Lead Security Engineer, Enterprise Security

1 hour, 24 minutes ago
Full-time
Lead
Cybersecurity
Klaviyo

Klaviyo

Klaviyo offers intelligent email marketing, SMS, and automation services for ecommerce businesses, empowering brands to personalize customer interactions and drive growth.

IT Services
1K-5K
Founded 2012

Description

  • Partner across Engineering, IT, and Security teams to drive the architecture and lifecycle of critical corporate SaaS applications from procurement to offboarding.
  • Design and operate identity and access management controls across corporate SaaS platforms, including JITA, privilege management, and SSO/SCIM integrations.
  • Mature and expand Klaviyo’s Zero Trust network architecture by establishing web gateways, defining secure access policies, and building modern corporate network security foundations.
  • Design, prototype, and iterate on security solutions using AI tools, while responsibly reviewing and deploying AI-generated artifacts.
  • Manage and continuously improve Cloudflare WAF policies and other perimeter security controls.
  • Expand and mature endpoint security strategy and tooling in partnership with IT, Detection, Response, and Security teams.
  • Deliver complex, multi-team security projects from requirements through production by decomposing problems into actionable workstreams.
  • Establish design patterns and technical standards, and mentor other engineers through hands-on technical leadership.

Requirements

  • 7+ years of experience in security or infrastructure engineering roles.
  • Demonstrated ownership of enterprise security domains such as SaaS security, IAM, Zero Trust, endpoint security, or cloud-delivered security services.
  • AI-first approach to engineering, with the ability to design, refine, validate, and own AI-assisted work.
  • Hands-on experience writing policy-as-code, reviewing architecture, and debugging production issues.
  • Proficiency with Terraform for infrastructure as code.
  • Experience operating in AWS environments, including cloud security services, IAM policies, and secure architecture patterns.
  • Experience with enterprise identity providers such as Okta or AWS Cognito.
  • Experience with enterprise security tools such as Cloudflare, Wiz, and CrowdStrike.
  • Knowledge of secrets management, JITA, SSO, SCIM, SAML 2.0, OAuth, and OIDC.
  • Experience mentoring engineers and influencing team-wide technical standards.
  • Nice to have: experience with GCP or Azure environments.
  • Nice to have: experience with Spacelift for IaC orchestration.
  • Nice to have: experience with AI agent development or securing AI coding platforms such as Lovable, Vercel, or Cursor.

Benefits

  • Base salary range of $175,200 to $262,800 USD for U.S. locations.
  • Participation in the annual cash bonus plan.
  • Equity may be included as part of total compensation.
  • Sign-on payments may be included.
  • Comprehensive health, welfare, and wellbeing benefits based on eligibility.
  • Up to 10% travel for onboarding, team meetings, client or partner work, and industry events.
  • Accommodations available as needed for responsible AI use during the interview process.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Head of Classified Infrastructure, Frontier Systems

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is seeking a senior security leader for its Frontier Systems team to shape and execute classified infrastructure and information security strategy for defense and intelligence programs.

Cybersecurity Penetration Testing
9 minutes ago

Staff Security Engineer

Anduril Industries 1K-5K Aerospace & Defense

Anduril Industries is hiring a Security Engineer to secure its OT and ICS environments and help design foundational defenses for advanced defense technology and factory systems.

Go Linux Python Rust
9 minutes ago

Senior Security Engineering Manager, Enterprise Security

Upstart 1K-5K Banks

Upstart is hiring a Senior Security Manager to lead enterprise security engineering efforts that reduce risk across corporate systems, cloud environments, and security operations.

AWS CI/CD Kubernetes SIEM
24 minutes ago

Security Engineer, Detection & Response - Monitoring & Triage

Block 10K-50K Capital Markets

Block is hiring a Detection and Response Team (DART) security engineer to lead monitoring, triage, and incident response across its endpoints, cloud, identity, SaaS, and product environments.

AWS DNS Kubernetes Linux macOS Network Security SQL
39 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers