SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: EUR 90,000 - 120,000 / annual
Tide is a fintech platform serving SMEs across the UK, India, Germany, and France with business banking and administrative solutions. With over 2 million members and $300M+ in funding, Tide is expanding its EU operations and seeking a Head of ICT for its Luxembourg-based EU entity (Tide Platform S.A.).
This is a senior technology leadership role responsible for ICT governance, risk management, and regulatory compliance for the EU entity. You will report locally to Authorised Management and functionally to Tide's Chief Data and Technology Officer, serving as the first line of defence for ICT decisions within the entity.
Key Responsibilities:
- Own the entity's ICT Strategy, digital operational resilience strategy, and ICT project roadmap
- Act as Service Owner for the intra-group arrangement with Tide Platform Ltd (UK subsidiary), setting service levels, monitoring performance, and assessing material changes
- Direct the full outsourcing lifecycle for the entity, including due diligence, contracting, monitoring, exit planning, and CSSF notification; assume the Outsourcing Officer mandate
- Manage criticality and concentration risk across the third-party estate (30+ arrangements spanning Luxembourg, Germany, France, Bulgaria, and Romania)
- Ensure TPSA meets Digital Operational Resilience Act (DORA) obligations: asset classification, incident management, resilience testing, and exit planning
- Set first-line ICT security requirements and govern AI usage within the entity
- Report ICT and third-party risk to Authorised Management and the Board Risk and Compliance Committee
- Lead regulatory dialogue with the CSSF (Commission de Surveillance du Secteur Financier), including audits and examinations
- Shape Tide's expansion into new European markets and determine how much platform capability is brought to new regions
This role sits at the intersection of technology, risk, and regulation. You will manage a complex outsourcing landscape while maintaining independence from the group engineering function and working with second-line oversight (Business Information Security Officer, Operational Risk Manager) and Internal Audit.
Requirements:
- Extensive experience running or governing ICT in a regulated financial institution, including DORA delivery
- Deep third-party and outsourcing risk experience across the full lifecycle (due diligence, contracting, monitoring, exit)
- Knowledge of intra-group delegation models, sub-outsourcing, data location, and concentration risk
- Direct experience with the CSSF and understanding of Luxembourg expectations on local substance
- Fluency in modern cloud and engineering practices: CI/CD, Infrastructure as Code, cloud-native architecture, with depth to evaluate cloud configurations independently
- ISO 27001 ISMS implementation and frameworks such as NIST CSF and PCI DSS
- Ability to write for regulators and maintain position with group functions that do not report to you
- CISSP, CISM, or CISA certification preferred
- Fluent English; French, German, or Luxembourgish useful