Head of Information Security, Netherlands in London

Head of Information Security, Netherlands in London

London Full-Time 80000 - 100000 € / year (est.) No home office possible
Ant Group

At a Glance

  • Tasks: Lead and oversee Information Security strategies and compliance in a dynamic financial services environment.
  • Company: Join Ant International, a leader in digital payment solutions and innovation.
  • Benefits: Competitive salary, flexible working options, and opportunities for professional growth.
  • Other info: Collaborative culture focused on driving responsible innovation and market accessibility.
  • Why this job: Make a significant impact on global commerce while enhancing security frameworks.
  • Qualifications: 8+ years in ICT risk or cybersecurity with strong regulatory experience.

The predicted salary is between 80000 - 100000 € per year.

Ant International powers the future of global commerce with digital innovation for everyone and every business to thrive. In close collaboration with partners, we support merchants of all sizes worldwide to realise their growth aspirations through a comprehensive range of tech-driven digital payment and financial services solutions. With a focus on Travel, Trade, Technology, and Talent, Ant International is committed to enhancing the digital mindset and capacities of businesses worldwide. Through fostering collaborative efforts with partners, we are driving responsible innovation and increasing market accessibility for global SMEs.

What you will be doing:

  • Governance & Strategy: Develop, maintain, and oversee the Information Security and ICT Risk Management Frameworks in line with DORA, ISO 27001, NIST, and other applicable standards. Establish, maintain, and enforce security policies, standards, and procedures. Provide independent second-line challenge to first-line controls and risk management activities. Report on security posture to the Board and leadership team.
  • Regulatory Compliance & Engagement: Ensure full compliance with DORA (ICT risk management, incident reporting, resilience testing, third-party risk), PSD2-SCA, PCI-DSS, SWIFT CSP, GDPR (as it relates to ICT), and EBA guidelines. Act as the primary liaison for DNB, EBA, and other regulators; manage regulatory inquiries, audits, inspections, and reporting obligations.
  • Incident & Access Management: Own and manage end-to-end response to security incidents and data breaches, including coordination, escalation, investigation, containment, and regulatory reporting in line with DORA and GDPR. Oversee access control governance, including user provisioning, privileged access, and periodic access reviews. Manage KMS and (CBD) security practices in accordance with internal policies and regulatory expectations.
  • Third-Party & Outsourced Security Oversight: Maintain ownership of all outsourced security activities (e.g., SOC, penetration testing providers), ensuring service quality, SLA adherence, and alignment with security and compliance requirements. Manage the ICT third-party risk lifecycle, including due diligence, ongoing monitoring, and maintenance of the DORA register of critical ICT third-party providers.
  • Risk, Resilience & Assurance: Identify, assess, prioritise, and report ICT and cyber risks; define key risk indicators and present risk posture to the Board and Risk Committees. Oversee digital operational resilience testing (including threat-led penetration testing) and disaster recovery from an ICT perspective. Monitor the governance and technical effectiveness of cybersecurity controls (SIEM, EDR, DLP, IAM, vulnerability management, and data security) and track remediation of audit and assessment findings.
  • Culture, Collaboration & Stakeholder Engagement: Deliver security awareness programmes and foster a security-conscious culture. Advise the local entity Board, senior management, and technology teams on risk posture, outsourcing, and major technology changes. Collaborate with and provide subject-matter expertise to the EMEA Information Security team on regional projects and BAU activities.

What we are looking for:

  • 8+ years’ experience in ICT risk, cybersecurity governance, or audit within financial services.
  • Proven experience implementing DORA and engaging with DNB or comparable EU regulators.
  • Strong technical foundation in cloud security, IT infrastructure, application security, and cyber threats.
  • Strong knowledge of cloud security controls, SIEM, EDR, DLP, IAM, and security architecture.
  • Awareness of AI security risks and controls.
  • Experience in incident response and third-party security management.
  • Ability to influence stakeholders, present to Boards and regulators, and operate independently in a second-line role.
  • Fluent in English and Dutch.
  • Demonstrated ability to lead complex security compliance, incident response, and security initiatives in regulated environments.

Head of Information Security, Netherlands in London employer: Ant Group

Ant International is an exceptional employer, offering a dynamic work environment in the Netherlands that champions innovation and collaboration. With a strong commitment to employee growth, we provide extensive training opportunities and foster a culture of security awareness, ensuring our team members are equipped to thrive in the fast-evolving digital landscape. Join us to be part of a forward-thinking organisation that values your contributions and supports your professional journey in the realm of information security.

Ant Group

Contact Detail:

Ant Group Recruiting Team

StudySmarter Expert Advice🤫

We think this is how you could land Head of Information Security, Netherlands in London

Tip Number 1

Network like a pro! Get out there and connect with folks in the industry. Attend meetups, webinars, or conferences related to information security. You never know who might have the inside scoop on job openings or can put in a good word for you.

Tip Number 2

Show off your expertise! Create a personal blog or LinkedIn posts where you share insights on cybersecurity trends, DORA compliance, or incident response strategies. This not only showcases your knowledge but also helps you stand out to potential employers.

Tip Number 3

Don’t just apply blindly! Tailor your approach for each company. Research Ant International’s values and recent projects, then highlight how your experience aligns with their goals. A personalised touch can make all the difference.

Tip Number 4

Apply through our website! We’ve got a streamlined process that makes it easy for you to showcase your skills. Plus, it shows you’re genuinely interested in joining our team at Ant International. Let’s get you that dream job!

We think you need these skills to ace Head of Information Security, Netherlands in London

Governance & Strategy
Information Security Frameworks
DORA Compliance
ISO 27001
NIST Standards
Regulatory Compliance
Incident Response Management

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Head of Information Security role. Highlight your experience in ICT risk and cybersecurity governance, especially any work with DORA or EU regulators. We want to see how your skills align with our needs!

Craft a Compelling Cover Letter:Your cover letter is your chance to shine! Use it to explain why you're passionate about information security and how your background makes you the perfect fit for us. Don’t forget to mention your experience with cloud security and incident response.

Showcase Your Achievements:When detailing your experience, focus on specific achievements rather than just responsibilities. Did you lead a successful incident response? Share the results! We love seeing how you've made an impact in previous roles.

Apply Through Our Website:We encourage you to apply directly through our website. It’s the best way for us to receive your application and ensures you’re considered for the role. Plus, it shows you’re keen on joining our team!

How to prepare for a job interview at Ant Group

Know Your Frameworks

Make sure you’re well-versed in DORA, ISO 27001, and NIST standards. Brush up on how these frameworks apply to the role and be ready to discuss your experience with them. This will show that you understand the regulatory landscape and can navigate it effectively.

Showcase Your Incident Management Skills

Prepare specific examples of past incidents you've managed, focusing on your response strategies and outcomes. Highlight your ability to coordinate investigations and communicate with stakeholders during crises. This will demonstrate your hands-on experience and leadership in high-pressure situations.

Engage with Regulatory Knowledge

Familiarise yourself with the latest developments in regulations like GDPR and PCI-DSS. Be prepared to discuss how you’ve engaged with regulators in the past and how you would approach compliance in this role. This shows you’re proactive and knowledgeable about the regulatory environment.

Cultivate a Security Culture Mindset

Think about ways you’ve fostered a security-conscious culture in previous roles. Be ready to share ideas on how to implement security awareness programmes and engage with teams across the organisation. This will highlight your collaborative spirit and commitment to building a strong security culture.