SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Optimizely, a leading marketing technology platform serving 10,000+ brands including H&M, PayPal, and Zoom, is seeking an experienced Senior Compliance and Risk Analyst to join its global Compliance function in Berlin. This is a high-impact individual contributor role (IC3 level) with broad scope spanning information security certification, PCI DSS compliance, data privacy, and ESG programmes.
The role operates with significant autonomy and subject matter expertise, influencing outcomes across product, engineering, legal, and commercial teams without direct line management authority. You will report to the Director of Compliance.
Key responsibilities include:
Campaign ISO 27001 (15%): Support and co-maintain the ISO 27001 Information Security Management System for the Campaign product line, including scope definition, risk treatment, and Statement of Applicability. Collaborate with product, engineering, and infrastructure teams to maintain effective controls. Prepare and manage annual surveillance and recertification audits, conduct internal audits and management reviews, and maintain the risk register.
PCI DSS v4.0.1 (25%): Support Optimizely's global PCI DSS v4.0.1 compliance programme alongside security and product teams. Maintain accurate Cardholder Data Environment scope documentation, coordinate annual AOC/SAQ-D processes, manage the Qualified Security Assessor relationship, and drive remediation of findings.
ESG Programme (50%): Define and execute Optimizely's companywide ESG strategy, roadmap, and reporting framework. Develop ESG disclosure frameworks, coordinate data collection across Finance, HR, Facilities, Legal, and Product teams, and prepare annual ESG reports. Respond to customer ESG questionnaires and rating agency requests (EcoVadis, CDP, MSCI). Build and maintain ESG roadmap, engage executive stakeholders, and monitor regulatory developments.
GDPR and Data Privacy (10%): Support global data privacy compliance with GDPR, CCPA, and other privacy laws. Assist with DPIAs, vendor privacy assessments, and DPA workflows.
Success metrics include establishing clear compliance status within 90 days, maintaining Campaign ISO 27001 certification with clean audits, improving PCI DSS process quality, and publishing a comprehensive ESG/Sustainability report with a continuous improvement roadmap within 12 months.