Lead Security Governance & Risk Engineer

United States Digital Space LLC

Boston (MA)

On-site

USD 140,000 - 210,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Klaviyos is seeking a Lead Security Governance & Risk Engineer to own parts of the risk program, turning policy into automated risk decisions. You’ll run risk registers, lead AI risk governance, and build automation to continuously quantify risk posture.

Collaboration with Trust & Compliance, Engineering, Legal, and Finance is essential to align risk with business priorities. The role demands hands-on risk engineering, cybersecurity risk quantification, and strong communication with senior

Qualifications

  • 7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high-growth organization, including hands-on risk engineering or quantitative risk work.
  • Strong command of cyber risk quantification, able to express risk in financial and business terms (FAIR, riskquant, or similar) rather than qualitative severity ratings alone.
  • Hands-on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems and to automate risk reporting.
  • Experience building and running a technology and/or third-party risk register and taxonomy, with the tooling and process automation behind it.
  • Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls).
  • Hands-on familiarity with modern risk and security tooling: third-party risk platforms, cyber risk quantification, vulnerability management, and endpoint and data-security telemetry.

Responsibilities

  • Operate and maintain the risk register and taxonomy.
  • Lead AI risk governance and ISO 42001 readiness.
  • Drive third-party risk automation and risk scoring.
  • Perform hands-on risk quantification to support leadership decisions.
  • Support risk governance cadence with risk materials and reviews.
  • Operate as a second line of defense with independent oversight and reporting.
  • Collaborate across Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk findings.

Skills

Cyber risk quantification
Financial risk terms
Risk governance
Translate risk to business
Independent work
Communication to non-technical
SQL
Python
APIs integration

Tools

SQL
Python
APIs

Job description

*At the company, we value the unique backgrounds, experiences and perspectives each the company (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. If you’re a close but not exact match with the description, we hope you’ll still consider applying. Want to learn more about life at the company? Visit the company.com/careersto see how we empower creators to own their own destiny.*

An exciting opportunity within the Security Trust and Risk (STAR) team whose mission is to ensure the safety and security of our customers, partners and Klaviyos as well as deliver best in class technology solutions, infrastructure and services. This is achieved by providing a robust and secure technology foundation to do great work. We solve problems using technology, embrace automation and AI, and support the company's continued scalability and sustainable employee growth in a rapidly evolving environment.

The STAR team assists the Global Security Services (GSS) organization in developing and refining information security policies, standards and strategy, enterprise risk management, creating metrics and reporting, coordinating cross-functional projects, and strategically aligning global information security initiatives with the broader CISO vision amongst other governance, risk and compliance efforts. The STAR team is highly collaborative and cross-functional, working closely with various functions within the GSS team (namely Security Product and Development and Security Intelligence Operations), Global Technology Solutions (GTS) team and the broader the company organization.

About the role:

The Lead Security Governance & Risk Engineer is a senior, hands‑on role at the point where security governance meets risk engineering. You will own the parts of the risk programme that turn policy and standards into measured, monitored, and automated risk decisions. Reporting to the Senior Manager, Security Risk Engineering and operating as a second line of defense, you will run the technology and third‑party risk register, lead AI risk governance and ISO 42001 readiness, and build the automation that gives the company a continuously updated, quantified view of its risk posture.

You will work alongside the Trust and Compliance team who are the custodians of our security policies and standards, making sure each one connects to a specific risk it reduces and is enforced through operational controls rather than living as a document. You will partner closely with Engineering, Product, GTS, Legal, Internal Audit, the ARIA team, and Finance to make risk legible across the business, and you will challenge first‑line teams credibly while keeping your independence. This is a role for an engineer who thinks like a risk professional: someone who automates repeatable assessment, instruments controls, quantifies risk in financial terms, and treats AI as foundational infrastructure rather than an afterthought.

How you’ll have an impact:
  • Operate and maintain the risk register and taxonomy. Run the technology and third‑party risk register on a consistent standard (threat actor, technique, scenario, safeguard, loss event, quantification) so that risks aggregate, prioritise, and report meaningfully across the business.
  • Lead AI risk governance and ISO 42001 readiness. Maintain the AI risk assessment methodology and risk criteria, maintain the consolidated AI risk register against the K:AI inventory, and define AI risk treatment plans that map each risk to specific controls and treatment decisions. Drive ISO/IEC 42001 readiness (Clauses 6.1 and 8.2/8.3) toward the certification target, working with the Trust & Compliance and ARIA teams.
  • Drive third‑party risk automation and risk scoring. Contribute vendor and application risk signals into the composite risk score, partnering with the TPRM lead who owns vendor onboarding automation and the TPRM process.
  • Perform the hands‑on risk quantification. Apply cyber risk quantification (expected loss, probability, and cost of remediation versus acceptance) so leadership and the Technology Risk Committee can make rational investment and risk‑acceptance decisions rather than relying on qualitative severity labels.
  • Support the risk governance cadence. Contribute to weekly risk huddles, monthly risk reviews, and the quarterly Technology Risk Committee (CIO, CISO, CTO), preparing accurate, succinct, decision‑ready risk materials and translating high‑severity findings into clear business impact.
  • Operate as a second line of defense. Provide independent oversight, credible challenge, and guidance to first‑line teams, apply consistent risk taxonomies and reporting standards, and elevate risks that exceed established tolerance.
  • Partner cross‑functionally and close the loop. Work with Engineering, Product, GTS, Legal, Internal Audit, ARIA, and Finance on risk and audit findings affecting systems and processes, tracking findings and remediation through to closure with clear ownership.
Who you are:
  • 7+ years of experience in information security, technology risk, cyber risk, or operational risk within a large, complex, or high‑growth organization, including hands‑on risk engineering or quantitative risk work.
  • Strong command of cyber risk quantification, able to express risk in financial and business terms (FAIR, riskquant, or similar) rather than qualitative severity ratings alone.
  • Hands‑on engineering ability: SQL, Python, and integrating with APIs to extract, transform, and load data between systems and to automate risk reporting.
  • Experience building and running a technology and/or third‑party risk register and taxonomy, with the tooling and process automation behind it.
  • Working knowledge of security and AI frameworks (NIST CSF and RMF, ISO 27000 series, ISO 42001, SOC 2, PCI DSS, CIS Controls) and how they translate into credible control requirements.
  • Hands‑on familiarity with modern risk and security tooling: third‑party risk platforms, cyber risk quantification, vulnerability management, and endpoint and data‑security telemetry, with a clear point of view on where AI augments versus replaces human judgement.
  • Experience authoring and maintaining security policies and standards, with a governance mindset that ties policy to the risk it reduces and to operational controls.
  • Able to operate independently as a second line of defense while engaging credibly with senior engineers, architects, and security teams.
  • Proficiency discussing complex, nuanced topics with technical and non‑technical audiences alike, and translating technical risk into clear business impact.
  • Excellent ability to plan, prioritise, and execute work cross‑functionally and on time.
Nice to have:
  • Experience leading an evolution from a traditional GRC / compliance model toward an automated, engineering‑led, or AI‑enabled risk capability.
  • AI governance, model risk, or responsible‑AI programme experience, and ISO 42001 readiness or certification work.
  • Experience building me
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Security Governance & Risk Engineer
Lead Security Governance & Risk Engineer

Klaviyo • Boston (MA)

On-site
USD 156,000 - 234,000
Engineering Manager
Engineering Manager

Safe Security • Town of Delhi (NY)

On-site
USD 180,000 - 240,000
Equity
Unlimited Leave
Comprehensive Benefits
+1
Manager of Risk & Governance (AI Safety)
Manager of Risk & Governance (AI Safety)

Reflection AI • San Francisco (CA)

On-site
USD 200,000 - 280,000
Lead Security Risk Engineer, AI & GRC Automation
Lead Security Risk Engineer, AI & GRC Automation

United States Digital Space LLC • Boston (MA)

On-site
USD 140,000 - 210,000
CRO - Information Security & Risk Oversight Lead
CRO - Information Security & Risk Oversight Lead

Bloomberg • New York (NY)

On-site
USD 140,000 - 180,000
Security Risk Manager
Security Risk Manager

United States Digital Space LLC • San Francisco (CA)

Hybrid
USD 194,000 - 220,000
Mental health, wellness & fitness benefits
Career coaching & support
Inclusive family building benefits
+2
Senior Security AI Engineer
Senior Security AI Engineer

Imperial Funding Corporation • Kansas City (MO)

On-site
USD 130,000 - 190,000
Medical, prescription, dental benefits
Wellness program and EAP
401(k) with company match
+1
Senior Lead Software Engineer - Technology Risk
Senior Lead Software Engineer - Technology Risk

JPMorgan Chase & Co. • Plano (TX)

On-site
USD 150,000 - 210,000
Chief Information Security Officer
Chief Information Security Officer

Glocomms • Charlotte (NC)

On-site
USD 150,000 - 200,000
Risk and Compliance Lead
Risk and Compliance Lead

Replit • Foster City (CA)

On-site
USD 180,000 - 240,000
401(k) program
Health insurance
Dental insurance
+10