{"id":1605676,"url":"https://alion.io/job/optimizely-director-security-engineering","title":"Director, Security Engineering","company":{"id":39533,"name":"Optimizely","domain":"optimizely.com","url":"https://alion.io/company/optimizely","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"SuccessFactors","truth_index":null},"role":"Leadership","role_family":"Leadership","seniority":"head","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["London, United Kingdom"],"countries":["GB"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":130000,"max_usd":256000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":35},"experience_years_min":10,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Anomaly Detection","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"CI/CD","optional":false},{"name":"Commander.js","optional":false},{"name":"Go","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Machine Learning","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"OWASP","optional":false},{"name":"Platform Engineering","optional":false},{"name":"Python","optional":false},{"name":"ISO 27001","optional":true},{"name":"JavaScript","optional":true},{"name":"LLM","optional":true},{"name":"NIST AI RMF","optional":true},{"name":"Node JS","optional":true},{"name":"OWASP Top 10","optional":true},{"name":"SOC 2","optional":true}],"status":"live","first_seen_at":"2026-09-30T02:00:00Z","employer_posted_date":"2026-09-30","last_verified_at":"2026-10-01T19:50:31Z","board_verified":true,"closed_at":null,"days_open":2,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":2},"description":"We're not here to add to the noise. We're here to cut through it- with AI that actually works for marketers.\nFrom AI-powered content creation to world-class CMS and the industry's most trusted experimentation platform, Optimizely is the tool modern marketers actually want to use. AI-Ready. Set. Go.\n10,000+ brands including H&M, PayPal, and Zoom already get it. So do Gartner, Forrester, and IDC, who consistently recognize us as leaders in MarTech.\nBut here's the thing about building great products: it takes great people. Our 1,600+ Optimizers across 12 global offices are curious, collaborative, and refreshingly human. We don't do corporate speak. We do real conversations, big ideas, and genuinely care for the work we make together.\nIf you want to be part of a team that's shaping the future of marketing technology - and actually enjoys doing it - you're in the right place.\nFind us on Instagram: @optimizely\nIntroduction\nYou own Optimizely's security program end to end: strategy, engineering, operations, and response. Attackers now use AI to write better phishing, find flaws faster, clone voices, and automate intrusion at a speed human-only teams can't match. Our own AI adoption adds internal risk: agents with credentials, models handling customer data, prompt injection, and shadow tooling. You'll get ahead of both - through automation, platform engineering, and partnership across the business, not through a bigger team.\nThis role leads end-to-end security strategy, governance, and operations-defining roadmaps, managing budgets, and communicating risk to executives while serving as a senior security advocate for sales, customer audits, and incident communications. You will own full-lifecycle detection and response (telemetry, automation, CI/CD detection-as-code, and MTTR/ATT&CK metrics) and serve as Incident Commander, running regular tabletop/purple-team exercises and postmortem improvements. A major focus is driving AI security and internal AI governance: integrating LLMs/ML into SOC triage and anomaly detection, defending AI attack surfaces (agent activity, prompt injection, machine identities), hardening against AI-driven threats (phishing-resistant MFA, supply chain/developer guardrails, help desk impersonation defenses), and implementing NIST/OWASP/ATLAS risk frameworks. Additionally, you will oversee enterprise architecture, secure-by-default software lifecycles, and risk-based vulnerability management.\nJob Responsibilities\nHow you'll work across Optimizely\nYou'll have little authority outside your own team and a lot of accountability across the company. Influence and genuine partnership are how the work gets done.\nInfrastructure and Cloud Platform. Co-own hardened baselines, network and identity architecture, secrets management, and telemetry pipelines. Land controls as platform capabilities, not tickets. \nCompliance and Risk. Partner on the control framework, audit evidence, third-party risk, and enterprise risk reporting so one set of controls serves both real security and assurance obligations. \nReliability Engineering. Share incident tooling, on-call practice, severity language, and postmortem discipline. Security and availability incidents should feel like one muscle, not two. \nScaling security to be a given\nA core expectation of the role, not a stretch goal. We'll ask you in interview how you've done it before.\nAutomate the repeatable. Any alert triaged the same way twice is an automation candidate. \nBuild platforms, not tickets. Self-service tooling and guardrails so engineering teams see their own risk and fix it without waiting on your queue. \nConsolidate and buy the boring parts. Fewer, better-integrated tools with real API coverage. Managed detection and specialist partners where they're genuinely cheaper and faster than hiring. \nUse AI as leverage. Triage, evidence collection, documentation, customer questionnaires, and code and configuration review - so senior people spend their time on judgment calls. \nPeople, process, and technology\nPeople. A security awareness program that changes behavior, including deepfake and AI-enabled social engineering. Hire, coach, and grow a senior team, and run the security champions network. \nProcess. Policy, standards, risk management, incident response, vulnerability management, change management, and third-party risk - lightweight, current, and genuinely followed. \nTechnology. Security architecture and toolchain across cloud, identity, endpoint, data, application, and AI. Prefer engineered controls over policy statements wherever one is possible. \nLeadership\nLead a security team across multiple functional areas, including policies, processes, vision, and strategies that increase the group's efficiency, productivity, and impact. \nManage experienced individual contributors and, where applicable, other managers. Own the full employee life cycle, and partner with FP&A on budget and your HR Business Partner on performance and compensation. \nKnowledge and Experience\nSignificant experience (atleast 10+ years) leading security engineering or operations in a cloud-native SaaS environment, including time as a people leader. \nHands-on depth in detection and response. You've built or substantially rebuilt the capability, and you can still read a detection and a query. \nProven incident command on high-severity incidents, including customer and regulatory notification decisions. \nDeep cloud security across AWS or Azure, containers, infrastructure as code, and CI/CD, plus strong identity and access management expertise. \nPractical automation ability - Python, Go, or similar - used to remove toil, and a track record of expanding coverage without proportional headcount growth. \nA working understanding of AI and machine learning security: how these systems fail, how they're attacked, and how attackers use them. \nDemonstrated success working with customers on security reviews, audits, escalations, and executive briefings. \nStrong collaboration and influence across Infrastructure, Compliance and Risk, and Reliability Engineering, shipping outcomes through teams you don't manage. \nExcellent written and verbal communication. You can brief an engineer, an executive, and an enterprise customer on the same incident and land it with all three. \nNice to have: securing AI product features, OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, MITRE ATLAS, SOC 2, or ISO 27001. \nEducation\nDegree in a STEM field, preferably Information Security or Computer Engineering, or equivalent practical experience. Certifications such as CISSP, CCSP, GCIA, GCIH, GCFA, or AWS and Azure security certifications are welcome.\n\nDisplaying technical expertise. Driving continuous improvement. Driving projects to completion. Solving complex problems. Building collaborative relationships. Communicating with impact.\n\nOptimizely is committed to a diverse and inclusive workplace. Optimizely is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.\n#LI-JS1","description_format":"text","description_chars":7166,"description_truncated":false,"requirements":{"experience_years_min":10,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Artificial Intelligence","Commerce","Marketing Automation","Digital Marketing"],"lifecycle":[{"event":"open","at":"2026-10-01T19:50:31Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":2,"expected_fill_days":27,"reasons":["conf:7","win:early"],"computed_at":"2026-10-02T02:57:41Z"},"pay":null,"html_url":"https://alion.io/job/optimizely-director-security-engineering","json_url":"https://alion.io/job/optimizely-director-security-engineering.json","meta":{"generated_at":"2026-10-02T02:57:41Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":4015,"day_limit":5000,"remaining_today":985,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}