GRC CareersAGJ, the AI governance job boardPost a Job

Jobs › Lead Security Governance & Risk Engineer

Lead Security Governance & Risk Engineer

Klaviyo

Role at a glance

Category
GRC
Work arrangement
Hybrid
Location
Boston, MA
Posted
Jul 20, 2026
Apply for this roleApplications go directly to Klaviyo
ShareEmailLinkedInXFacebookPrint / Save PDF

Klaviyo is hiring a Lead Security Governance & Risk Engineer in Boston, MA. This is a GRC role in the governance, risk, and compliance field. Review the full details below and apply directly with Klaviyo.

Leads Klaviyo's AI risk governance program and ISO/IEC 42001 readiness workstreams, turning security policies into automated risk decisions. Runs the enterprise technology and third-party risk registers utilizing quantitative cyber risk methodologies (FAIR). Provides second-line independent risk challenge across engineering, legal, and internal audit

Full responsibilities and requirements are on Klaviyo's application page.

Apply for this role →
About Klaviyo
Hiring for governance, risk, and compliance roles on GRC Careers.
Browse all Klaviyo roles →

Location and market context

This role is based in Boston, MA on a hybrid schedule. Local candidates benefit from being close to Klaviyo's teams and regional hiring market, while the hybrid arrangement offers some flexibility. Confirm the exact in-office expectation and any relocation support with the employer.

About cybersecurity governance roles

Cybersecurity governance connects security control frameworks to business and regulatory risk, covering policy, risk assessment, and control assurance rather than hands-on operations. Roles like this one are typically evaluated against frameworks such as NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices.

How to position yourself for this cybersecurity governance role

Strong candidates emphasize security control frameworks, risk assessment, policy and standards, and translating technical security posture into governance and board-level reporting. In your resume and outreach, tie your experience to how Klaviyo would apply NIST CSF, ISO/IEC 27001, SOC 2, and security risk and control-assurance practices, and lead with concrete outcomes rather than duties.

Similar GRC roles

Lead IT Cyber Risk & Controls Analyst
Blue Cross Blue Shield of Michigan
Detroit, MI$95k to $135k
Senior Cybersecurity GRC Analyst
Caterpillar
Peoria, IL$98k to $138k
Service Information Security Officer (SISO)
Department of the Air Force - Agency Wide
Pentagon, Arlington$152k to $210k
IT CYBERSECURITY SPECIALIST (INFOSEC)
Army National Guard Units
Colchester, Vermont$91k to $119k
IT CYBERSECURITY SPECIALIST (INFOSEC)
United States Fleet Forces Command
Suffolk, Virginia$115k to $158k
IT Cybersecurity Specialist (SYSADMIN)
U.S. Coast Guard
Elizabeth City, North Carolina$76k to $99k
Get more roles like this by email
We will email you new GRC roles in Boston, MA as they post. Free and confidential, one click to unsubscribe.

More GRC jobs: All GRC roles · Browse by category & location