Information Security Compliance Manager
Tide
Job Summary
As an Information Security Compliance Manager at Tide, you will be a seasoned professional with unrivalled expertise in the Indian regulatory landscape for financial institutions. You will manage regulatory requirements, confidently represent Tide to local regulators, and ensure compliance with mandatory security and data standards for Tide’s India operations. Core responsibilities include acting as the primary regulatory liaison, owning compliance with Indian regulatory requirements (e.g., RBI Master Directions), defining local security standards, leading regulatory audits (RBI SAR), managing regulatory risk, and reporting to leadership and regulators. You will also proactively monitor regulatory developments and operate as part of the Second Line of Defence.
Must Have
- Act as the primary point of contact and representative for Tide Risk and Compliance when interacting with Indian financial regulators (e.g., RBI, CERT-IN) and key local partners on information security topics.
- Own and ensure Tide’s compliance with all applicable Indian regulatory requirements and guidelines related to information security (e.g., RBI Master Directions, Data Localisation requirements, Payment Security Standards).
- Act as a subject matter expert to define and enforce local information security standards specific to the Indian regulatory and operational environment.
- Lead and facilitate all regulatory-specific audits in India, including the RBI Systems Audit Report (SAR), Data Localisation audits, and any other mandated external assessments.
- Manage information security risk within the India context, specifically interpreting and applying Indian regulatory risk management requirements to Tide's operations.
- Prepare and present regular, comprehensive reports on security posture, risk status, and compliance efforts to Tide India Senior Leadership, key partners, and regulatory bodies as required.
- Proactively monitor the Indian financial sector for new or changing regulatory and compliance developments pertaining to information security and advising leadership on necessary preparations or changes.
- Operate as part of the Second Line of Defence (2LOD), providing independent oversight and challenge on the effectiveness of information security controls against Indian regulatory mandates.
- 7+ years experience in information security risk and compliance, with a heavy focus on the Indian financial sector.
- Mandatory, demonstrable experience interacting with financial regulators and government agencies in India (RBI, CERT-IN).
- In-depth, current knowledge of RBI Master Directions, data protection regulations (including PII/sensitive data handling), and payment security standards applicable to the Indian market.
- Proven experience in successfully managing and responding to regulatory audits, particularly the RBI SAR.
- Exceptional communication and presentation skills required for engaging with regulators and senior management.
Good to Have
- Relevant certifications such as CISM, CISA, or CRISC are strongly preferred.
Perks & Benefits
- Competitive salary and share options
- Generous annual leave on top of bank holidays
- Paid maternity, paternity, and adoption leave
- Extended unpaid and paid sabbatical options after completing milestone years with Tide
- Private family health insurance with additional OPD coverage and top-up options
- Comprehensive accidental and life insurance protection
- Access to therapy sessions, courses, meditations, and workshops for mental wellbeing
- Paid days annually for volunteering or personal growth
- Annual budget for books, courses, coaching, and more for learning and development
- Work from abroad for up to 90 days annually (WOO)
- Contribution towards setting up your home office
- Keep your old laptop and get a new one when it’s time for a replacement
- Office perks with snacks, coffee, tea, and lunch (location dependent)
Job Description
ABOUT TIDE
At Tide we help SMEs save time (and money) in the running of their businesses by not only offering business accounts and related banking services, but also a comprehensive set of highly usable and connected administrative solutions from invoicing to accounting.
Tide is transforming the small business banking market with over 1.6 million members globally across the UK, India, Germany and France. Using advanced technology, all solutions are designed with SMEs in mind. With quick onboarding, low fees and innovative features, we thrive on making data-driven decisions to help SMEs save both time and money.
Tide facts:
- Tide is available for UK, Indian, German and French SMEs
- Over 1.6 million members: 800,000 UK and 800,000 in India and growing rapidly
- Over $200 million raised in funding
- Over 2500 Tideans globally - we’re diversity champions!
- We have offices in Central London, with a member support and technology centre in Sofia, Bulgaria, technology centres in Serbia, Romania, Lithuania and Hyderabad and offices in Gurugram and New Delhi, India
ABOUT THE ROLE:
As an Information Security Compliance Manager, you will be a seasoned information security and risk professional with unrivalled expertise in the Indian regulatory landscape for financial institutions. You excel at managing regulatory requirements, confidently representing Tide to local regulators, and ensuring compliance with mandatory security and data standards for Tide’s India operations.
Core responsibilities will include:
- Primary Regulatory Liaison: Acting as the primary point of contact and representative for Tide Risk and Compliance when interacting with Indian financial regulators (e.g., RBI, CERT-IN) and key local partners on information security topics.
- Regulatory Compliance Ownership: Owning and ensuring Tide’s compliance with all applicable Indian regulatory requirements and guidelines related to information security (e.g., RBI Master Directions, Data Localisation requirements, Payment Security Standards).
- Local Standards Definition: Acting as a subject matter expert to define and enforce local information security standards specific to the Indian regulatory and operational environment.
- Audit Management (Regulatory): Leading and facilitating all regulatory-specific audits in India, including the RBI Systems Audit Report (SAR), Data Localisation audits, and any other mandated external assessments.
- Regulatory Risk Management: Managing information security risk within the India context, specifically interpreting and applying Indian regulatory risk management requirements to Tide's operations.
- Reporting to Regulators & Leadership: Preparing and presenting regular, comprehensive reports on security posture, risk status, and compliance efforts to Tide India Senior Leadership, key partners, and regulatory bodies as required.
- Regulatory Intelligence: Proactively monitoring the Indian financial sector for new or changing regulatory and compliance developments pertaining to information security and advising leadership on necessary preparations or changes.
- Second Line of Defence: Operating as part of the Second Line of Defence (2LOD), providing independent oversight and challenge on the effectiveness of information security controls against Indian regulatory mandates.
WHAT WE ARE LOOKING FOR:
- 7+ years experience in information security risk and compliance, with a heavy focus on the Indian financial sector.
- Mandatory, demonstrable experience interacting with financial regulators and government agencies in India (RBI, CERT-IN).
- In-depth, current knowledge of RBI Master Directions, data protection regulations (including PII/sensitive data handling), and payment security standards applicable to the Indian market.
- Proven experience in successfully managing and responding to regulatory audits, particularly the RBI SAR.
- Exceptional communication and presentation skills required for engaging with regulators and senior management.
- Relevant certifications such as CISM, CISA, or CRISC are strongly preferred.
WHAT YOU’LL GET IN RETURN:
Our location-specific employee benefits are designed to cater to the unique needs of Tideans:
- Competitive Compensation - competitive salary and share options
- Time Off – Generous annual leave on top of bank holidays.
- Parental Leave – Paid maternity, paternity, and adoption leave to support your family journey.
- Sabbatical – Extended unpaid and paid leave options after completing milestone years with Tide.
- Health Insurance – Private family insurance with additional OPD coverage and top-up options.
- Life & Accident Cover – Comprehensive accidental and life insurance protection.
- Mental Wellbeing – Access to therapy sessions, courses, meditations, and workshops.
- Volunteering & Development Days – Paid days annually for volunteering or personal growth.
- Learning & Development – Annual budget for books, courses, coaching, and more.
- WOO (Work Outside the Office) – Work from abroad for up to 90 days annually.
- Home Office Setup – Contribution towards setting up your home office
- Laptop Ownership – Keep your old laptop and get a new one when it’s time for a replacement.
- Snacks & Meals – Office perks with snacks, coffee, tea, and lunch (location dependent).
TIDE IS A PLACE FOR EVERYONE
At Tide, we believe that we can only succeed if we let our differences enrich our culture. Our Tideans come from a variety of backgrounds and experience levels. We consider everyone irrespective of their ethnicity, religion, sexual orientation, gender identity, family or parental status, national origin, veteran, neurodiversity or differently-abled status. We celebrate diversity in our workforce as a cornerstone of our success. Our commitment to a broad spectrum of ideas and backgrounds is what enables us to build products that resonate with our members’ diverse needs and lives.
We are One Team and foster a transparent and inclusive environment, where everyone’s voice is heard.
At Tide, we thrive on diversity, embracing various backgrounds and experiences. We welcome all individuals regardless of ethnicity, religion, sexual orientation, gender identity, or disability. Our inclusive culture is key to our success, helping us build products that meet our members' diverse needs. We are One Team, committed to transparency and ensuring everyone’s voice is heard.