More jobs:
Director, Security Engineering
Job in
London, Greater London, W1B, England, UK
Listed on 2026-09-04
Listing for:
Optimizely
Full Time
position Listed on 2026-09-04
Job specializations:
-
IT/Tech
Cybersecurity
Job Description & How to Apply Below
From AI-powered content creation to world-class CMS and the industry's most trusted experimentation platform, Optimizely is the tool modern marketers actually want to use. AI-Ready. Set. Go.10,000+ brands including H&M, Pay Pal, and Zoom already get it. So do Gartner, Forrester, and IDC, who consistently recognize us as leaders in Mar Tech.
But here's the thing about building great products: it takes great people. Our 1,600+ Optimizers across 12 global offices are curious, collaborative, and refreshingly human. We don't do corporate speak. We do real conversations, big ideas, and genuinely care for the work we make together.
If you want to be part of a team that's shaping the future of marketing technology — and actually enjoys doing it — you're in the right place.
Find us on Instagram: @optimizely
Introduction You own Optimizely's security program end to end: strategy, engineering, operations, and response. Attackers now use AI to write better phishing, find flaws faster, clone voices, and automate intrusion at a speed human-only teams can't match. Our own AI adoption adds internal risk: agents with credentials, models handling customer data, prompt injection, and shadow tooling. You'll get ahead of both — through automation, platform engineering, and partnership across the business, not through a bigger team.
This role leads end-to-end security strategy, governance, and operations—defining roadmaps, managing budgets, and communicating risk to executives while serving as a senior security advocate for sales, customer audits, and incident communications. You will own full-lifecycle detection and response (telemetry, automation, CI/CD detection-as-code, and MTTR/ATT&CK metrics) and serve as Incident Commander, running regular tabletop/purple-team exercises and postmortem improvements. A major focus is driving AI security and internal AI governance: integrating LLMs/ML into SOC triage and anomaly detection, defending AI attack surfaces (agent activity, prompt injection, machine identities), hardening against AI-driven threats (phishing-resistant MFA, supply chain/developer guardrails, help desk impersonation defenses), and implementing NIST/OWASP/ATLAS risk frameworks.
Additionally, you will oversee enterprise architecture, secure-by-default software life cycles, and risk-based vulnerability management.
Job Responsibilities How you'll work across Optimizely You'll have little authority outside your own team and a lot of accountability across the company. Influence and genuine partnership are how the work gets done. Infrastructure and Cloud Platform. Co-own hardened baselines, network and identity architecture, secrets management, and telemetry pipelines. Land controls as platform capabilities, not tickets. Compliance and Risk. Partner on the control framework, audit evidence, third-party risk, and enterprise risk reporting so one set of controls serves both real security and assurance obligations.
Reliability Engineering. Share incident tooling, on-call practice, severity language, and postmortem discipline. Security and availability incidents should feel like one muscle, not two. Scaling security to be a givenA core expectation of the role, not a stretch goal. We'll ask you in interview how you've done it before. Automate the repeatable. Any alert triaged the same way twice is an automation candidate.
Build platforms, not tickets. Self-service tooling and guardrails so engineering teams see their own risk and fix it without waiting on your queue. Consolidate and buy the boring parts. Fewer, better-integrated tools with real API coverage. Managed detection and specialist partners where they're genuinely cheaper and faster than hiring. Use AI as leverage. Triage, evidence collection, documentation, customer questionnaires, and code and configuration review — so senior people spend their time on judgment calls.
People, process, and technology
People. A security awareness program that changes behavior, including deepfake and AI-enabled social engineering. Hire, coach, and grow a senior team,…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×