risk management, and executive... 
    Temporary work
    Worldwide

    InterSystems

    Boston, MA
    4 days ago
  • $25 - $50 per hour

     ...Role Overview TSA is accepting applications for Lead and Supervisory Transportation Security Officers at airports in Boston. These roles are ideal for individuals looking to step into leadership positions within airport security operations. TSA provides training to... 
    Shift work
    Night shift
    Weekend work

    Airport Security Careers

    Boston, MA
    4 days ago
  • Securitas Security Services USA, Inc. is seeking a Security Supervisor in Cambridge MA. The role supervises Security Officers and leads post operations, ensuring adherence to post orders, timely rounds, and accurate reporting. You will coach staff, participate in trainings... 

    Securitas Security Services USA, Inc.

    Somerville, MA
    4 days ago
  • $129.3k - $177.8k

     ...caring community(remote in location) The Lead Intelligence Data Architect serves as...  ...made usable across enterprise information security teams and tools. This role ensures Humana...  ...supports security operations, detection engineering, and vulnerability managementCollection... 
    Full time
    Temporary work
    Work at office
    Remote work
    Home office

    Humana

    Boston, MA
    8 hours ago
  • $238k - $374k

     ...biotech and the resources of a leading pharmaceutical company. It is...  ..., and a direct line to governance: this is the environment elite...  ...selectivity, half-life, immunogenicity risk, protein stability and...  ...and Test cycles for protein engineering; ensure generative protein design... 
    Minimum wage
    Temporary work
    Local area
    Remote work

    Takeda

    Boston, MA
    4 days ago
  • $30.85 per hour

     ...Job Description Job Description Overview Company Overview: Allied Universal®, North America’s leading security and facility services company, offers rewarding careers that provide you a sense of purpose. While working in a dynamic, welcoming, and collaborative... 
    Hourly pay
    Full time
    Currently hiring
    Work at office
    Local area
    Flexible hours
    Shift work
    Night shift

    Allied Universal

    Cambridge, MA
    2 days ago
  • $24.15 per hour

    Allied Universal is currently hiring a Full Time Security Officer for a Pharma Company in Cambridge, MA. Shift: Monday - Friday, 3 PM - 11 PM. Starting pay is $24.15 per hour, with paid orientation and training. Candidates should have 2+ years of security experience and... 
    Hourly pay
    Full time
    Currently hiring
    Monday to Friday
    Shift work

    Alliedbarton Security Services

    Cambridge, MA
    3 days ago
  • GardaWorld Security Services is seeking a Tactical Security Supervisor to oversee patrols and risk responses in Cambridge, MA. The role demands vigilance, quick assessment, and effective decision-making across varied environments such as retail stores, airports, and detention... 

    GardaWorld

    Cambridge, MA
    4 days ago
  •  ...expanding its cloud compliance and security capabilities to support government cloud offerings and customers with...  .../ GovRAMP Compliance Program Lead to build and lead our authorization...  ...visibility role partners with Product, Engineering, Cloud Services, Security, Managed... 

    InterSystems Corporation

    Boston, MA
    14 hours ago
  • Anthropic is seeking a Personal Security Program Manager to support the GSIS function. You will operate within established policy frameworks...  ..., and timely escalation when scope shifts, with a focus on risk-aware decision making and scalable security processes across the... 
    Shift work

    Anthropic

    Boston, MA
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Lead Security Governance & Risk Engineer. Be the first to apply!