Lead Security Risk Engineer
About the role
The Lead Security Governance & Risk Engineer is a senior, hands-on role at the intersection of security governance and risk engineering. You will own the parts of the risk programme that turn policy and standards into measured, monitored, and automated risk decisions. Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third-party risk register, lead AI risk governance and ISO 42001 readiness, and build the automation that gives Klaviyo a continuously updated, quantified view of its risk posture.
You will work alongside the Trust and Compliance team, ensuring each security policy and standard connects to a specific risk it reduces and is enforced through operational controls. You will partner closely with Engineering, Product, GTS, Legal, Internal Audit, the ARIA team, and Finance to make risk legible across the business, while maintaining independence and providing credible challenge to first-line teams.
This role is ideal for an engineer who thinks like a risk professional: someone who automates repeatable assessments, instruments controls, quantifies risk in financial terms, and treats AI as foundational infrastructure.
Responsibilities
- Operate and maintain the risk register and taxonomy. Run the technology and third-party risk register on a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that risks aggregate, prioritize, and report meaningfully across the business.
- Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and risk criteria, manage the consolidated AI risk register against the K:AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions. Drive ISO/IEC 42001 readiness (Clauses 6.1 and 8.2/8.3) toward certification, collaborating with the Trust & Compliance and ARIA teams.
- Drive third-party risk automation and risk scoring. Contribute vendor and application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.
- Perform hands-on risk quantification. Apply cyber risk quantification (expected loss, probability, and cost of remediation versus acceptance) so leadership and the Technology Risk Committee can make data-driven investment and risk-acceptance decisions.
- Support the risk governance cadence. Contribute to weekly risk huddles, monthly risk reviews, and the quarterly Technology Risk Committee (CIO, CISO, CTO), preparing accurate, decision-ready risk materials and translating high-severity findings into clear business impact.
- Operate as a second line of defense. Provide independent oversight, credible challenge, and guidance to first-line teams, apply consistent risk taxonomies and reporting standards, and escalate risks that exceed established tolerance.
- Partner cross-functionally and close the loop. Work with Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings, tracking remediation through to closure with clear ownership.
Requirements
- 7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high-growth organization, including hands-on risk engineering or quantitative risk work.
- Strong command of cyber risk quantification, able to express risk in financial and business terms (FAIR, riskquant, or similar) rather than qualitative severity ratings alone.
- Hands-on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems to automate risk reporting.
- Experience building and running a technology and/or third-party risk register and taxonomy, with the tooling and process automation behind it.
- Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls) and how they translate into credible control requirements.
- Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, and endpoint and data-security telemetry, with a clear point of view on where AI augments versus replaces human judgement.
- Experience authoring and maintaining security policies and standards, with a governance mindset that ties policy to the risk it reduces and to operational controls.
- Able to operate independently as a second line of defense while engaging credibly with senior engineers, architects, and security teams.
- Proficiency discussing complex, nuanced topics with technical and non-technical audiences alike, and translating technical risk into clear business impact.
- Excellent ability to plan, prioritize, and execute work cross-functionally and on time.
Nice to have
- Experience leading an evolution from a traditional GRC/compliance model toward an automated, engineering-led, or AI-enabled risk capability.
- AI governance, model risk, or responsible-AI programme experience, and ISO 42001 readiness or certification work.
- Experience building metrics and dashboards (KPIs, KRIs, KCIs) using business intelligence or dashboarding tools like Tableau.
- Experience in a regulated or high-trust environment (SOC 2, ISO 27000 series, ISO 42001, HIPAA, GDPR).
- Threat modeling or secure design reviews, and experience designing or implementing technical security controls in AWS.
- Experience securing web applications, Kubernetes clusters, and/or containers.
- Relevant professional certifications such as CISSP, CISM, CRISC, ISO 27001 Lead Auditor/Lead Implementer, an ISO 42001/AI governance certification, or Open FAIR.