About Constructor

Constructor’s mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency. With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students.

About the Role

We're looking for a Head of Cybersecurity to expand and lead our security function across four areas: application security, security compliance, infrastructure & cloud security, and business application security. You'll take over a small existing security team, with a mandate to grow it as the company scales. This is a hands-on leadership role. You'll set direction and represent security to leadership, but you're also expected to dig into technical detail with engineering, IT, and compliance teams.

Duties & Responsibilities

Application security * Build and run our AppSec program, including agentic/AI-assisted security reviews of code and pull requests * Integrate security checks into CI/CD pipelines so vulnerabilities are caught before production * Run developer security training and champion secure coding practices org-wide * Evaluate and roll out AI coding tools in ways that improve, not undermine, code security

Security compliance * Own ISO 27001 and SOC 2 certification and ongoing security audits * Collect requirements from stakeholders and build a roadmap for additional certifications as the business requires them * Maintain policies, controls, and evidence in a way that scales without slowing teams down

Infrastructure & Cloud Security * Work closely with our DevOps organization to secure our Kubernetes infrastructure and cloud environments, including sovereign cloud deployments * Define security standards for infrastructure-as-code, network architecture, and access control * Partner with Engineering teams on secure-by-default configurations

Business Application Security * Work closely with IT and Business application teams to secure Microsoft 365 and other line-of-business systems, including CRM and ERP * Own identity, access, and data protection controls across business applications * Manage third-party/vendor risk for business-critical SaaS

What We Offer

  • 💻 Choice of work equipment (e.g., laptop, monitor, etc.)
  • 🇬🇧 English classes (iTalki – $130 monthly)
  • ⏰ Flexible schedule (we usually work between 09:00/10:00 and 18:00/19:00)
  • 👶 Newborn bonus (€500 per child)
  • 🧠 Patent remuneration
  • 🌴 Paid leave
  • 🧑‍💻 Remote work in locations without our offices
  • Hybrid work in locations with offices (2 days in-office, 3 days remote)

Qualifications & Experience:

  • 8+ years in information security, including 3+ years in a leadership role, preferably in all-remote or hybrid international organizations
  • Track record running application security programs, ideally with CI/CD-integrated tooling and modern (AI-assisted) code review
  • Hands-on experience with ISO 27001 and/or SOC 2, proven experience leading and successfully completing the audit, not just reading the standard
  • Experience securing business applications (M365, CRM, ERP) and vendor risk management
  • Ability to explain risk and trade-offs clearly to both engineers and executives
  • Comfortable operating with a small team and prioritizing across competing demands
  • Working knowledge of Kubernetes and cloud security; sovereign cloud experience is a plus
Constructor TECH

Constructor TECH