SlipstreamJobsFresh Startup & VC-Backed Jobs

Head of Product and Identity Security

Tide - London, England, United Kingdom - Hybrid - posted 2026-09-18

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Tide is a fintech company serving over 2 million SMEs globally with business banking and administrative solutions (invoicing, accounting, etc.). The company has raised over $300 million and operates across the UK, India, Germany, and France with 2,800+ employees. The Security Engineering team comprises three core areas: Product Security, Identity, and Threat Detection & Response. As Head of Product and Identity Security, you will lead two of these three areas, reporting directly to the Chief Information Security Officer (CISO) and operating as a peer to the Head of Threat Detection & Response. This is a player-manager role where you stay hands-on with the technology while directing strategy and team execution. You will lead a global team across the UK, Eastern Europe, and India. Key Responsibilities: - Define product and identity security strategy with the CISO and operationalize it into a funded, sequenced roadmap - Lead, coach, and grow a global team; conduct regular 1:1s; support career growth and progression - Own application security end-to-end: secure design reviews, threat modelling, secure coding standards, tooling, and remediation - Run the penetration testing programme across web, mobile, and infrastructure; manage external partners and stay hands-on - Own cloud security posture: configuration, workload protection, detection coverage, and guardrails that keep engineering fast and safe - Set the approach to AI and agentic security: how models, agents, and ML pipelines are designed, deployed, monitored, and defended - Own secure architecture to embed security requirements from the ground up in new products, platforms, and integrations - Own Tide's staff identity platform and IAM roadmap: zero trust, multi-factor authentication, role-based access control, joiner/mover/leaver processes - Stand up and run a rapid-response vulnerability operations capability with clear service levels and tight SecOps/engineering integration - Face off directly with executives, product leaders, and engineering leadership; articulate risk, trade-offs, and investment cases - Deliver security enablement and security champions programmes so engineering teams move quickly without security bottlenecks - Act as senior escalation point for product and identity security issues, including high-severity incidents - Recruit, onboard, and build technical capability across the team through mentoring and structured upskilling - Own performance management: feedback, development plans, and managing underperformance - Define and report metrics demonstrating programme effectiveness: vulnerability ageing, remediation rates, secure design review coverage, enablement reach Requirements: - At least 10 years of overall cybersecurity experience, including at least 5 years in a comparable leadership role (ideally in a technology company or fintech) - Background as a hands-on security engineer, ideally including application and/or mobile penetration testing, with appetite to remain technical as a player-manager - Strong knowledge of AI, agentic security, and ML, with a clear point of view on securing them in production - Strong grasp of threat modelling and ability to articulate risk credibly to both engineering and non-technical audiences - Proven track record of delivering successful security enablement and security champions programmes - Highly organized with ability to operationalize a programme and define strategy in conjunction with the CISO - Strong stakeholder management skills and confidence to face off to executives directly - Experience leading distributed teams across multiple countries and time zones - Excellent spoken and written communication skills Nice to Have: - Experience with identity providers (IdPs), privileged access management (PAM), and broader IAM tooling (Okta, Ping, ConductorOne, or equivalents) - Experience standing up a rapid-response vulnerability operations or remediation operations function and integrating it with SecOps

Similar roles