Director of Information Security
Career Integrity & Compliance Audit Report
This vacancy has been independently reviewed by the OppaJob Transatlantic Career Intelligence Desk to confirm authentic direct employer recruiting, verify compensation transparency, and eliminate applicant processing fees.
Transatlantic Cost of Living & Purchasing Power Benchmark
Compare US ($) vs UK (Β£) Salary & Net Take-Home Pay
Calculate tax deductions, living costs, and purchasing power parity across US & UK metros.
Position Overview & Specifications
About You
As Director of Information Security, you will own Constructor's security program end-to-end β protecting our platform, our customers' data, and our team. You'll report to the CIO and serve as the company's senior security leader, responsible for everything from compliance frameworks and incident response to hands-on prospect engagements and internal policy. This is a high-autonomy role where you'll shape strategy and execute it yourself in a lean, engineering-driven organization.
About Us
Constructor is the only search and product discovery platform tailor-made for enterprise ecommerce where conversions matter. Constructor's AI-first solutions make it easier for shoppers to discover products they want to buy and for ecommerce teams to deliver highly personalized experiences that drive impressive results. Optimizing specifically for ecommerce metrics like revenue, conversion rate and profit, Constructor generates consistent $10M+ lifts for some of the biggest brands in ecommerce, such as Sephora, Petco, home24, Maxeda Brands, Birkenstock and The Very Group. Constructor is a U.S. based company that was founded in 2015 by Eli Finkelshteyn and Dan McCormick.
About the Position
The Director of Information Securityβs responsibilities will include:
Customer trust & sales enablement β Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture
Compliance & audit β Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance
Incident response β Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan
Risk management β Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board
Access governance β Run quarterly access reviews across all systems; ensure least-privilege principles are enforced
Internal advisory β Field "Can I use this?" questions from employees evaluating new tools, vendors, and workflows
AI governance β Define and maintain guardrails for internal AI use, balancing productivity with data protection
Security exercises β Plan and execute tabletop exercises, simulated incidents, and red/purple team engagements
DLP & insider threat β Oversee the data loss prevention program, triage alerts, and refine policies
Vendor security β Review third-party vendor security posture and manage the vendor risk assessment process
Security awareness β Maintain the employee security training program and foster a security-conscious culture
Infrastructure security partnership β Collaborate with Platform Engineering on cloud security posture (AWS), container security, and vulnerability management
5+ years of experience in information security, with at least 2 years in a senior or leadership role
2+ years hands-on experience in a DevOps or Platform Engineering role
Proficiency with AI tools like Claude Code
Deep familiarity with compliance frameworks (SOC 2, ISO 27001, GDPR, CCPA)
Experience owning incident response end-to-end in a SaaS or cloud-native environment
Comfortable in customer-facing settings β you can clearly articulate security posture to enterprise prospects
Hands-on experience with identity management (Okta or similar), MDM, DLP, and cloud security tooling
Strong understanding of application security in a modern stack
Excellent English written communication β you'll author policies, questionnaire responses, and board-level summaries
Ability to operate independently with minimal oversight in a fully remote culture
Location - Ideally Croatia as this is where the wider team is based, or in Europe.
ποΈ Unlimited vacation time -we strongly encourage all of our employees take at least 3 weeks per year
π° A competitive compensation package including stock options
π Fully remote team - choose where you live
ποΈ Work from home stipend! We want you to have the resources you need to set up your home office
π» Apple laptops provided for new employees
π§βπ Training and development budget for every employee, refreshed each year
πͺ Parental leave for qualified employees
π§ Work with smart people who will help you grow and make a meaningful impact
At Constructor.io we are committed to cultivating a work environment that is diverse, equitable, and inclusive. As an equal opportunity employer, we welcome individuals of all backgrounds and provide equal opportunities to all applicants regardless of their education, diversity of opinion, race, color, religion, gender, gender expression, sexual orientation, national origin, genetics, disability, age, veteran status or affiliation in any other protected group. Studies have shown that women and people of color may be less likely to apply for jobs unless they meet every one of the qualifications listed. Our primary interest is in finding the best candidate for the job. We encourage you to apply even if you donβt meet all of our listed qualifications.
Find Jobs in United Kingdom on Arbeitnow
Candidate Selection & Onboarding Process
Application & Resume Screening
Submit your tailored CV/Resume directly to the talent acquisition portal.
Technical & Competency Interviews
Virtual interviews with the hiring manager and multidisciplinary team.
Formal Offer & Benefits Negotiation
Written agreement outlining compensation, equity, retirement vesting, and relocation allowances.
Onboarding & Corporate Integration
Equipment provisioning, team orientation, and commencement of duties.
United States Work Authorization & Sponsorship Guide
Under United States immigration law (INA Β§ 101(a)(15)(H)), foreign nationals seeking full-time professional positions typically navigate either non-immigrant specialty occupation classifications or immigrant visa sponsorship:
Requires a relevant Bachelor's degree or higher. Employers must file an approved Labor Condition Application (LCA) with the US Department of Labor confirming the prevailing wage rate.
Canadian and Mexican citizens qualify under USMCA (TN status). F-1 STEM graduates benefit from 36-month aggregate work authorization through E-Verify enrolled employers.
Candidate Preparation Blueprint: Technology
Based on transatlantic hiring benchmarks for Director of Information Security roles across Constructor's corporate sector, successful applicants typically excel across three core dimensions:
Demonstrated portfolio evidence, architecture/system design case studies, or validated professional certifications directly applicable to Technology.
STAR method competency responses highlighting cross-functional leadership, conflict resolution, and delivering measurable enterprise ROI under tight timelines.
Total compensation expectation aligned within the benchmarked Salary Disclosed on Application bracket, including retirement vesting and health parity.
Explore Related Opportunities (Worldwide / Remote)
Other high-paying verified positions matching your industry profile.
Senior Full Stack Cloud Architect (AI Platform)
Critical Care & ICU Registered Nurse (RN)
Renewable Power Systems & Grid Engineer
Director of Corporate Operations & Strategy
Lead Quantitative Risk Analyst
Staff Machine Learning & LLM Systems Engineer
Apply for this Position
Receive high-paying Technology openings directly to your inbox.