Director, Security Engineering

Optimizely

City of Westminster

On-site

GBP 110,000 - 160,000

Full time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Optimizely is seeking a senior security leader to own end-to-end security programs for a cloud-native SaaS platform. You will define strategy, governance, and response, coordinating with engineering, compliance, and sales to guard customer data and regulatory readiness.

You will drive AI security integration, incident command, tabletop exercises, and risk management using NIST/OWASP frameworks, while mentoring a global security team.

Qualifications

  • Significant experience (at least 10+ years) leading security engineering or operations in a cloud-native SaaS environment.
  • Hands-on depth in detection and response; can read a detection and a query.
  • Proven incident command on high-severity incidents with customer/regulatory notification.
  • Deep cloud security across AWS/Azure, containers, IaC, CI/CD, and IAM.
  • Practical automation ability — Python, Go, or similar.
  • Working knowledge of AI/ML security and how systems fail or are attacked.
  • Experience with security reviews, audits, escalations, and executive briefings.
  • Strong collaboration and influence across infrastructure, risk/compliance, and reliability teams.
  • Nice to have: OWASP Top 10 for LLM, NIST AI RMF, MITRE ATLAS, SOC 2, ISO 27001.

Responsibilities

  • Infrastructure and Cloud Platform: Co-own hardened baselines, network/identity, secrets mgmt, telemetry pipelines.
  • Compliance and Risk: Partner on control framework, audit evidence, 3rd-party risk, and risk reporting.
  • Reliability Engineering: Share incident tooling, on-call practice, severity language, and postmortem discipline.

Skills

Security leadership
Detection & response
Incident command
Cloud security
Automation (Python/Go)
AI/ML security
Customer audits
Cross-functional collaboration
Executive communication
Security architecture

Education

STEM degree in Information Security or Computer Engineering
CISSP/CCSP or similar certifications welcome

Job description

Select how often (in days) to receive an alert: Create Alert

We're not here to add to the noise. We're here to cut through it- with AI that actually works for marketers.

From AI-powered content creation to world-class CMS and the industry's most trusted experimentation platform, Optimizely is the tool modern marketers actually want to use. AI-Ready. Set. Go.

10,000+ brands including H&M, PayPal, and Zoom already get it. So do Gartner, Forrester, and IDC, who consistently recognize us as leaders in MarTech.

But here's the thing about building great products: it takes great people. Our 1,600+ Optimizers across 12 global offices are curious, collaborative, and refreshingly human. We don't do corporate speak. We do real conversations, big ideas, and genuinely care for the work we make together.

If you want to be part of a team that's shaping the future of marketing technology — and actually enjoys doing it — you're in the right place.

Find us on Instagram: @optimizely

Introduction

You own Optimizely's security program end to end: strategy, engineering, operations, and response. Attackers now use AI to write better phishing, find flaws faster, clone voices, and automate intrusion at a speed human-only teams can't match. Our own AI adoption adds internal risk: agents with credentials, models handling customer data, prompt injection, and shadow tooling. You'll get ahead of both — through automation, platform engineering, and partnership across the business, not through a bigger team.

This role leads end-to-end security strategy, governance, and operations—defining roadmaps, managing budgets, and communicating risk to executives while serving as a senior security advocate for sales, customer audits, and incident communications. You will own full-lifecycle detection and response (telemetry, automation, CI/CD detection-as-code, and MTTR/ATT&CK metrics) and serve as Incident Commander, running regular tabletop/purple-team exercises and postmortem improvements. A major focus is driving AI security and internal AI governance: integrating LLMs/ML into SOC triage and anomaly detection, defending AI attack surfaces (agent activity, prompt injection, machine identities), hardening against AI-driven threats (phishing-resistant MFA, supply chain/developer guardrails, help desk impersonation defenses), and implementing NIST/OWASP/ATLAS risk frameworks. Additionally, you will oversee enterprise architecture, secure-by-default software lifecycles, and risk-based vulnerability management.

Job Responsibilities

How you'll work across Optimizely

You'll have little authority outside your own team and a lot of accountability across the company. Influence and genuine partnership are how the work gets done.

  • Infrastructure and Cloud Platform. Co-own hardened baselines, network and identity architecture, secrets management, and telemetry pipelines. Land controls as platform capabilities, not tickets.
  • Compliance and Risk. Partner on the control framework, audit evidence, third-party risk, and enterprise risk reporting so one set of controls serves both real security and assurance obligations.
  • Reliability Engineering. Share incident tooling, on-call practice, severity language, and postmortem discipline. Security and availability incidents should feel like one muscle, not two.

Scaling security to be a given

A core expectation of the role, not a stretch goal. We'll ask you in interview how you've done it before.

  • Automate the repeatable. Any alert triaged the same way twice is an automation candidate.
  • Build platforms, not tickets. Self-service tooling and guardrails so engineering teams see their own risk and fix it without waiting on your queue.
  • Consolidate and buy the boring parts. Fewer, better-integrated tools with real API coverage. Managed detection and specialist partners where they're genuinely cheaper and faster than hiring.
  • Use AI as leverage. Triage, evidence collection, documentation, customer questionnaires, and code and configuration review — so senior people spend their time on judgment calls.

People, process, and technology

  • People. A security awareness program that changes behavior, including deepfake and AI-enabled social engineering. Hire, coach, and grow a senior team, and run the security champions network.
  • Process. Policy, standards, risk management, incident response, vulnerability management, change management, and third-party risk — lightweight, current, and genuinely followed.
  • Technology. Security architecture and toolchain across cloud, identity, endpoint, data, application, and AI. Prefer engineered controls over policy statements wherever one is possible.

Leadership

  • Lead a security team across multiple functional areas, including policies, processes, vision, and strategies that increase the group's efficiency, productivity, and impact.
  • Manage experienced individual contributors and, where applicable, other managers. Own the full employee life cycle, and partner with FP&A on budget and your HR Business Partner on performance and compensation.
Knowledge and Experience
  • Significant experience (atleast10+ years)leading security engineering or operations in a cloud-native SaaS environment, including time as a people leader.
  • Hands‑on depth in detection and response. You’ve built or substantially rebuilt the capability, and you can still read a detection and a query.
  • Proven incident command on high‑severity incidents, including customer and regulatory notification decisions.
  • Deep cloud security across AWS or Azure, containers, infrastructure as code, and CI/CD, plus strong identity and access management expertise.
  • Practical automation ability — Python, Go, or similar — used to remove toil, and a track record of expanding coverage without proportional headcount growth.
  • A working understanding of AI and machine learning security: how these systems fail, how they're attacked, and how attackers use them.
  • Demonstrated success working with customers on security reviews, audits, escalations, and executive briefings.
  • Strong collaboration and influence across Infrastructure, Compliance and Risk, and Reliability Engineering, shipping outcomes through teams you don't manage.
  • Excellent written and verbal communication. You can brief an engineer, an executive, and an enterprise customer on the same incident and land it with all three.
  • Nice to have: securing AI product features, OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, MITRE ATLAS, SOC 2, or ISO 27001.
Education

Degree in a STEM field, preferably Information Security or Computer Engineering, or equivalent practical experience. Certifications such as CISSP, CCSP, GCIA, GCIH, GCFA, or AWS and Azure security certifications are welcome.

Displaying technical expertise. Driving continuous improvement. Driving projects to completion. Solving complex problems. Building collaborative relationships. Communicating with impact.

Optimizely is committed to a diverse and inclusive workplace. Optimizely is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Security Engineering
Director, Security Engineering

Optimizely • Greater London

On-site
GBP 150,000 - 210,000
Director, AI Security & Cloud Engineering
Director, AI Security & Cloud Engineering

Optimizely • Greater London

Hybrid
GBP 150,000 - 210,000
Director of AI Security & Cloud Defense
Director of AI Security & Cloud Defense

Optimizely • City of Westminster

On-site
GBP 110,000 - 160,000
Lead Security Operations Engineer
Lead Security Operations Engineer

Jobtailor • Greater London

On-site
GBP 120,000 - 170,000
Marketing Analytics Lead
Marketing Analytics Lead

Optimizely • Greater London

On-site
GBP 70,000 - 110,000
Artificial Intelligence (AI) Offensive Security Analyst
Artificial Intelligence (AI) Offensive Security Analyst

Citigroup Inc. • Greater London

Hybrid
GBP 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Intropic • City Of London

On-site
GBP 90,000 - 140,000
Senior Software Engineer
Senior Software Engineer

United States Digital Space LLC • United Kingdom

Remote
GBP 85,000 - 120,000
Security Engineer, Detection and Response
Security Engineer, Detection and Response

Jobtailor • Greater London

On-site
GBP 90,000 - 130,000
Hands-On Cyber Security Engineer: Build, Automate, Protect
Hands-On Cyber Security Engineer: Build, Automate, Protect

Interact Software • Manchester

On-site
GBP 65,000 - 90,000