klaviyo
Lead Security Engineer, Enterprise Security
At a Glance
- Location
- Denver, Colorado, United States
- Experience
- 7+ years
- Posted
- 2026-07-30T17:32:07-04:00
Key Requirements
Required Skills
Domain Knowledge
- Engineering
- SaaS
Requirements
Have 7+ years of experience in security or infrastructure engineering roles, with demonstrated ownership of enterprise security domains such as SaaS security, IAM, Zero Trust, endpoint security, or cloud-delivered security services
Approach every project AI-first: you design with AI, refine with AI, and take full responsibility for validating and owning what you deploy — you are not a passive consumer of AI output
Hands-on by default — you are equally comfortable writing policy-as-code, reviewing architecture, and debugging a production issue
Proficient with Terraform for building and maintaining infrastructure-as-code across enterprise security systems
Experienced operating in AWS environments, with strong familiarity with cloud security services, IAM policies, and secure architecture patterns
Experience with enterprise IdP solutions such as Okta, AWS Cognito
Responsibilities
Partner across several teams to drive the security architecture and lifecycle of Klaviyo’s critical SaaS applications, from procurement to offboarding
Ensure the design and operations of identity and access management (IAM) across corporate SaaS platforms, including Just-in-Time Access (JITA), privilege management, and SSO/SCIM integrations; ensuring identity implementation meets or exceeds security standards
Mature and expand Klaviyo’s Zero Trust network architecture — establishing web gateways, defining secure access policies, and building the foundation for a modern corporate network security posture
Champion an AI-first approach to security engineering: designing, prototyping, and iterating with AI tools, and owning the responsible review and deployment of AI-generated artifacts
Manage and mature Cloudflare WAF policies and other perimeter security controls, ensuring coverage, tuning, and continuous improvement
Expand and mature Klaviyo’s endpoint security strategy and tooling, partnering with IT, Detection, Response, and the broader security teams to achieve full endpoint visibility, proactive threat coverage, and rapid response capability across the fleet