dev.bg

Head of Information Security

Constructor · Fully Remote · Head

28 септември 2026 г.
Публикувана
29 септември 2026 г.
Последно видяна
Активна
Статус
1 ден
Отворена от

Умения

application securityrisk managementdata protectioncloud securitysecure codingKubernetescomplianceISO 27001CI/CDSOC 2audit

Сертификати

Изискват се

Описание

Our mission

Constructor’s mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency.

With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students.

Please send your resume in English only.

About the Role

We’re looking for a Head of Cybersecurity to expand and lead our security function across four areas: application security, security compliance, infrastructure & cloud security, and business application security. You’ll take over a small existing security team, with a mandate to grow it as the company scales.

This is a hands-on leadership role. You’ll set direction and represent security to leadership, but you’re also expected to dig into technical detail with engineering, IT, and compliance teams.

Duties & Responsibilities:

Application security:

  • Build and run our AppSec program, including agentic/AI-assisted security reviews of code and pull requests.
  • Integrate security checks into CI/CD pipelines so vulnerabilities are caught before production.
  • Run developer security training and champion secure coding practices org-wide.
  • Evaluate and roll out AI coding tools in ways that improve, not undermine, code security.

Security compliance:

  • Own ISO 27001 and SOC 2 certification and ongoing security audits.
  • Collect requirements from stakeholders and build a roadmap for additional certifications as the business requires them.
  • Maintain policies, controls, and evidence in a way that scales without slowing teams down.

Infrastructure & Cloud Security:

  • Work closely with our DevOps organization to secure our Kubernetes infrastructure and cloud environments, including sovereign cloud deployments.
  • Define security standards for infrastructure-as-code, network architecture, and access control.
  • Partner with Engineering teams on secure-by-default configurations.

Business Application Security:

  • Work closely with IT and Business application teams to secure Microsoft 365 and other line-of-business systems, including CRM and ERP.
  • Own identity, access, and data protection controls across business applications.
  • Manage third-party/vendor risk for business-critical SaaS.

Qualifications & Experience:

  • 8+ years in information security, including 3+ years in a leadership role, preferably in all-remote or hybrid international organizations.
  • Track record running application security programs, ideally with CI/CD-integrated tooling and modern (AI-assisted) code review.
  • Hands-on experience with ISO 27001 and/or SOC 2, proven experience leading and successfully completing the audit, not just reading the standard.
  • Experience securing business applications (M365, CRM, ERP) and vendor risk management.
  • Ability to explain risk and trade-offs clearly to both engineers and executives.
  • Comfortable operating with a small team and prioritizing across competing demands.
  • Working knowledge of Kubernetes and cloud security; sovereign cloud experience is a plus.

What we offer:

  • Competitive salary.
  • Comprehensive health insurance.
  • Choice of equipment ( i.e. laptop, monitor, etc).
  • Flexible working schedule.
  • International company with large-scale projects and global clients.
  • Community of passionate experts to exchange knowledge and expertise with.
  • Opportunity to contribute to the better future of education together with a friendly and open-minded team.

Constructor fosters equal opportunity for people of all backgrounds and identities. We are led by a gender-balanced board committed to building a diverse and inclusive organisation where everyone can become their best self. We do not discriminate based on age, disability, gender identity, sexual orientation, ethnicity, race, religion or belief, parental and family status, or other protected characteristics. We welcome applications from women, men and non-binary candidates of all ethnicities and socio-economic backgrounds. We encourage people belonging to underrepresented groups to apply.

История на обявата

  • 29 септември 2026 г.Появи сеобхождане

Очаквано възнаграждение

Обявата не посочва заплата. Оценката по-долу е за CISO на ниво Senior / Executive според бенчмарка на CSF.BG — не е предложение на работодателя.

€5,100 – €11,200+нето/месец · 10+ години опит
Много високо търсене·Всички нива за ролята

Няма нито една обява за тази роля и ниво с публикувана заплата, с която да се сравни.

Знаеш колко се плаща за такава роля? — анонимно, за да станат тези числа по-точни.