We are looking for an experienced and self-driven Compliance & Risk Analyst to join our global Compliance function. This is a high-impact IC3 role with broad scope, spanning information security certification, PCI DSS compliance, data privacy, and environmental, social, and governance (ESG) programmes.
The role is based in Germany and will serve as a key compliance resource for the Campaign product line (which holds its own ISO 27001 certification scope), while also contributing to and helping to manage Optimizely's global PCI DSS v4.0.1 programme. In addition, the successful candidate will oversee and drive Optimizely's companywide ESG programme — a growing area of strategic importance as customers, investors, and regulators increasingly expect demonstrable sustainability and responsible business commitments.
This is an individual contributor role at the IC3 level, meaning you will be expected to operate with a high degree of autonomy, bring deep subject matter expertise, and influence outcomes across product, engineering, legal, and commercial teams without direct line management authority. You will report to the Director of Compliance.
What success looks like
In the first 90 days you will have a clear picture of the Campaign ISO 27001 ISMS, PCI DSS programme status, and the current state of Optimizely's ESG commitments. You will have built strong working relationships with the Director, Compliance & Risk, Security Engineering, Legal, and relevant product teams, and will have identified the key priorities and gaps to address in your first year.
At the 12-month mark, the Campaign ISO 27001 certification will be maintained with clean audit outcomes, the PCI DSS programme will be operating with improved process and evidence quality, GDPR obligations are being managed proactively, and Optimizely will have a published ESG/Sustainability report with a clear roadmap for continuous improvement.