Head of ICT

1 day agoHeadSalary: 90K - 120KLuxembourgCybersecurityJobs by Tide

Tide is a UK-founded fintech business financial platform providing banking and financial-management services to small businesses and sole traders.

London, United Kingdom
About Tide

Tide Platform Limited operates Tide, offering business accounts, payments, accounting and tax tools, savings, payroll, and business finance. Tide is FCA-authorised for electronic-money and payment services and is not itself a bank; its business bank accounts are provided through partner banks including ClearBank.

View jobs by Tide

Skills

Candidate Availability

Required and preferred rules are kept separate and reflect the wording in the original posting.

About the Role

You will lead the ICT function for the EU entity in Luxembourg. You will own its ICT strategy, project roadmap, digital operational resilience strategy, outsourcing governance, third-party risk position, and first-line ICT security requirements. You will ensure practical DORA compliance, govern AI use, report risk to senior management and the board committee, and lead ICT engagement with the CSSF.

Requirements

  • Extensive experience running or governing ICT in a regulated financial institution, including DORA delivery
  • Deep third-party and outsourcing risk experience across the full lifecycle
  • Knowledge of intra-group delegation models, sub-outsourcing, data location, and concentration risk
  • Direct experience with the CSSF and understanding of Luxembourg local-substance expectations
  • Knowledge of modern cloud and engineering practices, including CI/CD, Infrastructure as Code, and cloud-native architecture
  • Experience implementing ISO 27001 ISMS and knowledge of NIST CSF and PCI DSS
  • Ability to write for regulators and work effectively with group functions
  • Fluent English
  • CISSP, CISM, or CISA preferred
  • French, German, or Luxembourgish is useful

Responsibilities

  • Own the entity's ICT strategy, ICT project roadmap, and digital operational resilience strategy
  • Act as Service Owner for the intra-group arrangement with Tide Platform Ltd
  • Set service levels and evidence rights, monitor performance, and assess material changes
  • Direct the outsourcing lifecycle, including due diligence, contractual protections, registers, monitoring, exit strategy, and CSSF notification
  • Own criticality, concentration risk, and exit strategies across the third-party and cloud estate
  • Ensure practical compliance with DORA obligations, including classification, incident management, resilience testing, and exit planning
  • Set and verify first-line ICT security requirements and govern AI use
  • Report ICT and third-party risk to Authorised Management and the Board Risk and Compliance Committee
  • Lead ICT dialogue with the CSSF, including audits and regulatory examinations

Benefits

  • Equity
  • Generous annual leave in addition to bank holidays
  • Maternity, paternity, and adoption leave
  • Paid and unpaid sabbatical options after milestone years
  • Access to therapy sessions, courses, meditations, and workshops
  • Paid volunteering and personal-growth days
  • Annual learning and development budget
  • Home office setup contribution