Klaviyo

Klaviyo

Klaviyo offers intelligent email marketing, SMS, and automation services for ecommerce businesses, empowering brands to personalize customer interactions and drive growth.

IT Services
1K-5K
Founded 2012

Description

  • Partner across Engineering, IT, and Security teams to drive the architecture and lifecycle of critical corporate SaaS applications from procurement to offboarding.
  • Design and operate identity and access management controls across corporate SaaS platforms, including JITA, privilege management, and SSO/SCIM integrations.
  • Mature and expand Klaviyo’s Zero Trust network architecture by establishing web gateways, defining secure access policies, and building modern corporate network security foundations.
  • Design, prototype, and iterate on security solutions using AI tools, while responsibly reviewing and deploying AI-generated artifacts.
  • Manage and continuously improve Cloudflare WAF policies and other perimeter security controls.
  • Expand and mature endpoint security strategy and tooling in partnership with IT, Detection, Response, and Security teams.
  • Deliver complex, multi-team security projects from requirements through production by decomposing problems into actionable workstreams.
  • Establish design patterns and technical standards, and mentor other engineers through hands-on technical leadership.

Requirements

  • 7+ years of experience in security or infrastructure engineering roles.
  • Demonstrated ownership of enterprise security domains such as SaaS security, IAM, Zero Trust, endpoint security, or cloud-delivered security services.
  • AI-first approach to engineering, with the ability to design, refine, validate, and own AI-assisted work.
  • Hands-on experience writing policy-as-code, reviewing architecture, and debugging production issues.
  • Proficiency with Terraform for infrastructure as code.
  • Experience operating in AWS environments, including cloud security services, IAM policies, and secure architecture patterns.
  • Experience with enterprise identity providers such as Okta or AWS Cognito.
  • Experience with enterprise security tools such as Cloudflare, Wiz, and CrowdStrike.
  • Knowledge of secrets management, JITA, SSO, SCIM, SAML 2.0, OAuth, and OIDC.
  • Experience mentoring engineers and influencing team-wide technical standards.
  • Nice to have: experience with GCP or Azure environments.
  • Nice to have: experience with Spacelift for IaC orchestration.
  • Nice to have: experience with AI agent development or securing AI coding platforms such as Lovable, Vercel, or Cursor.

Benefits

  • Base salary range of $175,200 to $262,800 USD for U.S. locations.
  • Participation in the annual cash bonus plan.
  • Equity may be included as part of total compensation.
  • Sign-on payments may be included.
  • Comprehensive health, welfare, and wellbeing benefits based on eligibility.
  • Up to 10% travel for onboarding, team meetings, client or partner work, and industry events.
  • Accommodations available as needed for responsible AI use during the interview process.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Saviynt IAM Specialist

The Missing Link 51-250 Internet Software & Services

The Missing Link is seeking a Security Engineer - Saviynt to support large enterprise identity governance initiatives, design and deliver Saviynt-based solutions, and strengthen its growing cyber security practice.

Active Directory Azure Cybersecurity JavaScript PowerShell REST API SAP SQL
5 hours, 11 minutes ago

AI Security Architect (REMOTE - United States)

EnableComp 251-1K Insurance

EnableComp is seeking a remote AI Security Architect to secure and govern its AI and machine learning initiatives within its healthcare revenue cycle management environment.

Azure Cybersecurity HIPAA LLM Machine Learning
5 hours, 26 minutes ago

Senior Infrastructure Security Engineer

Dropbox 1K-5K Internet Software & Services

Dropbox is hiring a Security Engineer to secure its AI and agentic infrastructure while helping protect products and users across cloud and on-prem environments.

Bash CI/CD CrowdStrike Go Java Kubernetes Linux LLM Node.js OAuth OpenID Connect OWASP Python Ruby Rust SIEM
5 hours, 26 minutes ago

Staff, Security Engineer

Fullscript 251-1K Health Care Providers & Services

Fullscript is hiring a Staff Security Engineer to lead hands-on security engineering across its healthcare technology platform, shaping secure product development and protecting systems that support practitioners and patients.

AWS GitHub GitLab GraphQL JavaScript Node.js Penetration Testing Ruby on Rails
5 hours, 56 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers