SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Optimizely is seeking a Director of Security Engineering to own the company's security program end-to-end: strategy, engineering, operations, and incident response. This is a leadership role managing a senior security team across multiple functional areas, with accountability for security posture across a 1,600+ person organization operating in 12 global offices.
Key responsibilities include:
**Security Strategy & Operations**: Define security roadmaps, manage budgets, and communicate risk to executives. Own full-lifecycle detection and response including telemetry, automation, CI/CD detection-as-code, and metrics (MTTR, ATT&CK). Serve as Incident Commander, running tabletop exercises and postmortem improvements.
**AI Security Focus**: A major emphasis is driving AI security and internal AI governance—integrating LLMs/ML into SOC triage and anomaly detection, defending AI attack surfaces (agent activity, prompt injection, machine identities), hardening against AI-driven threats (phishing-resistant MFA, supply chain guardrails, help desk impersonation defenses), and implementing NIST/OWASP/ATLAS frameworks.
**Cross-functional Partnerships**: Work with infrastructure/cloud platform teams on hardened baselines, network and identity architecture, secrets management, and telemetry pipelines. Partner with compliance on control frameworks, audit evidence, and third-party risk. Collaborate with reliability engineering on incident tooling and postmortem discipline.
**Scaling Security**: Build platforms and self-service tooling so engineering teams see their own risk and fix it without waiting on security queues. Automate repeatable alert triage. Consolidate tooling and leverage managed detection services where cost-effective. Use AI to augment senior team capacity on judgment calls.
**People Leadership**: Hire, coach, and grow a senior security team. Run the security champions network. Develop a security awareness program addressing deepfake and AI-enabled social engineering. Own full employee lifecycle, budget planning, and performance management.
**Required Experience**: 10+ years leading security engineering or operations in cloud-native SaaS environments with people leadership experience. Hands-on depth in detection and response with ability to read queries and detection logic. Proven incident command on high-severity incidents including customer and regulatory notifications. Deep cloud security expertise (AWS/Azure, containers, IaC, CI/CD) plus strong IAM knowledge. Practical automation ability (Python, Go, or similar). Working understanding of AI/ML security. Demonstrated success with customer security reviews, audits, and executive briefings.