Get more replies from employers
Send a job-specific resume in minutes.
Optimizely is seeking an experienced security leader to own the end-to-end security program, including strategy, governance, operations, and incident communications. You will manage budgets, roadmaps, and executive risk discussions while championing AI security and enterprise-wide protections.
The role requires deep cloud security expertise, incident command experience, and the ability to collaborate across Infrastructure, Compliance & Risk, and Reliability teams.
Select how often (in days) to receive an alert: Create Alert
We're not here to add to the noise. We're here to cut through it- with AI that actually works for marketers.
From AI-powered content creation to world-class CMS and the industry's most trusted experimentation platform, Optimizely is the tool modern marketers actually want to use. AI-Ready. Set. Go.
10,000+ brands including H&M, PayPal, and Zoom already get it. So do Gartner, Forrester, and IDC, who consistently recognize us as leaders in MarTech.
But here's the thing about building great products: it takes great people. Our 1,600+ Optimizers across 12 global offices are curious, collaborative, and refreshingly human. We don't do corporate speak. We do real conversations, big ideas, and genuinely care for the work we make together.
If you want to be part of a team that's shaping the future of marketing technology — and actually enjoys doing it — you're in the right place.
Find us on Instagram: @optimizely
You own Optimizely's security program end to end: strategy, engineering, operations, and response. Attackers now use AI to write better phishing, find flaws faster, clone voices, and automate intrusion at a speed human-only teams can't match. Our own AI adoption adds internal risk: agents with credentials, models handling customer data, prompt injection, and shadow tooling. You'll get ahead of both — through automation, platform engineering, and partnership across the business, not through a bigger team.
This role leads end-to-end security strategy, governance, and operations—defining roadmaps, managing budgets, and communicating risk to executives while serving as a senior security advocate for sales, customer audits, and incident communications. You will own full-lifecycle detection and response (telemetry, automation, CI/CD detection-as-code, and MTTR/ATT&CK metrics) and serve as Incident Commander, running regular tabletop/purple-team exercises and postmortem improvements. A major focus is driving AI security and internal AI governance: integrating LLMs/ML into SOC triage and anomaly detection, defending AI attack surfaces (agent activity, prompt injection, machine identities), hardening against AI-driven threats (phishing-resistant MFA, supply chain/developer guardrails, help desk impersonation defenses), and implementing NIST/OWASP/ATLAS risk frameworks. Additionally, you will oversee enterprise architecture, secure-by-default software lifecycles, and risk-based vulnerability management.
How you'll work across Optimizely
You'll have little authority outside your own team and a lot of accountability across the company. Influence and genuine partnership are how the work gets done.
Scaling security to be a given
A core expectation of the role, not a stretch goal. We'll ask you in interview how you've done it before.
People, process, and technology
Leadership
Degree in a STEM field, preferably Information Security or Computer Engineering, or equivalent practical experience. Certifications such as CISSP, CCSP, GCIA, GCIH, GCFA, or AWS and Azure security certifications are welcome.
Displaying technical expertise. Driving continuous improvement. Driving projects to completion. Solving complex problems. Building collaborative relationships. Communicating with impact.
Optimizely is committed to a diverse and inclusive workplace. Optimizely is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.