
Director of Information Security
Posted Jul 30

Posted Jul 30
This is a fully remote position, open to applicants in Croatia.
• Establish customer trust and enhance sales enablement by addressing prospect security inquiries, reviewing and finalizing security questionnaires, and engaging directly with prospects and clients to represent Constructor's security posture.
• Take ownership of SOC 2 Type II and ISO 27001 certification programs, manage external auditors, uphold controls, and ensure ongoing compliance.
• Manage all security incidents from initial detection to resolution and post-incident analysis; continuously enhance the incident response plan.
• Perform ongoing risk assessments, maintain the risk register, and present the risk posture to leadership and the board.
• Conduct quarterly access reviews across all systems to ensure enforcement of least-privilege principles.
• Address "Can I use this?" inquiries from employees evaluating new tools, vendors, and workflows.
• Establish and maintain guidelines for internal AI usage, balancing productivity with data protection.
• Organize and execute tabletop exercises, simulated incidents, and red/purple team engagements.
• Oversee the data loss prevention program, triage alerts, and refine policies related to insider threats.
• Assess the security posture of third-party vendors and manage the vendor risk assessment process.
• Sustain the employee security training program and promote a security-aware culture.
• Collaborate with Platform Engineering on cloud security posture (AWS), container security, and vulnerability management.
• Over 5 years of experience in information security, including a minimum of 2 years in a senior or leadership role.
• Proficient with AI tools such as Claude Code.
• Strong familiarity with compliance frameworks including SOC 2, ISO 27001, GDPR, and CCPA.
• Experience managing incident response processes from start to finish in a SaaS or cloud-native environment.
• Comfortable in customer-facing situations, with the ability to clearly communicate security posture to enterprise prospects.
• Hands-on experience with identity management solutions (Okta or similar), MDM, DLP, and cloud security tools.
• Robust understanding of application security within a modern technology stack.
• Exceptional English written communication skills, capable of authoring policies, questionnaire responses, and executive summaries for the board.
• Ability to work independently with minimal supervision in a fully remote environment.
• CISSP, CISM, or equivalent certification is preferred but not essential.
• 🏝️ Unlimited vacation time - we strongly encourage all employees to take at least 3 weeks off each year.
• 💰 A competitive compensation package that includes stock options.
• 🌎 Fully remote team - choose your preferred location.
• 🛋️ Work from home stipend! We want to ensure you have the resources needed to set up your home office.
• 💻 Apple laptops provided for new employees.
• 🧑🎓 An annual training and development budget for every employee.
• 👪 Parental leave available for qualified employees.
• 🧠 Collaborate with intelligent colleagues who will support your growth and help you make a significant impact.
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.