Klaviyo - Denver, CO

posted 4 months ago

Full-time - Mid Level
Denver, CO
Publishing Industries

About the position

At Klaviyo, we are seeking an Application Security Engineering Manager to lead our Security Operations AppSec team. This role is pivotal as we expand our function to support the deployment of secure applications across our software ecosystem. The Application Security Engineering Manager will work collaboratively with various teams within Klaviyo to develop secure software patterns and apply them to shared libraries. This will enable our development and platform teams to concentrate on product functionality while ensuring security is integrated into our processes. The technical responsibilities of the Security Operations Application Security Engineers include developing a secure code architecture and patterns that allow Klaviyo to perform transactions efficiently and securely on our platform. The manager will identify legacy patterns of data access and work towards consolidating functionality into centralized libraries, simplifying code maintenance and modifications to core activities. A strong understanding of core third-party solutions such as Django and React is essential, as is the ability to leverage new security features within our codebase as they are released. The role also involves hands-on implementation of architecture designs and library development within our codebase, as well as maximizing the use of existing tooling to ensure our teams fully benefit from our investments. In terms of managerial responsibilities, the Application Security Engineering Manager will create roadmaps for Application Security goals that align with reducing risk across the platform. Success will be measured using standards such as the OWASP top 10, Secure Code Best Practices, and CIS Benchmarks. The manager will mentor Application Security Engineers, focusing on personal, technical, and career growth, while ensuring a healthy work/life balance by managing individual workloads. Tracking team performance, providing continuous feedback, and conducting periodic employee reviews are also key aspects of this role. Additionally, the manager will identify the necessary tooling to execute efficiently and enable all developers to practice secure code best practices, utilizing both internally developed and commercial products.

Responsibilities

  • Lead the Security Operations AppSec team to support secure application deployment.
  • Develop secure code architecture and patterns for efficient transactions.
  • Identify and consolidate legacy data access patterns into centralized libraries.
  • Understand and leverage third-party solutions like Django and React for security features.
  • Collaborate with Security Operations team members on Detection and Response, Offensive Security, and Infrastructure hardening.
  • Implement architecture designs and library development within the codebase.
  • Maximize the use of existing tooling to enhance team efficiency.
  • Create roadmaps for Application Security goals to reduce platform risk.
  • Mentor Application Security Engineers in personal and technical growth.
  • Manage workloads to ensure a healthy work/life balance for team members.
  • Track team performance and provide continuous feedback and reviews.
  • Identify necessary tooling for secure code best practices.

Requirements

  • Prior leadership experience in a technical role.
  • 8+ years of experience developing secure code libraries, preferably in Python.
  • Experience with technologies such as Python, Django, Nginx, React.
  • Familiarity with MySQL, RabbitMQ, Redis.
  • Experience with Amazon Web Services (EC2, RDS, Aurora, etc.).
  • Knowledge of Terraform, Packer, Jenkins, and Kubernetes.

Benefits

  • Medical, dental, and vision coverage
  • Health savings accounts
  • Flexible spending accounts
  • 401(k)
  • Flexible paid time off
  • Company-paid holidays
  • Learning allowance
  • Access to professional coaching services
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service