Head of Information Security
Constructor TECH · France · Hybrid
Posted Sep 10, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
Our mission
Constructor’s mission is to enable all educational organisations to provide high-quality digital education to 10x people with 10x efficiency.
With strong expertise in machine intelligence and data science, Constructor’s all-in-one platform for education and research addresses today’s pressing educational challenges: access inequality, tech clutter, and low engagement of students.
Please send your resume in English only.
About the Role
We're looking for a Head of Cybersecurity to expand and lead our security function across four areas: application security, security compliance, infrastructure & cloud security, and business application security. You'll take over a small existing security team, with a mandate to grow it as the company scales.
This is a hands-on leadership role. You'll set direction and represent security to leadership, but you're also expected to dig into technical detail with engineering, IT, and compliance teams.
Duties & Responsibilities
Application security
Build and run our AppSec program, including agentic/AI-assisted security reviews of code and pull requests
Integrate security checks into CI/CD pipelines so vulnerabilities are caught before production
Run developer security training and champion secure coding practices org-wide
Evaluate and roll out AI coding tools in ways that improve, not undermine, code security
Security compliance
Own ISO 27001 and SOC 2 certification and ongoing security audits
Collect requirements from stakeholders and build a roadmap for additional certifications as the business requires them
Maintain policies, controls, and evidence in a way that scales without slowing teams down
Infrastructure & Cloud Security
Work closely with our DevOps organization to secure our Kubernetes infrastructure and cloud environments, including sovereign cloud deployments
Define security standards for infrastructure-as-code, network architecture, and access control
Partner with Engineering teams on secure-by-default configurations
Business Application Security
Work closely with IT and Business application teams to secure Microsoft 365 and other line-of-business systems, including CRM and ERP
Own identity, access, and data protection controls across business applications
Manage third-party/vendor risk for business-critical SaaS
Qualifications & Experience:
8+ years in information security, including 3+ years in a leadership role, preferably in all-remote or hybrid international organizations
Track record running application security programs, ideally with CI/CD-integrated tooling and modern (AI-assisted) code review
Hands-on experience with ISO 27001 and/or SOC 2, proven experience leading and successfully completing the audit, not just reading the standard
Experience securing business applications (M365, CRM, ERP) and vendor risk management
Ability to explain risk and trade-offs clearly to both engineers and executives
…