Principal Engineer, Security
Core
Own Klaviyo's infrastructure security architecture (IAM, secrets management, network defenses) and build security guardrails as IaC modules to enable 'secure by default' across the platform.
Role type
Principal Engineer, Security (hands-on IC)
Builds
Production security controls, IaC guardrails, security tooling, and compliance frameworks for a multi-tenant SaaS platform.
Domain
Cloud Infrastructure Security / SaaS
Deliverable
production ML models | product features | infrastructure
Required skills
Cloud infrastructure security (AWS/GCP IAM, service mesh mTLS, secrets management), Vulnerability management, Security SLO definition, Threat modeling, IaC (Infrastructure as Code), Security ADR/RFC authoring, On-call incident response, AI/automation in security
Preferred skills
Zero-trust architecture, Enterprise compliance (SOC 2, ISO 27001, GDPR), CI/CD pipeline security, AI/ML system security
Technologies
AWS, GCP, Kubernetes, Terraform, Python, Go, Kubernetes, Prometheus, Grafana
Responsibilities
Define and own infrastructure security architecture; Build and maintain security guardrails as IaC modules; Own the vulnerability management program; Define security SLO and compliance framework; Author security ADRs and RFCs; Lead threat modeling and security design reviews; Partner with SRE/AppSec on cross-cutting initiatives; Write high-impact code and mentor engineers; Transform workflows by integrating AI into security engineering.
Seniority
Principal, hands-on IC with strategic influence