Principal Engineer, Security

United States Digital Space LLC

Boston (MA)

On-site

USD 244,000 - 366,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Klaviyos in the United States is seeking a Principal Engineer, Security to own infrastructure security architecture across IAM, secrets, network defenses, and compliance controls.

This hands-on IC role collaborates with the Core Infrastructure PE, SRE, and AppSec teams to make security by default a reality for every engineering team. You will lead threat modeling, guardrails, and vulnerability management to reduce risk at scale.

Qualifications

  • 10+ years in infrastructure or platform security engineering.
  • Deep cloud security expertise (IAM, service mesh mTLS, secrets).
  • Ability to translate security work into business language.
  • Experience with security tooling and automation in CI/CD pipelines.

Responsibilities

  • Define and own the company's infrastructure security architecture: IAM frameworks, service-to-service auth, secrets management, network segmentation, and production access controls, designed to scale with our multi-tenant, multi-region footprint.
  • Build and maintain security guardrails as IaC modules; codify controls into golden paths that teams inherit automatically so security improves with velocity, not against it.
  • Own the vulnerability management program: SLO-backed triage and remediation, trend tracking, and systemic fixes, turn recurring vulnerability classes into solved engineering problems.
  • Define the security SLO and compliance framework for production infrastructure; run readiness reviews, communicate posture clearly to engineering and exec stakeholders.
  • Author security ADRs and RFCs; partner with the Core Infrastructure PE to embed security controls in CI/CD pipelines, paved roads, and the observability stack.
  • Lead threat modeling and security design reviews for high-risk architectural changes, accelerate delivery by making reviews lightweight and high-signal.
  • Partner with SRE, AppSec, and FinOps on cross-cutting initiatives: zero-trust progress, GDPR/compliance guardrails, and audit readiness for SOC 2/ISO 27001.
  • Write high-impact code, automation, and tooling; mentor Staff and Senior security engineers across teams through design pairing, code review, and example.
  • Transform workflows by putting AI at the center, building smarter systems and ways of working from the ground up.

Skills

Security engineering
Cloud security (AWS/GCP)
CI/CD security
Threat modeling
Automation

Job description

*At the company, we value the unique backgrounds, experiences and perspectives each the company (we call ourselves Klaviyos) brings to our workplace each and every day. We believe everyone deserves a fair shot at success and appreciate the experiences each person brings beyond the traditional job requirements. Want to learn more about life at the company? Visit the company.com/careersto see how we empower creators to own their own destiny.*

the company's platform sends billions of messages and processes petabytes of customer data for hundreds of thousands of businesses. As we scale up-market and embed AI/agentic systems throughout our product and platform, security must be built into the foundation, not bolted on. The Principal Engineer, Security is a hands‑on IC who owns the company's infrastructure security architecture: IAM, secrets management, network defenses, vulnerability management, security tooling, and the compliance controls that underpin our enterprise and regulatory obligations.

This is an individual-contributor role, no direct reports. You lead through technical depth, code, and design quality, partnering closely with the Core Infrastructure PE, SRE, and AppSec teams to make "secure by default" a reality for every engineering team at the company.

What You'll Do
  • Define and own the company's infrastructure security architecture: IAM frameworks, service-to-service auth, secrets management, network segmentation, and production access controls, designed to scale with our multi-tenant, multi-region footprint.
  • Build and maintain security guardrails as IaC modules; codify controls into golden paths that teams inherit automatically so security improves with velocity, not against it.
  • Own the vulnerability management program: SLO-backed triage and remediation, trend tracking, and systemic fixes, turn recurring vulnerability classes into solved engineering problems.
  • Define the security SLO and compliance framework for production infrastructure; run readiness reviews, communicate posture clearly to engineering and exec stakeholders.
  • Author security ADRs and RFCs; partner with the Core Infrastructure PE to embed security controls in CI/CD pipelines, paved roads, and the observability stack.
  • Lead threat modeling and security design reviews for high-risk architectural changes, accelerate delivery by making reviews lightweight and high-signal.
  • Partner with SRE, AppSec, and FinOps on cross-cutting initiatives: zero-trust progress, GDPR/compliance guardrails, and audit readiness for SOC 2/ISO 27001.
  • Write high-impact code, automation, and tooling; mentor Staff and Senior security engineers across teams through design pairing, code review, and example.
  • Transform workflows by putting AI at the center, building smarter systems and ways of working from the ground up.
Who You Are
  • Experience: 10+ years in infrastructure or platform security engineering, with a track record of shipping security improvements that measurably reduced risk or improved compliance posture at scale.
  • Technical depth: Deep in cloud infrastructure security (AWS/GCP IAM, service mesh mTLS, secrets management, network defenses); you architect and ship production controls, not just audit them.
  • SLO and compliance rigor: You define security SLOs, track MTTR for vulnerabilities, and communicate risk posture clearly; you translate security work into business language that non-security stakeholders act on.
  • Developer-centric mindset: You build tools and guardrails that other engineers adopt because they make their work easier—not because they're required to.
  • Cross-org influence: You align teams through threat models, security reviews, and IaC guardrails; you earn credibility via code, design quality, and clear reasoning, not title.
  • Operational excellence: You've been on-call for security incidents. You write runbooks, lead readiness reviews, and treat recurring vulnerabilities as systemic engineering problems.
  • Communication: You write crisp ADRs and RFCs, run effective security design reviews, and translate risk exposure into decisions business stakeholders can act on.
  • AI tools and automation: You've brought AI into security engineering, automated threat detection, intelligent vulnerability triage, AI-assisted compliance checks, or security copilots—with explicit guardrails and audit trails.
  • You've already experimented with AI in work or personal projects, and you're excited to dive in and learn fast. You're hungry to responsibly explore new AI tools and workflows, finding ways to make your work smarter and more efficient.
Nice to Haves
  • Experience with zero-trust architecture and progressive access control in a large multi-tenant SaaS environment.
  • Deep familiarity with enterprise compliance frameworks (SOC 2, ISO 27001, GDPR) and the infrastructure controls that underpin them.
  • Track record of embedding security tooling into CI/CD and IaC pipelines adopted org-wide.
  • Experience securing AI/ML systems: model access controls, data privacy guardrails, and agentic system security boundaries.
Success in 6 - 12 Months
  • Security guardrails codified as IaC modules and enforced in paved roads; IAM and secrets management posture measurably improved.
  • Security SLO framework established; MTTR for critical vulnerabilities trending down; recurring vulnerability classes addressed systemically.
  • Zero-trust progress measurable against defined milestones; demonstrable audit readiness for SOC 2 / ISO 27001.

Massachusetts Applicants:It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Our salary range reflects the cost of labor across various U.S. geographic markets. The range displayed below reflects the minimum and maximum target salaries for the position across all our US locations. The base salary offered for this position is determined by several factors, including the applicant’s job-related skills, relevant experience, education or training, and work location.

In addition to base salary, our total compensation package may include participation in the company’s annual cash bonus plan, variable compensation (OTE) for sales and customer success roles, equity, sign-on payments, and a comprehensive range of health, welfare, and wellbeing benefits based on eligibility.

Your recruiter can provide more details about the specific salary/OTE range for your preferred location during the hiring process.

Base Pay Range For US Locations:

$244,000-$366,000 USD

*This role may require up to 10% travel for purposes such as new h*

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff+ Software Engineer, Security Infrastructure
Staff+ Software Engineer, Security Infrastructure

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare programs
Vision, dental coverage
HSA/FSA contributions
+8
Staff+ Security Engineer, Developer Tools
Staff+ Security Engineer, Developer Tools

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare coverage
Mental health support
Parental leave
+3
Senior Software Engineer - Infrastructure Security
Senior Software Engineer - Infrastructure Security

United States Digital Space LLC • Boston (MA)

On-site
USD 130,000 - 180,000
Staff+ Security Engineer, Core Command
Staff+ Security Engineer, Core Command

United States Digital Space LLC • San Mateo (CA)

On-site
USD 200,000 - 300,000
Healthcare programs
Medical/Vision/Dental coverage
HSA with employer contributions
+7
Senior Corporate Security Engineer
Senior Corporate Security Engineer

United States Digital Space LLC • Bellevue (CA)

Hybrid
USD 166,000 - 195,000
Health insurance
Equity ownership
401(k) matching
+2
Software Engineering Manager, Data Protection Platform
Software Engineering Manager, Data Protection Platform

United States Digital Space LLC • San Mateo (CA)

On-site
USD 250,000 - 350,000
Healthcare programs
Vision and dental coverage
HSA with employer contributions
+3
Principal Consulting Architect, Security
Principal Consulting Architect, Security

United States Digital Space LLC • United States

On-site
USD 160,000 - 253,000
Stock program
401k with company matching
Comprehensive benefits
Senior Security Engineer, Corporate Services Security
Senior Security Engineer, Corporate Services Security

Amazon • Boston (MA)

On-site
USD 178,400 - 226,700
Health insurance
401(k) matching
Paid time off
+1
Staff Application Security Engineer
Staff Application Security Engineer

United States Digital Space LLC • United States

Hybrid
USD 240,000 - 300,000
Up to four weeks of fully remote work per year
Senior-Staff Software Engineer, Tooling
Senior-Staff Software Engineer, Tooling

United States Digital Space LLC • San Mateo (CA)

On-site
USD 130,000 - 280,000
Healthcare
Vision & Dental
HSA / FSA
+8