The Director of Information Security’s responsibilities will include:
Customer trust & sales enablement — Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture
Compliance & audit — Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance
Incident response — Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan
Risk management — Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board
Access governance — Run quarterly access reviews across all systems; ensure least-privilege principles are enforced
Internal advisory — Field "Can I use this?" questions from employees evaluating new tools, vendors, and workflows
AI governance — Define and maintain guardrails for internal AI use, balancing productivity with data protection
Security exercises — Plan and execute tabletop exercises, simulated incidents, and red/purple team engagements
DLP & insider threat — Oversee the data loss prevention program, triage alerts, and refine policies
Vendor security — Review third-party vendor security posture and manage the vendor risk assessment process
Security awareness — Maintain the employee security training program and foster a security-conscious culture
Infrastructure security partnership — Collaborate with Platform Engineering on cloud security posture ( AWS ), container security, and vulnerability management
5+ years of experience in information security, with at least 2 years in a senior or leadership role
Proficiency with AI tools like Claude Code
Deep familiarity with compliance frameworks ( SOC 2 , ISO 27001 , GDPR , CCPA )
Experience owning incident response end-to-end in a SaaS or cloud-native environment
Comfortable in customer-facing settings — you can clearly articulate security posture to enterprise prospects
Hands-on experience with identity management ( Okta or similar), MDM , DLP , and cloud security tooling
Strong understanding of application security in a modern stack
Excellent English written communication — you'll author policies, questionnaire responses, and board-level summaries
Ability to operate independently with minimal oversight in a fully remote culture
CISSP , CISM , or equivalent certification preferred but not required
...client success through exceptional communication, customer service, and relationship management. This entry-level opportunity is ideal for individuals looking to develop skills in account management, customer relations, sales support, business operations, and client...
Data Quality Analyst (DQ Analytics Tool, SQL, data analytics, data quality, unit testing, version controls, data lineage) in McLean, VAData... ...multiple tasks simultaneouslyAbility to collaborate with people from a diverse set of backgrounds-------------------------...
...expected to have a deep understanding of exercise physiology, nutrition, and motivational strategies to help clients achieve their fitness... ...Education: Bachelor's Degree in Kinesiology, Sports Science, or a related field and one (1) year of experience as a...
Job Description: We are seeking energetic and reliable Fulfillment Associates to join our team at the retail distribution facility in Elizabethtown, PA. This position features a highly desirable A-Shift schedule: Tuesday through Friday from 6:00 AM to 4:00 PM (enjoy...
...Job Title: Marketing Manager Location-Type: Hybrid, Atlanta, GA (Buckhead, 3 days/week in office) Start Date: ASAP Duration: Permanent Compensation Range: $80,000 - $90,000k Benefits: Health insurance, dental insurance, vision, paid time off, performance...