Skip to content

Nobody tells you why you were rejected. We will. Free, in 30 seconds.

Score my CV against live jobs

Director of Information Security

Constructor · Remote - EMEA

On-siteSeniorPosted 2 Sept 2026

What this role requires

5 requirements, read out of the advert rather than guessed from the job title:

Also mentioned, not required: AI, Okta, MDM, DLP, cloud security. Worth having, but their absence is not what gets a CV filtered out.

See how often each of these is required across open security roles in Europe.

Check my CV against these 5 requirements

Free, no card. Tells you which of them your CV evidences and which it only implies.

Job description

About You

As Director of Information Security, you will own Constructor's security program end-to-end — protecting our platform, our customers' data, and our team. You'll report to the CIO and serve as the company's senior security leader, responsible for everything from compliance frameworks and incident response to hands-on prospect engagements and internal policy. This is a high-autonomy role where you'll shape strategy and execute it yourself in a lean, engineering-driven organization.

About Us

Constructor is the only search and product discovery platform tailor-made for enterprise ecommerce where conversions matter. Constructor's AI-first solutions make it easier for shoppers to discover products they want to buy and for ecommerce teams to deliver highly personalized experiences that drive impressive results. Optimizing specifically for ecommerce metrics like revenue, conversion rate and profit, Constructor generates consistent $10M+ lifts for some of the biggest brands in ecommerce, such as Sephora, Petco, home24, Maxeda Brands, Birkenstock and The Very Group. Constructor is a U.S. based company that was founded in 2015 by Eli Finkelshteyn and Dan McCormick.

About the Position

The Director of Information Security’s responsibilities will include:

Read the full description (36 more sections)

Customer trust & sales enablement — Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture

Compliance & audit — Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance

Incident response — Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan

Risk management — Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board

Access governance — Run quarterly access reviews across all systems; ensure least-privilege principles are enforced

Internal advisory — Field "Can I use this?" questions from employees evaluating new tools, vendors, and workflows

AI governance — Define and maintain guardrails for internal AI use, balancing productivity with data protection

Security exercises — Plan and execute tabletop exercises, simulated incidents, and red/purple team engagements

DLP & insider threat — Oversee the data loss prevention program, triage alerts, and refine policies

Vendor security — Review third-party vendor security posture and manage the vendor risk assessment process

Security awareness — Maintain the employee security training program and foster a security-conscious culture

Infrastructure security partnership — Collaborate with Platform Engineering on cloud security posture (AWS), container security, and vulnerability management

Requirements

5+ years of experience in information security, with at least 2 years in a senior or leadership role

2+ years hands-on experience in a DevOps or Platform Engineering role

Proficiency with AI tools like Claude Code

Deep familiarity with compliance frameworks (SOC 2, ISO 27001, GDPR, CCPA)

Experience owning incident response end-to-end in a SaaS or cloud-native environment

Comfortable in customer-facing settings — you can clearly articulate security posture to enterprise prospects

Hands-on experience with identity management (Okta or similar), MDM, DLP, and cloud security tooling

Strong understanding of application security in a modern stack

Excellent English written communication — you'll author policies, questionnaire responses, and board-level summaries

Ability to operate independently with minimal oversight in a fully remote culture

Location - Ideally Croatia as this is where the wider team is based, or in Europe.

Benefits

🏝️ Unlimited vacation time -we strongly encourage all of our employees take at least 3 weeks per year

💰 A competitive compensation package including stock options

🌎 Fully remote team - choose where you live

🛋️ Work from home stipend! We want you to have the resources you need to set up your home office

💻 Apple laptops provided for new employees

🧑‍🎓 Training and development budget for every employee, refreshed each year

👪 Parental leave for qualified employees

🧠 Work with smart people who will help you grow and make a meaningful impact

Diversity, Equity, and Inclusion at Constructor

At Constructor.io we are committed to cultivating a work environment that is diverse, equitable, and inclusive. As an equal opportunity employer, we welcome individuals of all backgrounds and provide equal opportunities to all applicants regardless of their education, diversity of opinion, race, color, religion, gender, gender expression, sexual orientation, national origin, genetics, disability, age, veteran status or affiliation in any other protected group. Studies have shown that women and people of color may be less likely to apply for jobs unless they meet every one of the qualifications listed. Our primary interest is in finding the best candidate for the job. We encourage you to apply even if you don’t meet all of our listed qualifications.

Find Jobs in United Kingdom on Arbeitnow

You will apply. Then you will hear nothing.

And no one will tell you what was wrong. See it before you send: your ATS score, every weak line, and the fix for each.

  1. 1

    Drop in your CV

    One PDF, thirty seconds. No card.

  2. 2

    See what is wrong with it

    Every weak passage, quoted from your own CV, with the line to replace it.

  3. 3

    Apply where you fit

    Every European role ranked against what your CV actually says.

  • Free, no card
  • Your CV file is deleted after parsing
  • Or skip the upload — build your profile by hand
  • Refreshed every 6 hours