Lead Security Risk Analyst
22 hours ago
We’re seeking a highly motivated Lead Security Risk Partner who will help us continue to evolve our Risk function by using engineering principles and data-driven strategies to precisely identify, understand, communicate, and prioritize mitigation of risk. This role will start out primarily focused on a subset of our Risk programs: internal security risk management (risk discovery, assessment, and governance) and security metrics (analysis, curation, reporting)
You’ll partner closely with Engineering, IT, Security, Leadership, and basically every other team at Klaviyo to create a holistic view of risk based on high quality data about our assets, weaknesses, threats, and safeguards (controls). You’ll help your fellow Klaviyos identify, understand, prioritize, and manage risks that they own. You will help evolve our risk management practices to be transparent and centered around evidence-based risk models. Through all of this, you’ll help Klaviyo scale securely and sustainably deliver value for our customers.
What you’ll be doing
- Lead and execute new Risk program maturity projects that introduce more rigorous, streamlined, and automated approaches to risk management
- Partner with other departments and teams to drive mutual understanding of security risks they own and how to prioritize managing those risks in support of Klaviyo’s goals
- Create, tune, and operationalize business relevant security metrics (KPIs, KRIs, KCIs) that demonstrably improve security outcomes across Klaviyo
- Review new products, product features, and internal business projects to guide teams toward secure paths forward and away from accruing new security debt
- Collaboratively define and enable teams about security policies and standards that clearly establish Klaviyo’s risk tolerance bar
- Experience doing security risk assessments, co-creating risk treatment strategies, and influencing risk treatment prioritization across diverse business units (Engineering, IT, Finance, Legal, etc.)
- Thorough understanding of cloud-native web application architectures, security threats, and security best practices, especially in the context of AWS and Kubernetes
- Experience using data visualization tools and SQL to build and operationalize security metrics (e.g. Apache Superset, Tableau, Domo, Amazon QuickSight)
- Experience with scalable approaches to threat modeling, secure design reviews, and risk assessment methods that balance rigor and efficiency (e.g. Mozilla’s Rapid Risk Assessment)
- Experience with security automation and process streamlining, ideally in the context of security risk management
Everyone on our team must have:
- A strong bias toward evidence, logic, math, and reason when communicating risk (instead of fear, uncertainty, and doubt)
- A strong bias toward “guardrails, not gates” and “paved security roads” philosophies (instead of rigid “centralized command-and-control” thinking)
- Excellent ability to plan, prioritize, and deliver results cross-functionally and in a timely fashion
- Proficiency discussing complex, nuanced topics with technical & non-technical audiences alike, especially software engineering teams
- Strong alignment with Klaviyo’s core values
Bonus points if you have any of the following:
- Experience building tools with REST APIs and Python
- Experience with data engineering tools (e.g. dbt, Airflow, Airbyte) or data lake platforms (e.g. Snowflake, Databricks)
- Experience with cyber risk quantification (CRQ) tools and frameworks (e.g. FAIR, RiskLens, Safe Security, etc.)
-
Lead Risk Analyst
2 weeks ago
San Francisco, United States Earnest Full timeThe Lead Quant Risk Analyst will report to the Head of Risk.As the Lead Quant Risk Analyst, you will:Play a pivotal role in managing and optimizing our loss modeling and underwriting, ensuring frictionless risk optimization to support our strategic goalsDefine roadmap and strategy around risk modeling foundation, structure, and backbone of the modeling...
-
Lead Risk Analyst
2 weeks ago
San Francisco, United States Earnest Full timeThe Lead Quant Risk Analyst will report to the Head of Risk.As the Lead Quant Risk Analyst, you will:Play a pivotal role in managing and optimizing our loss modeling and underwriting, ensuring frictionless risk optimization to support our strategic goalsDefine roadmap and strategy around risk modeling foundation, structure, and backbone of the modeling...
-
Sr. Analyst Information Security
22 hours ago
San Francisco, CA, United States DBA Web Technologies Full timeSr. Analyst Information Security (CISSP, Risk Management, Network Security, encryption, communication protocols) in Waukegan, IL Position: Sr. Analyst Information Security Location: Waukegan, IL Duration: Full-Time Permanent position (no contracts, no corp to corp, no remote) Salary: Excellent Compensation with benefits SKILLS: Information Security...
-
Lead Quantitative Risk Analyst
4 weeks ago
San Francisco, United States Earnest Current Job Openings Full timeThe Lead Quant Risk Analyst will report to the Head of Risk. As the Lead Quant Risk Analyst, you will: Play a pivotal role in managing and optimizing our loss modeling and underwriting, ensuring frictionless risk optimization to support our strategic goals Define roadmap and strategy around risk modeling foundation, structure, and backbone of the modeling...
-
Lead Quantitative Risk Analyst
2 weeks ago
San Francisco, United States Earnest Full timeThe Lead Quant Risk Analyst will report to the Head of Risk.As the Lead Quant Risk Analyst, you will:Play a pivotal role in managing and optimizing our loss modeling and underwriting, ensuring frictionless risk optimization to support our strategic goalsDefine roadmap and strategy around risk modeling foundation, structure, and backbone of the modeling...
-
Analyst, Vendor Risk Management
2 days ago
San Francisco, CA, United States BlueVoyant Full timeAnalyst, Vendor Risk Management Location: Hybrid In Washington, DC Metro Area United States Citizenship Required The Position The Analyst, Vendor Risk Management will work with clients to identify client supply chain risk and cybersecurity challenges, advise on best practices in vendor risk management, and ensure successful delivery of BlueVoyant...
-
Lead Security Analyst
2 weeks ago
San Francisco, United States Optomi Full timeLead Security Analyst - Hybrid in Alexandria, VAOptomi, in partnership with a company in the IT Media and broadcasting space is looking to add a Lead Security Analyst to their growing team! The Lead Security Analyst will handle all escalated alerts from the MSSP and investigate events of interest and incidents as they are validated, prioritized, and...
-
Security Risk Analyst
1 week ago
San Diego, United States Booz Allen Hamilton Full timeJob Number: R0209827Cybersecurity Risk Analyst, MidThe Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this ‘cyber noise,‘ how can these organizations understand their risks and how to mitigate them? The answer is you. We need...
-
Risk Analyst
2 weeks ago
San Francisco, United States BlueVoyant Full timeROC Risk Analyst ILocation: Remote in UKResponsibilitiesProduce formatted reports for clients to help them understand cyber risk profiles of specific networks.Assist in discovery, analysis and tracking of advanced cyber threats.Identify and correlate adversary tactics, techniques, and procedures (TTPs) across a range of raw data sources from host to...
-
Risk Analyst
1 week ago
San Francisco, United States BlueVoyant Full timeROC Risk Analyst ILocation: Remote in UKResponsibilitiesProduce formatted reports for clients to help them understand cyber risk profiles of specific networks.Assist in discovery, analysis and tracking of advanced cyber threats.Identify and correlate adversary tactics, techniques, and procedures (TTPs) across a range of raw data sources from host to...
-
Senior Security Risk Analyst
2 days ago
Atlanta, GA, United States Equifax, Inc. Full timeAs a Senior Security Analyst, this role will be responsible for managing security risk programs and supporting risk and compliance initiatives. This role requires a motivated self-starter who has strong analytical and problem-solving skills, a strong understanding of risk and compliance management principles, excellent communication, and knowledge of...
-
Junior Business Risk Analyst
19 hours ago
San Francisco, United States BlueVoyant Full timeJr. Business Risk AnalystLocation: Hybrid in Washington, DC or Remote in the United StatesUS Citizenship RequiredThe PositionBVGS is a high growth technology company with a focus on protecting critical national security and commercial supply chains. We leverage diverse datasets and collection techniques to proactively illuminate supply chains and identify...
-
Senior Security Risk Analyst
2 days ago
Atlanta, GA, United States Equifax, Inc. Full timeAs a Senior Security Analyst, this role will be responsible for managing security risk programs and supporting risk and compliance initiatives. This role requires a motivated self-starter who has strong analytical and problem-solving skills, a strong understanding of risk and compliance management principles, excellent communication, and knowledge of...
-
Director, Security Risk
2 days ago
Cleveland, OH, United States Security Management Resources Full timeLocation: Remote; Cleveland, Ohio, USARelocation: Yes, within the United States SMR’s client is a privately held corporation with a prestigious portfolio of market-leading brands. An expansion of their security and risk management program has created a senior role that is perfect for an experienced leader. The position reports directly to the Chief...
-
Security Analyst
4 weeks ago
San Francisco, United States Abnormal Security Full timeJob DescriptionJob DescriptionAbout The RoleWe are looking for a Security Analyst to join our frontline cybersecurity defense team. As a Security Analyst, you will be responsible for identifying, catching, and preventing email fraud by efficiently handling a high volume of requests and applying policies. About YouDetail-oriented and passionate about...
-
Senior Security Risk Analyst
2 weeks ago
San Diego, United States Booz Allen Hamilton Full timeCybersecurity Risk Analyst, SeniorThe Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you. We need your knowledge as a...
-
Senior Security Risk Analyst
2 weeks ago
San Diego, United States Booz Allen Hamilton Full timeCybersecurity Risk Analyst, SeniorThe Opportunity:Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you. We need your knowledge as a...
-
Cybersecurity Risk Analyst, Senior
2 days ago
San Diego, CA, United States Booz Allen Hamilton Full timeCybersecurity Risk Analyst, Senior The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to government agencies. In all of this “cyber noise,” how can these organizations understand their risks and how to mitigate them? The answer is you. We need your knowledge as...
-
Cybersecurity Risk Analyst, Senior
22 hours ago
San Diego, CA, United States Booz Allen Hamilton Full timeYour growth matters to us - explore our career development opportunities. A PLACE WHERE YOU BELONG Bring your whole self to work in our culture of respect and inclusivity. SUPPORT YOUR WELLBEING Learn how we’ll support you as you pursue a balanced, fulfilling life. YOUR CANDIDATE JOURNEY Discover what to expect during your journey as a candidate with us....
-
Security Analyst
4 weeks ago
San Francisco, United States Abnormal Security Full timeJob DescriptionJob DescriptionAbout The RoleWe are looking for an Overnight Security Analyst to join our frontline cybersecurity defense team. As a Security Analyst, you will be responsible for identifying, catching, and preventing email fraud by efficiently handling a high volume of requests and applying policies.About YouDetail-oriented and passionate...