← All roles
C

Director of Information Security

Constructor · Engineering · Lead · 26d ago

✓

Open to candidates across EMEA, Europe.

The role is open across EMEA/Europe, with a preference for Croatia, making it an eligible multi-country regional listing.

EMEAEuropeSecuritySOC 2ISO 27001DevOps

Direct from the employer's own careers page

Who can apply

Read straight from the listing, so you know before you spend time on it.

EMEAEurope

Open to candidates across EMEA, Europe.

“Remote - EMEA”

The wider team is based in Croatia, with remote operations across Europe/EMEA.

Async-first
The listing doesn't promise async-first working.
Contractor / B2B
No mention of hiring international contractors or invoicing.
Global stipend
Provides a work from home stipend for home office setup.
Annual retreat
No company-paid get-togethers mentioned.

Read from the listing automatically. Always confirm the details with the company before you accept an offer.

About the role

As Director of Information Security reporting to the CIO, you will lead Constructor's security program end-to-end in a lean, engineering-driven environment. You will be responsible for security compliance frameworks (SOC 2, ISO 27001), incident response, AI governance, internal policies, vendor evaluations, and representing the company's security posture directly in prospect and customer engagements.

What you'll do

  • Represent Constructor's security posture directly with enterprise prospects and customers and answer security questionnaires.
  • Own SOC 2 Type II and ISO 27001 compliance programs, manage external audits, and maintain controls.
  • Lead incident response from detection through post-mortem and conduct regular security exercises.
  • Manage risk assessments, maintain the risk register, and report risk posture to leadership and the board.
  • Run quarterly access reviews across systems, enforce least-privilege principles, and oversee DLP and insider threat programs.
  • Partner with Platform Engineering on AWS cloud security posture, container security, and vulnerability management.

What you bring

  • 5+ years of experience in information security, including at least 2 years in a senior or leadership role.
  • 2+ years hands-on experience in a DevOps or Platform Engineering capacity.
  • Deep familiarity with compliance frameworks including SOC 2, ISO 27001, GDPR, and CCPA.
  • Proven experience managing incident response end-to-end in a cloud-native SaaS environment.
  • Strong understanding of application security, identity management (Okta or similar), and modern cloud security tools.
  • Located in Europe (ideally Croatia) with excellent written English communication skills.

About Constructor

Constructor is an AI-first search and product discovery platform built specifically for enterprise ecommerce brands to drive conversion, revenue, and profit lifts.

View Constructor profile & open roles →

Get new verified roles in your inbox — no account needed.

Unsubscribe any time. See our Privacy Policy.