Principal Engineer, Security
Job description
About the role
You define and own the end-to-end infrastructure security architecture for Klaviyo, shaping how IAM, secrets, and network controls scale across a multi-tenant, multi-region footprint. You build security as code guardrails that teams inherit automatically, ensuring security improves with product velocity rather than lagging behind. You lead vulnerability management as a SLO-backed program, turning recurring classes of issues into solved engineering problems through systemic fixes. You author security ADRs and RFCs, run threat modeling and design reviews for high-risk changes, and translate complex risk findings into clear actions for both engineers and executives. You partner closely with Core Infrastructure, SRE, and AppSec to embed zero-trust, compliance controls, and audit readiness into every paved road and CI/CD pipeline. You mentor engineers across the organization, using design pairing, code review, and hands-on automation to elevate the entire security culture at Klaviyo.
Key facts
What you'll do
Define and own Klaviyo's infrastructure security architecture including IAM frameworks, service-to-service authentication, secrets management, network segmentation, and production access controls designed for a multi-tenant, multi-region environment.
Build and maintain security guardrails as Infrastructure as Code modules, codifying controls into golden paths that engineering teams inherit automatically so security scales with velocity.
Own the vulnerability management program with SLO-backed triage, remediation tracking, trend analysis, and systemic fixes that convert recurring vulnerability patterns into solved engineering problems.
Define security service-level objectives and the compliance framework for production infrastructure, execute readiness reviews, and communicate posture clearly to both technical teams and executive stakeholders.
Author security Architecture Decision Records and Requests for Comments, collaborating with Core Infrastructure Principal Engineers to embed security controls directly into CI/CD pipelines, paved roads, and observability platforms.
Lead threat modeling and security design reviews for high-risk architectural changes, making reviews lightweight, high-signal, and actionable to accelerate secure delivery.
Partner with SRE, AppSec, and FinOps on cross-cutting initiatives such as zero-trust adoption, GDPR and regulatory guardrails, and audit readiness for SOC 2 and ISO 27001.
Write high-impact code, automation, and tooling while mentoring Staff and Senior security engineers across teams through design pairing, rigorous code review, and concrete examples.
Transform workflows by putting AI at the center of tooling and processes, building smarter systems and modern ways of working from the ground up.
Establish and operate security observability and alerting strategies that surface meaningful risk signals without overwhelming defenders, enabling faster response and better decisions.
Champion secure software development lifecycle practices, ensuring security requirements are considered at design time, implemented during development, and verified before production release.
Drive incident response readiness for infrastructure services, participating in on-call rotations, post-incident reviews, and improving controls to prevent recurrence at scale.
Collaborate with product and platform teams to integrate security into roadmaps, balancing risk reduction with delivery speed and maintaining a pragmatic, business-aware approach.
Contribute to open-source security tooling and internal platform efforts that raise the baseline security posture across the industry while reflecting Klaviyo's unique multi-tenant constraints.
Requirements
10+ years of experience in infrastructure or platform security engineering, with a track record of shipping improvements that measurably reduced risk or enhanced compliance posture at scale.
Deep expertise in cloud infrastructure security controls such as AWS or GCP IAM, service mesh mutual TLS, secrets management systems, and network defense mechanisms.
Demonstrated ability to define and track security SLOs, perform vulnerability trend analysis, and communicate risk in language that non-security stakeholders understand and act upon.
A builder's mindset focused on creating developer-friendly tools and guardrails that teams adopt voluntarily because they deliver clear workflow advantages.
Proven success aligning multiple teams through threat models, security design reviews, and Infrastructure as Code guardrails, leveraging code quality and design clarity to earn trust.
Strong experience with compliance frameworks relevant to multi-tenant SaaS businesses, including SOC 2, ISO 27001, and GDPR, and comfort with audit evidence preparation and remediation tracking.
Hands-on experience contributing to or maintaining security tooling, automation, and CI/CD integrations that scale reliably in high-velocity environments.
Excellent written and verbal communication skills for documenting designs, leading reviews, and influencing stakeholders without direct authority.