Back to Jobs
Development 1h ago

Director of Information Security

CroatiaCroatia
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

QA EngineerBestseller 🔥
Learn in 10 Hours
BackendBestseller 🔥
Learn in 18 Hours
DevOpsBestseller 🔥
Learn in 63 Hours
CybersecurityAI Engineer

Want to know if you're a match for this job?

Calculate My Match Score

About the Position

The Director of Information Security’s responsibilities will include:

  • Customer trust & sales enablement — Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture

  • Compliance & audit — Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance

  • Incident response — Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan

  • Risk management — Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board

  • Access governance — Run quarterly access reviews across all systems; ensure least-privilege principles are enforced

  • Internal advisory — Field "Can I use this?" questions from employees evaluating new tools, vendors, and workflows

  • AI governance — Define and maintain guardrails for internal AI use, balancing productivity with data protection

  • Security exercises — Plan and execute tabletop exercises, simulated incidents, and red/purple team engagements

  • DLP & insider threat — Oversee the data loss prevention program, triage alerts, and refine policies

  • Vendor security — Review third-party vendor security posture and manage the vendor risk assessment process

  • Security awareness — Maintain the employee security training program and foster a security-conscious culture

  • Infrastructure security partnership — Collaborate with Platform Engineering on cloud security posture (AWS), container security, and vulnerability management

Requirements

  • 5+ years of experience in information security, with at least 2 years in a senior or leadership role

  • Proficiency with AI tools like Claude Code

  • Deep familiarity with compliance frameworks (SOC 2, ISO 27001, GDPR, CCPA)

  • Experience owning incident response end-to-end in a SaaS or cloud-native environment

  • Comfortable in customer-facing settings — you can clearly articulate security posture to enterprise prospects

  • Hands-on experience with identity management (Okta or similar), MDM, DLP, and cloud security tooling

  • Strong understanding of application security in a modern stack

  • Excellent English written communication — you'll author policies, questionnaire responses, and board-level summaries

  • Ability to operate independently with minimal oversight in a fully remote culture

  • CISSP, CISM, or equivalent certification preferred but not required

How would you rate this job post?

See what other professionals think about this role.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More