Director, Security Engineering
Date: Sep 1, 2026
Location: London, GB, WC2N 4JS
Company: Optimizely
Introduction
You own Optimizely's security program end to end: strategy, engineering, operations, and response. Attackers now use AI to write better phishing, find flaws faster, clone voices, and automate intrusion at a speed human-only teams can't match. Our own AI adoption adds internal risk: agents with credentials, models handling customer data, prompt injection, and shadow tooling. You'll get ahead of both — through automation, platform engineering, and partnership across the business, not through a bigger team.
This role leads end-to-end security strategy, governance, and operations—defining roadmaps, managing budgets, and communicating risk to executives while serving as a senior security advocate for sales, customer audits, and incident communications. You will own full-lifecycle detection and response (telemetry, automation, CI/CD detection-as-code, and MTTR/ATT&CK metrics) and serve as Incident Commander, running regular tabletop/purple-team exercises and postmortem improvements. A major focus is driving AI security and internal AI governance: integrating LLMs/ML into SOC triage and anomaly detection, defending AI attack surfaces (agent activity, prompt injection, machine identities), hardening against AI-driven threats (phishing-resistant MFA, supply chain/developer guardrails, help desk impersonation defenses), and implementing NIST/OWASP/ATLAS risk frameworks. Additionally, you will oversee enterprise architecture, secure-by-default software lifecycles, and risk-based vulnerability management.
Job Responsibilities
How you'll work across Optimizely
You'll have little authority outside your own team and a lot of accountability across the company. Influence and genuine partnership are how the work gets done.
- Infrastructure and Cloud Platform. Co-own hardened baselines, network and identity architecture, secrets management, and telemetry pipelines. Land controls as platform capabilities, not tickets.
- Compliance and Risk. Partner on the control framework, audit evidence, third-party risk, and enterprise risk reporting so one set of controls serves both real security and assurance obligations.
- Reliability Engineering. Share incident tooling, on-call practice, severity language, and postmortem discipline. Security and availability incidents should feel like one muscle, not two.
Scaling security to be a given
A core expectation of the role, not a stretch goal. We'll ask you in interview how you've done it before.
- Automate the repeatable. Any alert triaged the same way twice is an automation candidate.
- Build platforms, not tickets. Self-service tooling and guardrails so engineering teams see their own risk and fix it without waiting on your queue.
- Consolidate and buy the boring parts. Fewer, better-integrated tools with real API coverage. Managed detection and specialist partners where they're genuinely cheaper and faster than hiring.
- Use AI as leverage. Triage, evidence collection, documentation, customer questionnaires, and code and configuration review — so senior people spend their time on judgment calls.
People, process, and technology
- People. A security awareness program that changes behavior, including deepfake and AI-enabled social engineering. Hire, coach, and grow a senior team, and run the security champions network.
- Process. Policy, standards, risk management, incident response, vulnerability management, change management, and third-party risk — lightweight, current, and genuinely followed.
- Technology. Security architecture and toolchain across cloud, identity, endpoint, data, application, and AI. Prefer engineered controls over policy statements wherever one is possible.
Leadership
- Lead a security team across multiple functional areas, including policies, processes, vision, and strategies that increase the group's efficiency, productivity, and impact.
- Manage experienced individual contributors and, where applicable, other managers. Own the full employee life cycle, and partner with FP&A on budget and your HR Business Partner on performance and compensation.
Knowledge and Experience
- Significant experience (atleast 10+ years) leading security engineering or operations in a cloud-native SaaS environment, including time as a people leader.
- Hands-on depth in detection and response. You've built or substantially rebuilt the capability, and you can still read a detection and a query.
- Proven incident command on high-severity incidents, including customer and regulatory notification decisions.
- Deep cloud security across AWS or Azure, containers, infrastructure as code, and CI/CD, plus strong identity and access management expertise.
- Practical automation ability — Python, Go, or similar — used to remove toil, and a track record of expanding coverage without proportional headcount growth.
- A working understanding of AI and machine learning security: how these systems fail, how they're attacked, and how attackers use them.
- Demonstrated success working with customers on security reviews, audits, escalations, and executive briefings.
- Strong collaboration and influence across Infrastructure, Compliance and Risk, and Reliability Engineering, shipping outcomes through teams you don't manage.
- Excellent written and verbal communication. You can brief an engineer, an executive, and an enterprise customer on the same incident and land it with all three.
- Nice to have: securing AI product features, OWASP Top 10 for LLM Applications, the NIST AI Risk Management Framework, MITRE ATLAS, SOC 2, or ISO 27001.
Education
-
Degree in a STEM field, preferably Information Security or Computer Engineering, or equivalent practical experience. Certifications such as CISSP, CCSP, GCIA, GCIH, GCFA, or AWS and Azure security certifications are welcome.
-
Displaying technical expertise. Driving continuous improvement. Driving projects to completion. Solving complex problems. Building collaborative relationships. Communicating with impact.
Optimizely is committed to a diverse and inclusive workplace. Optimizely is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.
#LI-JS1