Constructor’s mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency. With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students.
We're looking for a Head of Cybersecurity to expand and lead our security function across four areas: application security, security compliance, infrastructure & cloud security, and business application security. You'll take over a small existing security team, with a mandate to grow it as the company scales. This is a hands-on leadership role. You'll set direction and represent security to leadership, but you're also expected to dig into technical detail with engineering, IT, and compliance teams.
Application security * Build and run our AppSec program, including agentic/AI-assisted security reviews of code and pull requests * Integrate security checks into CI/CD pipelines so vulnerabilities are caught before production * Run developer security training and champion secure coding practices org-wide * Evaluate and roll out AI coding tools in ways that improve, not undermine, code security
Security compliance * Own ISO 27001 and SOC 2 certification and ongoing security audits * Collect requirements from stakeholders and build a roadmap for additional certifications as the business requires them * Maintain policies, controls, and evidence in a way that scales without slowing teams down
Infrastructure & Cloud Security * Work closely with our DevOps organization to secure our Kubernetes infrastructure and cloud environments, including sovereign cloud deployments * Define security standards for infrastructure-as-code, network architecture, and access control * Partner with Engineering teams on secure-by-default configurations
Business Application Security * Work closely with IT and Business application teams to secure Microsoft 365 and other line-of-business systems, including CRM and ERP * Own identity, access, and data protection controls across business applications * Manage third-party/vendor risk for business-critical SaaS
