Rodeo
Get started

Constructor

Director of Information Security

Remote
Posted about 22 hours ago
Sign up to applySee more jobs like this

How your CV stacks up

1Upload CV
2Analyse CV
3Improve CV

Upload your CV to see how well it fits this job role

?%

About You

As Director of Information Security, you will own Constructor's security program end-to-end — protecting our platform, our customers' data, and our team. You'll report to the CIO and serve as the company's senior security leader, responsible for everything from compliance frameworks and incident response to hands-on prospect engagements and internal policy. This is a high-autonomy role where you'll shape strategy and execute it yourself in a lean, engineering-driven organization.

About Us

Constructor is the only search and product discovery platform tailor-made for enterprise ecommerce where conversions matter. Constructor's AI-first solutions make it easier for shoppers to discover products they want to buy and for ecommerce teams to deliver highly personalized experiences that drive impressive results. Optimizing specifically for ecommerce metrics like revenue, conversion rate and profit, Constructor generates consistent $10M+ lifts for some of the biggest brands in ecommerce, such as Sephora, Petco, home24, Maxeda Brands, Birkenstock and The Very Group. Constructor is a U.S. based company that was founded in 2015 by Eli Finkelshteyn and Dan McCormick.

About the Position

The Director of Information Security’s responsibilities will include:

  • Customer trust & sales enablement — Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture
  • Compliance & audit — Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance
  • Incident response — Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan
  • Risk management — Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board
  • Access governance — Run quarterly access reviews across all systems; ensure least-privilege principles are enforced
  • Internal advisory — Field "Can I use this?" questions from employees evaluating new tools, vendors, and workflows
  • AI governance — Define and maintain guardrails for internal AI use, balancing productivity with data protection
  • Security exercises — Plan and execute tabletop exercises, simulated incidents, and red/purple team engagements
  • DLP & insider threat — Oversee the data loss prevention program, triage alerts, and refine policies
  • Vendor security — Review third-party vendor security posture and manage the vendor risk assessment process
  • Security awareness — Maintain the employee security training program and foster a security-conscious culture
  • Infrastructure security partnership — Collaborate with Platform Engineering on cloud security posture (AWS), container security, and vulnerability management

Reasons to use Rodeo

I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?

Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.

Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.

Start with a chat, not a search bar

Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.

P

Graduate Consultant — 2026 Scheme

PwC·London, UK
£35,000/yr

Why you're a good match

Strong

Your economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.

See breakdown
Save jobNot relevant
View details

It searches the market for you

Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.

Why you're a good match

You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.

See breakdown
Strong

Experience fit

Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.

See breakdown
Strong

Only hits

No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.

Requirements

  • 5+ years of experience in information security, with at least 2 years in a senior or leadership role
  • Proficiency with AI tools like Claude Code
  • Deep familiarity with compliance frameworks (SOC 2, ISO 27001, GDPR, CCPA)
  • Experience owning incident response end-to-end in a SaaS or cloud-native environment
  • Comfortable in customer-facing settings — you can clearly articulate security posture to enterprise prospects
  • Hands-on experience with identity management (Okta or similar), MDM, DLP, and cloud security tooling
  • Strong understanding of application security in a modern stack
  • Excellent English written communication — you'll author policies, questionnaire responses, and board-level summaries
  • Ability to operate independently with minimal oversight in a fully remote culture
  • CISSP, CISM, or equivalent certification preferred but not required

Get help with your application

Your very own career expert that helps elevate your application to the next level.

Get help applying for this job

Benefits

  • 🏝️ Unlimited vacation time -we strongly encourage all of our employees take at least 3 weeks per year
  • 💰 A competitive compensation package including stock options
  • 🌎 Fully remote team - choose where you live
  • 🛋️ Work from home stipend! We want you to have the resources you need to set up your home office
  • 💻 Apple laptops provided for new employees
  • 🧑‍🎓 Training and development budget for every employee, refreshed each year
  • 👪 Parental leave for qualified employees
  • 🧠 Work with smart people who will help you grow and make a meaningful impact

Diversity, Equity, and Inclusion at Constructor

At Constructor.io we are committed to cultivating a work environment that is diverse, equitable, and inclusive. As an equal opportunity employer, we welcome individuals of all backgrounds and provide equal opportunities to all applicants regardless of their education, diversity of opinion, race, color, religion, gender, gender expression, sexual orientation, national origin, genetics, disability, age, veteran status or affiliation in any other protected group. Studies have shown that women and people of color may be less likely to apply for jobs unless they meet every one of the qualifications listed. Our primary interest is in finding the best candidate for the job. We encourage you to apply even if you don’t meet all of our listed qualifications.

Trusted by 25,000+ job seekers

“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”

Jessica, London

Get help applying for this job

Skills

Information Security Leadership
SOC 2 Compliance
ISO 27001 Compliance
Incident Response
Risk Management
Access Governance
AI Governance
Data Loss Prevention
Vendor Security Assessment
Cloud Security
AWS
Identity Management
Application Security
GDPR
CCPA
Security Awareness Training

Location

United Kingdom

Sign up to applySee more jobs like this