Lead Security Engineer, Enterprise Security

Klaviyo Klaviyo · Enterprise · Boston, MA · IT & Security

Lead Security Engineer for an AI-first company, focusing on securing corporate systems (SaaS, IAM, Zero Trust, endpoints, perimeter). This is a hands-on technical leadership role involving project delivery, setting standards, and mentoring. The role emphasizes an AI-first approach to security engineering, using AI tools for design and iteration, and taking ownership of AI-generated artifacts. Experience with enterprise security domains, Terraform, AWS, and specific security tools (Cloudflare, Wiz, CrowdStrike) is required. Nice-to-haves include GCP/Azure experience, IaC orchestration, AI agent development, or securing AI coding platforms. The company is AI-first and requires AI fluency.

What you'd actually do

  1. Partner across several teams to drive the security architecture and lifecycle of Klaviyo’s critical SaaS applications, from procurement to offboarding
  2. Ensure the design and operations of identity and access management (IAM) across corporate SaaS platforms, including Just-in-Time Access (JITA), privilege management, and SSO/SCIM integrations; ensuring identity implementation meets or exceeds security standards
  3. Mature and expand Klaviyo’s Zero Trust network architecture — establishing web gateways, defining secure access policies, and building the foundation for a modern corporate network security posture
  4. Champion an AI-first approach to security engineering: designing, prototyping, and iterating with AI tools, and owning the responsible review and deployment of AI-generated artifacts
  5. Manage and mature Cloudflare WAF policies and other perimeter security controls, ensuring coverage, tuning, and continuous improvement

Skills

Required

  • 7+ years of experience in security or infrastructure engineering roles
  • Demonstrated ownership of enterprise security domains such as SaaS security, IAM, Zero Trust, endpoint security, or cloud-delivered security services
  • Proficient with Terraform for building and maintaining infrastructure-as-code
  • Experienced operating in AWS environments, with strong familiarity with cloud security services, IAM policies, and secure architecture patterns
  • Experience with enterprise security tooling such as Cloudflare (WAF, gateway), Wiz (CNAPP/cloud security), and CrowdStrike (EDR/endpoint)
  • Knowledgeable in secrets management, JITA, and modern identity patterns including SSO, SCIM, and privileged access workflows including SAML 2.0, SCIM, OAuth and OIDC
  • Experienced mentoring engineers and working through influence

Nice to have

  • Experience with GCP or Azure environments
  • Spacelift for IaC orchestration
  • AI agent development
  • securing AI coding platforms

What the JD emphasized

  • AI fluency isn’t optional
  • Champion an AI-first approach to security engineering
  • Approach every project AI-first
  • design with AI, refine with AI
  • validating and owning what you deploy
  • not a passive consumer of AI output
  • securing AI coding platforms