Director of Information Security
Constructor · Engineering · Lead · 26d ago
Open to candidates across EMEA, Europe.
The role is open across EMEA/Europe, with a preference for Croatia, making it an eligible multi-country regional listing.
Direct from the employer's own careers page
Who can apply
Read straight from the listing, so you know before you spend time on it.
Open to candidates across EMEA, Europe.
“Remote - EMEA”
The wider team is based in Croatia, with remote operations across Europe/EMEA.
- Async-first
- The listing doesn't promise async-first working.
- Contractor / B2B
- No mention of hiring international contractors or invoicing.
- Global stipend
- Provides a work from home stipend for home office setup.
- Annual retreat
- No company-paid get-togethers mentioned.
Read from the listing automatically. Always confirm the details with the company before you accept an offer.
About the role
As Director of Information Security reporting to the CIO, you will lead Constructor's security program end-to-end in a lean, engineering-driven environment. You will be responsible for security compliance frameworks (SOC 2, ISO 27001), incident response, AI governance, internal policies, vendor evaluations, and representing the company's security posture directly in prospect and customer engagements.
What you'll do
- Represent Constructor's security posture directly with enterprise prospects and customers and answer security questionnaires.
- Own SOC 2 Type II and ISO 27001 compliance programs, manage external audits, and maintain controls.
- Lead incident response from detection through post-mortem and conduct regular security exercises.
- Manage risk assessments, maintain the risk register, and report risk posture to leadership and the board.
- Run quarterly access reviews across systems, enforce least-privilege principles, and oversee DLP and insider threat programs.
- Partner with Platform Engineering on AWS cloud security posture, container security, and vulnerability management.
What you bring
- 5+ years of experience in information security, including at least 2 years in a senior or leadership role.
- 2+ years hands-on experience in a DevOps or Platform Engineering capacity.
- Deep familiarity with compliance frameworks including SOC 2, ISO 27001, GDPR, and CCPA.
- Proven experience managing incident response end-to-end in a cloud-native SaaS environment.
- Strong understanding of application security, identity management (Okta or similar), and modern cloud security tools.
- Located in Europe (ideally Croatia) with excellent written English communication skills.
About Constructor
Constructor is an AI-first search and product discovery platform built specifically for enterprise ecommerce brands to drive conversion, revenue, and profit lifts.
View Constructor profile & open roles →