Senior Corporate Security Engineer - Klaviyo|Meet.jobs

薪資

156k - 235k USD Annually

技能需求

    工作機會描述

    Klaviyo is seeking a Senior Corporate Security Engineer to join the Security Development Operations (SDO) team. The Corporate Security Engineer will play a critical role in protecting Klaviyo by monitoring, configuring, and making available to the company corporate supplied security products such as WAF tooling, CNAPP, EDR, cloud Integrations, network configurations and tooling. This role involves developing, implementing, and maintaining security systems and practices that ensure the safety of our digital assets. The ideal candidate will have a strong background in security engineering, with experience managing commercial security products, configuration of cloud environments including Azure and AWS, and collaborating across various teams to enhance our security posture.

    How you will make a difference:

    • Develop systems and tools to enhance the security properties of corporate infrastructure, including Identity and Access Management, Endpoint Security, Data Loss Prevention, and Zero Trust architecture.
    • Collaborate with various teams to implement security strategies and policies for in-house and SaaS security applications.
    • Conduct security reviews and provide architectural guidance for infrastructure systems, account lifecycle, and automation.
    • Execute and improve security consulting processes through runbooks and automation.
    • Perform risk assessments and threat modeling to identify and mitigate potential security risks.
    • Build and maintain security controls across various domains, including EDR, email security, ransomware resilience, and more.
    • Develop and maintain security automation tools to enhance corporate infrastructure security.
    • Drive remediation of security vulnerabilities identified through assessments.
    • Stay current with emerging security threats and industry trends to continuously improve security measures.

    Technologies we use (not exhaustive):

    • Python, Django, React, RabbitMQ, Celery, MySQL, Redis, Memcached
    • AWS, GCP, Azure, Windows 365, Terraform, BuildKite
    • Splunk, Snowflake, Lacework, Okta, Jamf, Meraki, Wiz, Crowdstrike

    We’d love to hear from you if you have:

    • 4+ years of experience as a Corporate Security Engineer or in a related role
    • Proven impact in multiple Corpsec domains: BeyondCorp, Corporate Identity, Endpoint Security, Data Loss Prevention, Device Trust, SaaS Security, Zero Trust.
    • Strong software engineering skills in Python, Golang, or Java.
    • Proficiency in threat modeling and implementing preventative and detective controls.
    • Advanced knowledge of operating system internals (macOS, Windows, Linux)
    • Experience with cloud security and infrastructure hardening.
    • Experience with infrastructure-as-code tools such as Terraform
    • Automation-first approach for all work performed

    • Practical experience with large-scale identity management infrastructure and BeyondCorp/Zero Trust architectures.

    • Excellent problem-solving skills and ability to work independently.

    • Strong communication skills to explain complex security issues in understandable terms.

    Klaviyo