Senior Compliance and Risk Analyst (Berlin, DE, 10176)

Optimizely
Optimizely

IT, Compliance / Regulatory

Berlin, Germany

Posted on Sep 7, 2026
We're not here to add to the noise. We're here to cut through it- with AI that actually works for marketers.
From AI-powered content creation to world-class CMS and the industry's most trusted experimentation platform, Optimizely is the tool modern marketers actually want to use. AI-Ready. Set. Go.
10,000+ brands including H&M, PayPal, and Zoom already get it. So do Gartner, Forrester, and IDC, who consistently recognize us as leaders in MarTech.
But here's the thing about building great products: it takes great people. Our 1,600+ Optimizers across 12 global offices are curious, collaborative, and refreshingly human. We don't do corporate speak. We do real conversations, big ideas, and genuinely care for the work we make together.
If you want to be part of a team that's shaping the future of marketing technology — and actually enjoys doing it — you're in the right place.
Find us on Instagram: @optimizely

Introduction

We are looking for an experienced and self-driven Compliance & Risk Analyst to join our global Compliance function. This is a high-impact IC3 role with broad scope, spanning information security certification, PCI DSS compliance, data privacy, and environmental, social, and governance (ESG) programmes.

The role is based in Germany and will serve as a key compliance resource for the Campaign product line (which holds its own ISO 27001 certification scope), while also contributing to and helping to manage Optimizely's global PCI DSS v4.0.1 programme. In addition, the successful candidate will oversee and drive Optimizely's companywide ESG programme — a growing area of strategic importance as customers, investors, and regulators increasingly expect demonstrable sustainability and responsible business commitments.

This is an individual contributor role at the IC3 level, meaning you will be expected to operate with a high degree of autonomy, bring deep subject matter expertise, and influence outcomes across product, engineering, legal, and commercial teams without direct line management authority. You will report to the Director of Compliance.

What success looks like

In the first 90 days you will have a clear picture of the Campaign ISO 27001 ISMS, PCI DSS programme status, and the current state of Optimizely's ESG commitments. You will have built strong working relationships with the Director, Compliance & Risk, Security Engineering, Legal, and relevant product teams, and will have identified the key priorities and gaps to address in your first year.

At the 12-month mark, the Campaign ISO 27001 certification will be maintained with clean audit outcomes, the PCI DSS programme will be operating with improved process and evidence quality, GDPR obligations are being managed proactively, and Optimizely will have a published ESG/Sustainability report with a clear roadmap for continuous improvement.

Job Responsibilities

Campaign (15%)

  • Support and co-maintain the ISO 27001 Information Security Management System (ISMS) for Campaign, including scope definition, risk treatment, and Statement of Applicability (SoA).
  • Act as a supporting contact for Campaign ISMS, collaborating with product, engineering, infrastructure, and Compliance teams to maintain effective, evidenced controls.
  • Assist in preparing and managing annual ISO 27001 surveillance and recertification audits, liaising with external auditors.
  • Conduct scheduled internal audits and management reviews, tracking findings to resolution.
  • Maintain and enhance the Campaign scope risk register, ensuring risks are assessed, treated, and reviewed per ISMS policy.
  • Align Campaign ISMS controls with Optimizely's overarching security program and group policies alongside the Director, Compliance & Risk.
  • Keep ISO 27001 documentation current, audit-ready, and available for customers via the Trust Center.

PCI DSS v4.0.1 (25%)

  • Support and co-maintain Optimizely's global PCI DSS v4.0.1 compliance program alongside security engineering and product teams.
  • Maintain an accurate Cardholder Data Environment (CDE) scope, including network segmentation docs, data flow diagrams, and system inventories.
  • Coordinate the annual AOC/SAQ-D process and manage the Qualified Security Assessor (QSA) relationship.
  • Track and drive remediation of PCI DSS findings, collaborating with engineering and infrastructure teams to meet compliance deadlines.
  • Monitor ongoing PCI DSS v4.0.1 requirements to ensure proactive, continuous compliance.

3.4 ESG Programme (50%)

  • Support Optimizely's companywide ESG programme, defining the strategy, roadmap, and reporting framework in line with relevant standards and stakeholder expectations.
  • Develop and maintain Optimizely's ESG disclosure frameworks working with ESG platforms like EcoVadis, Novartis, Malk and the Carbon Disclosure Project (CDP).
  • Coordinate ESG data collection across the business (including emissions data, diversity metrics, social impact indicators, and governance practices), working with Finance, HR, Facilities, Legal, and Product teams.
  • Prepare and publish Optimizely's annual ESG report or equivalent sustainability disclosure, ensuring accuracy, consistency, and alignment with investor and customer expectations.
  • Respond to customer ESG questionnaires and ESG rating agency requests (e.g. EcoVadis, CDP, MSCI), managing submissions and coordinating input from subject matter owners.
  • Build and maintain an ESG roadmap, identifying gaps against emerging requirements and tracking progress against commitments.
  • Engage internal stakeholders — including the executive team — to embed ESG thinking into business strategy and operational decisions.
  • Monitor regulatory developments in ESG and sustainability reporting and advise on implications for Optimizely.

GDPR and Data Privacy (10%)

  • Support Optimizely’s global data privacy programme, maintaining compliance with GDPR, CCPA, and global privacy laws.
  • Assist with operational privacy tasks, including DPIAs, vendor privacy assessments, and DPA workflows.
  • Maintain accurate data mapping, Records of Processing Activities (ROPA), and personal data inventories.
  • Handle and process Data Subject Access Requests (DSARs) and incoming customer privacy inquiries.
  • Partner with engineering, legal, and compliance teams to embed privacy-by-design into product development.

Knowledge and Experience

Essential

  • Proven experience (3-5+ years) managing or significantly contributing to an ISO 27001 ISMS, including audit preparation, internal auditing, and certification maintenance.
  • Solid working knowledge of PCI DSS (v4.0.1), including scoping, gap assessment, remediation tracking, and evidence collation for ROC or SAQ processes.
  • Practical experience with GDPR compliance, ideally including DPIAs, RoPA maintenance, DPA review, and DSARs.
  • Experience managing or contributing to an ESG or sustainability programme, including data collection, reporting, and external disclosure.
  • Strong ability to work cross-functionally with technical and non-technical stakeholders, translating compliance requirements into actionable tasks.
  • Excellent written and verbal communication skills in English; German language proficiency is strongly preferred given the location and regulatory environment.
  • Self-directed, highly organized, and comfortable managing multiple concurrent workstreams with competing deadlines.
  • Based in Germany, with the right to work in Germany.

Preferred

  • Relevant certifications such as ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, PCIP, or equivalent.
  • Familiarity with UK/EU GDPR and other local data protection laws.
  • Experience in a SaaS or enterprise technology company, ideally with exposure to multi-product compliance programmes.
  • Experience working with external auditors, certification bodies, or QSAs.
  • Familiarity with GRC tooling (e.g. Conveyor, Drata, Vanta, OneTrust, or similar).

Education

Bachelor's degree or equivalent experience

Optimizely is committed to a diverse and inclusive workplace. Optimizely is an equal opportunity employer and does not discriminate on the basis of race, national origin, gender, gender identity, sexual orientation, protected veteran status, disability, age, or other legally protected status.

#LI-JS1