EU remote
Head of Information Security
About this role
Our mission Constructor’s mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency. With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students. Please send your resume in English only.
About the Role We're looking for a Head of Cybersecurity to expand and lead our security function across four areas: application security, security compliance, infrastructure & cloud security, and business application security. You'll take over a small existing security team, with a mandate to grow it as the company scales. This is a hands-on leadership role. You'll set direction and represent security to leadership, but you're also expected to dig into technical detail with engineering, IT, and compliance teams.
Duties & Responsibilities Application security Build and run our AppSec program, including agentic/AI-assisted security reviews of code and pull requests Integrate security checks into CI/CD pipelines so vulnerabilities are caught before production Run developer security training and champion secure coding practices org-wide Evaluate and roll out AI coding tools in ways that improve, not undermine, code security Security compliance Own ISO 27001 and SOC 2 certification and ongoing security audits Collect requirements from stakeholders and build a roadmap for additional certifications as the business requires them Maintain policies, controls, and evidence in a way that scales without slowing teams down Infrastructure & Cloud Security Work closely with our DevOps organization to secure our Kubernetes infrastructure and cloud environments, including sovereign cloud deployments Define security standards for infrastructure-as-code, network architecture, and access control Partner with Engineering teams on secure-by-default configurations Business Application Security Work closely with IT and Business application teams to secure Microsoft 365 and other line-of-business systems, including CRM and ERP Own identity, access, and data protection controls across business applications Manage third-party/vendor risk for business-critical SaaS Qualifications & Experience: 8+ years in information security, including 3+ years in a leadership role, preferably in all-remote or hybrid international organizations Track record running application security programs, ideally with CI/CD-integrated tooling and modern (AI-assisted) code review Hands-on experience with ISO 27001 and/or SOC 2, proven experience leading and successfully completing the audit, not just reading the standard Experience securing business applications (M365, CRM, ERP) and vendor risk management <li data-leveltext="-" data-font="Aptos" data-listid="7" data-list-defn-props="{"335551671":0,"335552541":1,"335559685":720,"335559991":360,"469769226":"Ap