> Markdown version of [/jobs/ext/637567-principal-engineer-security](https://www.wearedevelopers.com/jobs/ext/637567-principal-engineer-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Principal Engineer, Security - **Company:** Klaviyo - **Location:** Boston, MA, United States - **Experience:** Expert - **Salary:** $244,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Audit Trail, Software as a Service, Cloud Computing Security, Code Review, Cyber Security, Continuous Integration, Identity and Access Management, Key Management, Network Segmentation, Reliability Engineering, Zero Trust Network Access, Software Vulnerability Management, Klaviyo Email and SMS Marketing, Istio, Software Security, Mttr, Build Tools, Machine Learning Operations - **Published:** June 25, 2026 - **Apply:** https://www.welcometothejungle.com/en/companies/klaviyo/jobs/principal-engineer-security_boston_g764hvw7 ## About the Role * Experience with zero-trust architecture and progressive access control in a large multi-tenant SaaS environment. * Deep familiarity with enterprise compliance frameworks (SOC 2, ISO 27001, GDPR) and the infrastructure controls that underpin them. * Track record of embedding security tooling into CI/CD and IaC pipelines adopted org-wide. * Experience securing AI/ML systems: model access controls, data privacy guardrails, and agentic system security boundaries. ## Description Klaviyo's platform sends billions of messages and processes petabytes of customer data for hundreds of thousands of businesses. As we scale up-market and embed AI/agentic systems throughout our product and platform, security must be built into the foundation, not bolted on. The Principal Engineer, Security is a hands-on IC who owns Klaviyo's infrastructure security architecture: IAM, secrets management, network defenses, vulnerability management, security tooling, and the compliance controls that underpin our enterprise and regulatory obligations. This is an individual-contributor role, no direct reports. You lead through technical depth, code, and design quality, partnering closely with the Core Infrastructure PE, SRE, and AppSec teams to make "secure by default" a reality for every engineering team at Klaviyo. What You'll Do * Define and own Klaviyo's infrastructure security architecture: IAM frameworks, service-to-service auth, secrets management, network segmentation, and production access controls, designed to scale with our multi-tenant, multi-region footprint. * Build and maintain security guardrails as IaC modules; codify controls into golden paths that teams inherit automatically so security improves with velocity, not against it. * Own the vulnerability management program: SLO-backed triage and remediation, trend tracking, and systemic fixes, turn recurring vulnerability classes into solved engineering problems. * Define the security SLO and compliance framework for production infrastructure; run readiness reviews, communicate posture clearly to engineering and exec stakeholders. * Author security ADRs and RFCs; partner with the Core Infrastructure PE to embed security controls in CI/CD pipelines, paved roads, and the observability stack. * Lead threat modeling and security design reviews for high-risk architectural changes, accelerate delivery by making reviews lightweight and high-signal. * Partner with SRE, AppSec, and FinOps on cross-cutting initiatives: zero-trust progress, GDPR/compliance guardrails, and audit readiness for SOC 2/ISO 27001. * Write high-impact code, automation, and tooling; mentor Staff and Senior security engineers across teams through design pairing, code review, and example. * Transform workflows by putting AI at the center, building smarter systems and ways of working from the ground up. Who You Are * Experience: 10+ years in infrastructure or platform security engineering, with a track record of shipping security improvements that measurably reduced risk or improved compliance posture at scale. * Technical depth: Deep in cloud infrastructure security (AWS/GCP IAM, service mesh mTLS, secrets management, network defenses); you architect and ship production controls, not just audit them. * SLO and compliance rigor: You define security SLOs, track MTTR for vulnerabilities, and communicate risk posture clearly; you translate security work into business language that non-security stakeholders act on. * Developer-centric mindset: You build tools and guardrails that other engineers adopt because they make their work easier-not because they're required to. * Cross-org influence: You align teams through threat models, security reviews, and IaC guardrails; you earn credibility via code, design quality, and clear reasoning, not title. * Operational excellence: You've been on-call for security incidents. You write runbooks, lead readiness reviews, and treat recurring vulnerabilities as systemic engineering problems. * Communication: You write crisp ADRs and RFCs, run effective security design reviews, and translate risk exposure into decisions business stakeholders can act on. * AI tools and automation: You've brought AI into security engineering, automated threat detection, intelligent vulnerability triage, AI-assisted compliance checks, or security copilots-with explicit guardrails and audit trails. * You've already experimented with AI in work or personal projects, and you're excited to dive in and learn fast. You're hungry to responsibly explore new AI tools and workflows, finding ways to make your work smarter and more efficient. ## Related Videos - [Modern Data Architectures need Software Engineering](https://www.wearedevelopers.com/videos/1030-modern-data-architectures-need-software-engineering) - [What Developers Get Wrong About Application Quality](https://www.wearedevelopers.com/videos/233-what-developers-get-wrong-about-application-quality) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [Real-World Security for Busy Developers](https://www.wearedevelopers.com/videos/1545-real-world-security-for-busy-developers) - [Get started with securing your cloud-native Java microservices applications](https://www.wearedevelopers.com/videos/123-get-started-with-securing-your-cloud-native-java-microservices-applications) - [Automated Security for the Entire SDLC](https://www.wearedevelopers.com/videos/100323-automated-security-for-the-entire-sdlc) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 120 - Apple and peers](https://www.wearedevelopers.com/magazine/455-dev-digest-120-apple-and-peers) - [Navigating the AI Shift](https://www.wearedevelopers.com/magazine/629-navigating-the-ai-shift) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [What is Software Engineering in the Age of AI?](https://www.wearedevelopers.com/magazine/640-what-is-software-engineering-in-the-age-of-ai) - [Dev Digest 164: AI Agents, AI Blindspots and MCP security problems](https://www.wearedevelopers.com/magazine/578-dev-digest-164-ai-agents-ai-blindspots-and-mcp-security-problems)