Director of Security Risk & Trust

Klaviyo Klaviyo · Enterprise · Boston, MA · IT & Security

Director of Security Risk and Trust responsible for engineering solutions for governance and compliance challenges at scale, building systems that make security and trust a competitive advantage, and leading a team at the intersection of security engineering, risk management, and regulatory compliance. This role will own the strategy and execution of Klaviyo's Risk and Trust program, partnering with Engineering, Product, Legal, IT, and business teams to embed compliance and risk management into how they build and operate. The role requires a strong technical foundation and an engineering mindset, with experience in designing automated compliance pipelines and developing governance frameworks for AI/ML systems. Responsibilities include defining and executing a forward-looking strategy, developing a risk management program, owning the compliance roadmap across various frameworks (ISO 27001, SOC 2, HIPAA, GDPR, CCPA/CPRA, AI governance), and translating regulatory requirements into engineering specifications. The role involves building compliance-as-code infrastructure, designing tooling and integrations, embedding controls into the SDLC, and evaluating technologies. A key focus is leading AI security governance, including developing an AI/ML governance framework aligned with ISO 42001, EU AI Act, and NIST AI RMF, and conducting risk assessments for AI/ML systems. The role also requires driving cross-functional impact with Product, Engineering, Legal, Privacy, Sales, and Customer Success teams, and engaging with executive leadership and the Board. The Director will also be hands-on with technical risk assessments, architecture reviews, automation scripting, and troubleshooting.

What you'd actually do

  1. Define and execute a forward-looking strategy that scales with Klaviyo's growth, product evolution, and expansion into new markets and regulated industries
  2. Develop a risk management program that quantifies and communicates risk in terms the business can act on—not just heat maps, but data-driven models that inform real decisions
  3. Own the compliance roadmap across frameworks including ISO 27001, ISO 42001, ISO 27017, ISO 27018, SOC 2 Type II, HIPAA, GDPR, CCPA/CPRA, and emerging AI governance regulations, identifying where frameworks overlap and engineering unified control sets rather than duplicating effort
  4. Translate regulatory and compliance requirements into clear, actionable engineering requirements that development teams can implement without ambiguity
  5. Build and maintain compliance-as-code infrastructure—automated evidence collection, continuous control monitoring, and policy-as-code implementations that reduce manual toil and increase assurance

Skills

Required

  • Security risk management
  • Regulatory compliance
  • Engineering mindset
  • Technical foundation
  • Governance frameworks
  • AI/ML governance
  • ISO 27001
  • SOC 2
  • HIPAA
  • GDPR
  • CCPA/CPRA
  • EU AI Act
  • NIST AI RMF
  • Compliance-as-code
  • CI/CD pipelines
  • Cloud infrastructure
  • Identity platforms
  • Risk assessments
  • Data poisoning
  • Model integrity
  • Bias
  • Prompt injection
  • Supply chain threats
  • Architecture diagrams
  • Terraform configs
  • Automation scripting

Nice to have

  • Salesforce
  • Customer Success
  • Trust teams
  • Board communication

What the JD emphasized

  • engineer solutions to governance and compliance challenges at scale
  • AI/ML governance framework
  • compliance-as-code
  • AI/ML systems