Head of Information Security
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+4 more
Job description
With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students. Please send your resume in English only. About the Role
We’re looking for a Head of Cybersecurity to expand and lead our security function across four areas: application security, security compliance, infrastructure & cloud security, and business application security. You’ll take over a small existing security team, with a mandate to grow it as the company scales.
This is a hands-on leadership role. You’ll set direction and represent security to leadership, but you’re also expected to dig into technical detail with engineering, IT, and compliance teams., * Build and run our AppSec program, including agentic/AI-assisted security reviews of code and pull requests
- Integrate security checks into CI/CD pipelines so vulnerabilities are caught before production
- Run developer security training and champion secure coding practices org-wide
- Evaluate and roll out AI coding tools in ways that improve, not undermine, code security
Security compliance
- Own ISO 27001 and SOC 2 certification and ongoing security audits
- Collect requirements from stakeholders and build a roadmap for additional certifications as the business requires them
- Maintain policies, controls, and evidence in a way that scales without slowing teams down
Infrastructure & Cloud Security
- Work closely with our DevOps organization to secure our Kubernetes infrastructure and cloud environments, including sovereign cloud deployments
- Define security standards for infrastructure-as-code, network architecture, and access control
- Partner with Engineering teams on secure-by-default configurations
Business Application Security
- Work closely with IT and Business application teams to secure Microsoft 365 and other line-of-business systems, including CRM and ERP
- Own identity, access, and data protection controls across business applications
- Manage third-party/vendor risk for business-critical SaaS, * Choice of work equipment (e.g., laptop, monitor, etc.)
- English classes (iTalki - $130 monthly)
- Flexible schedule (we usually work between 09:00/10:00 and 18:00/19:00)
- Newborn bonus (€500 per child)
- Patent remuneration
- Paid leave
- Remote work in locations without our offices
- Hybrid work in locations with offices (2 days in-office, 3 days remote)
Requirements
- 8+ years in information security, including 3+ years in a leadership role, preferably in all-remote or hybrid international organizations
- Track record running application security programs, ideally with CI/CD-integrated tooling and modern (AI-assisted) code review
- Hands-on experience with ISO 27001 and/or SOC 2, proven experience leading and successfully completing the audit, not just reading the standard
- Experience securing business applications (M365, CRM, ERP) and vendor risk management
- Ability to explain risk and trade-offs clearly to both engineers and executives
- Comfortable operating with a small team and prioritizing across competing demands
- Working knowledge of Kubernetes and cloud security; sovereign cloud experience is a plus
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
The Most Popular IT Jobs on the Market
Where to Find German Tech Jobs
Fully Remote Software Engineer Jobs
Finding IT & Technology English-speaking Jobs in GermanyÂ