Jobs and Careers
CO

Director of Information Security

Constructor
RemoteRemotefull_timePosted 2 Sept 2026

About the role

About You As Director of Information Security, you will own Constructor's security program end-to-end — protecting our platform, our customers' data, and our team. You'll report to the CIO and serve as the company's senior security leader, responsible for everything from compliance frameworks and incident response to hands-on prospect engagements and internal policy. This is a high-autonomy role where you'll shape strategy and execute it yourself in a lean, engineering-driven organization. About Us Constructor is the only search and product discovery platform tailor-made for enterprise ecommerce where conversions matter. Constructor's AI-first solutions make it easier for shoppers to discover products they want to buy and for ecommerce teams to deliver highly personalized experiences that drive impressive results. Optimizing specifically for ecommerce metrics like revenue, conversion rate and profit, Constructor generates consistent $10M+ lifts for some of the biggest brands in ecommerce, such as Sephora, Petco, home24, Maxeda Brands, Birkenstock and The Very Group. Constructor is a U.S. based company that was founded in 2015 by Eli Finkelshteyn and Dan McCormick. About the Position The Director of Information Security’s responsibilities will include: Customer trust & sales enablement — Answer prospect security questions, review and finalize security questionnaires, and meet directly with prospects and customers to represent Constructor's security posture Compliance & audit — Own SOC 2 Type II and ISO 27001 certification programs, manage external auditors, maintain controls, and ensure continuous compliance Incident response — Own all security incidents from detection through resolution and post-mortem; maintain and improve the incident response plan Risk management — Conduct ongoing risk assessments, maintain the risk register, and present risk posture to leadership and the board Access governance — Run quarterly access reviews across all systems; ensure least-privilege principles are enforced Internal advisory — Field "Can I use this?" questions from employees evaluating new tools, vendors, and workflows AI governance — Define and maintain guardrails for internal AI use, balancing productivity with data protection Security exercises — Plan and execute tabletop exercises, simulated incidents, and red/purple team engagements DLP & insider threat — Oversee the data loss prevention program, triage alerts, and refine policies Vendor security — Review third-party vendor security posture and manage the vendor risk assessment process Security awareness — Maintain the employee security training program and foster a security-conscious culture Infrastructure security partnership — Collaborate with Platform Engineering on cloud security posture (AWS), container security, and vulnerability management Requirements 5+ years of experience in information security, with at least 2 years in a senior or leadership role 2+ years hands-on experience in a

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Constructor

View company profile →