> Markdown version of [/jobs/ext/2726980-director-of-information-security](https://www.wearedevelopers.com/jobs/ext/2726980-director-of-information-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director of Information Security - **Company:** Constructor - **Location:** UK (Remote available) - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Artificial Intelligence, Amazon Web Services, Software as a Service, Cloud Computing Security, Cyber Security, Information Leak Prevention, DevOps, Identity and Access Management, Software Vulnerability Management, Okta, Software Security, Containerization, Purple Team (Cyber Security) - **Published:** September 5, 2026 - **Apply:** https://www.adzuna.co.uk/jobs/details/5869156266 ## About the Role * 5+ years of experience in information security, with at least 2 years in a senior or leadership role * 2+ years hands-on experience in a DevOps or Platform Engineering role * Proficiency with AI tools like Claude Code * Deep familiarity with compliance frameworks (SOC 2, ISO 27001, GDPR, CCPA) * Experience owning incident response end-to-end in a SaaS or cloud-native environment * Comfortable in customer-facing settings - you can clearly articulate security posture to enterprise prospects * Hands-on experience with identity management (Okta or similar), MDM, DLP, and cloud security tooling * Strong understanding of application security in a modern stack * Excellent English written communication - you'll author policies, questionnaire responses, and board-level summaries * Ability to operate independently with minimal oversight in a fully remote culture * Location - Ideally Croatia as this is where the wider team is based, or in Europe. ## Description As Director of Information Security, you will own Constructor's security program end-to-end - protecting our platform, our customers' data, and our team. You'll report to the CIO and serve as the company's senior security leader, responsible for everything from compliance frameworks and incident response to hands-on prospect engagements and internal policy. This is a high-autonomy role where you'll shape strategy and execute it yourself in a lean, engineering-driven organization., The Director of Information Security's responsibilities will include: * Customer trust & sales enablement - Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture * Compliance & audit - Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance * Incident response - Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan * Risk management - Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board * Access governance - Run quarterly access reviews across all systems; ensure least-privilege principles are enforced * Internal advisory - Field "Can I use this?" questions from employees evaluating new tools, vendors, and workflows * AI governance - Define and maintain guardrails for internal AI use, balancing productivity with data protection * Security exercises - Plan and execute tabletop exercises, simulated incidents, and red/purple team engagements * DLP & insider threat - Oversee the data loss prevention program, triage alerts, and refine policies * Vendor security - Review third-party vendor security posture and manage the vendor risk assessment process * Security awareness - Maintain the employee security training program and foster a security-conscious culture * Infrastructure security partnership - Collaborate with Platform Engineering on cloud security posture (AWS), container security, and vulnerability management ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Kubernetes Security Best Practices](https://www.wearedevelopers.com/videos/1411-kubernetes-security-best-practices) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)