Director of Information Security
CroatiaJob Description
Key Skills Required
Master these to land this role
Want to know if you're a match for this job?
About the Position
The Director of Information Security’s responsibilities will include:
Customer trust & sales enablement — Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture
Compliance & audit — Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance
Incident response — Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan
Risk management — Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board
Access governance — Run quarterly access reviews across all systems; ensure least-privilege principles are enforced
Internal advisory — Field "Can I use this?" questions from employees evaluating new tools, vendors, and workflows
AI governance — Define and maintain guardrails for internal AI use, balancing productivity with data protection
Security exercises — Plan and execute tabletop exercises, simulated incidents, and red/purple team engagements
DLP & insider threat — Oversee the data loss prevention program, triage alerts, and refine policies
Vendor security — Review third-party vendor security posture and manage the vendor risk assessment process
Security awareness — Maintain the employee security training program and foster a security-conscious culture
Infrastructure security partnership — Collaborate with Platform Engineering on cloud security posture (AWS), container security, and vulnerability management
Requirements
5+ years of experience in information security, with at least 2 years in a senior or leadership role
Proficiency with AI tools like Claude Code
Deep familiarity with compliance frameworks (SOC 2, ISO 27001, GDPR, CCPA)
Experience owning incident response end-to-end in a SaaS or cloud-native environment
Comfortable in customer-facing settings — you can clearly articulate security posture to enterprise prospects
Hands-on experience with identity management (Okta or similar), MDM, DLP, and cloud security tooling
Strong understanding of application security in a modern stack
Excellent English written communication — you'll author policies, questionnaire responses, and board-level summaries
Ability to operate independently with minimal oversight in a fully remote culture
CISSP, CISM, or equivalent certification preferred but not required
How would you rate this job post?
See what other professionals think about this role.
Safety First
- Never pay for a job application.
- Do not share sensitive bank info.
- Verify the client before starting work.