klaviyo

Lead Security Engineer, Enterprise Security

Apply Now

At a Glance

Location
Denver, Colorado, United States
Experience
7+ years
Posted
2026-07-30T17:32:07-04:00

Key Requirements

Required Skills

AWSAzureGCPTerraform

Domain Knowledge

  • Engineering
  • SaaS

Requirements

Have 7+ years of experience in security or infrastructure engineering roles, with demonstrated ownership of enterprise security domains such as SaaS security, IAM, Zero Trust, endpoint security, or cloud-delivered security services

Approach every project AI-first: you design with AI, refine with AI, and take full responsibility for validating and owning what you deploy — you are not a passive consumer of AI output

Hands-on by default — you are equally comfortable writing policy-as-code, reviewing architecture, and debugging a production issue

Proficient with Terraform for building and maintaining infrastructure-as-code across enterprise security systems

Experienced operating in AWS environments, with strong familiarity with cloud security services, IAM policies, and secure architecture patterns

Experience with enterprise IdP solutions such as Okta, AWS Cognito

Responsibilities

Partner across several teams to drive the security architecture and lifecycle of Klaviyo’s critical SaaS applications, from procurement to offboarding

Ensure the design and operations of identity and access management (IAM) across corporate SaaS platforms, including Just-in-Time Access (JITA), privilege management, and SSO/SCIM integrations; ensuring identity implementation meets or exceeds security standards

Mature and expand Klaviyo’s Zero Trust network architecture — establishing web gateways, defining secure access policies, and building the foundation for a modern corporate network security posture

Champion an AI-first approach to security engineering: designing, prototyping, and iterating with AI tools, and owning the responsible review and deployment of AI-generated artifacts

Manage and mature Cloudflare WAF policies and other perimeter security controls, ensuring coverage, tuning, and continuous improvement

Expand and mature Klaviyo’s endpoint security strategy and tooling, partnering with IT, Detection, Response, and the broader security teams to achieve full endpoint visibility, proactive threat coverage, and rapid response capability across the fleet