VP of IT and Cybersecurity

The Tidal Financial Group is a leading ETF investment technology platform dedicated to creating, operating, and growing ETFs. We combine expertise and innovative partnership approaches to offer comprehensive, value-generating ETF solutions. 

 

Our platform offers best-in-class strategic guidance, product planning, trust and fund services, legal support, operations support, marketing and research, and sales and distribution services.

About the role

The VP, IT & Cybersecurity owns Tidal Financial Group’s enterprise IT and cybersecurity strategy, operating model, and execution. This leader is accountable for the company’s technology reliability, security posture, operational resilience, and IT service experience—establishing departmental direction and advising executive leadership on technology risk, investment priorities, and business-enablement opportunities.

What you'll do

People leadership & operating cadence

  • Lead, coach, and develop the IT and Cyber teams; set clear goals, expectations, and performance standards.
  • Design and evolve the IT and Cybersecurity organization as Tidal scales, including workforce planning, leadership development, succession planning, and appropriate use of strategic partners.
  • Establish clear decision rights and accountability across managers, internal teams, MSPs, and MSSPs, reducing dependency on SVP involvement in routine operations.
  • Establish a weekly operating rhythm (intake, prioritization, escalations, metrics review, and leadership updates).
  • Build a culture of customer service, documentation, ownership, and continuous improvement.

IT service delivery & reliability

  • Own IT service management processes: ticket triage, SLAs, escalation paths, and end-user communications.
  • Ensure stable operation of core business platforms (Microsoft 365, identity, endpoint management, collaboration, file services, key SaaS applications).
  • Drive standardization of onboarding/offboarding, device lifecycle, patching, and asset management.

Cybersecurity strategy, governance, and execution

  • Define and own Tidal’s multi-year cybersecurity strategy, target maturity, control framework, and investment roadmap aligned with company growth and risk objectives.
  • Establish enterprise security policies and standards across endpoint protection, identity and access, monitoring, vulnerability management, data protection, and incident response.
  • Enforce least privilege, RBAC, and zero-trust practices across systems and vendor access.
  • Lead technology and cybersecurity decision-making during material incidents, including executive communication, containment priorities, recovery tradeoffs, and post-incident accountability.
  • Maintain and test incident response runbooks; coordinate tabletop exercises and post-incident reviews.

Risk management, compliance, and audit readiness

  • Maintain evidence and control operation for SOC 2 / vendor due diligence / regulatory expectations (as applicable).
  • Partner with business owners to close control gaps, remediate findings, and track risk exceptions; recommend or approve risk acceptance within defined authority and escalate material risks with clear options and recommendations.
  • Ensure third-party risk processes are followed for new vendors and renewals.

Vendor, MSP/MSSP, and budget management

  • Own the departmental budget, workforce plan, vendor portfolio, and sourcing strategy, balancing security, reliability, service quality, and cost.
  • Manage relationships with key vendors, MSPs, and security service providers; drive accountability on outcomes, deliverables, and SLAs.
  • Lead forecasting, renewal planning, licensing optimization, and procurement in partnership with Operations and Finance.

Department strategy and executive leadership

  • Define and own Tidal’s multi-year IT and Cybersecurity strategy, target operating model, annual priorities, and investment roadmap aligned with company objectives.
  • Make high-impact prioritization and investment decisions across security, reliability, cost, operational risk, and business speed.
  • Advise executive leadership on technology risk, operational resilience, material incidents, investment priorities, and risk-acceptance decisions.
  • Establish enterprise standards and decision frameworks for identity, endpoints, infrastructure, collaboration platforms, security controls, third-party access, and technology lifecycle management.
  • Represent IT and Cybersecurity in executive, audit, board, client, and strategic partner discussions as appropriate.
  • Translate strategic priorities into quarterly operating plans and provide decision-grade reporting on performance, incidents, risks, investments, and roadmap progress.

Metrics of success (examples)

  • Executive alignment on a multi-year IT and cybersecurity strategy, target operating model, and investment roadmap.
  • Measurable reduction in enterprise technology and cybersecurity risk, with timely closure or formal acceptance of material findings.
  • Ticket SLA attainment and CSAT; reduction in repeat/recurring incidents.
  • Endpoint compliance and patch timeliness; MFA/conditional access coverage.
  • Time-to-contain and recover from security incidents; completion of incident response exercises.
  • Resilience and recovery readiness for critical business services.
  • Audit/control evidence completeness, on-time delivery, and quality of audit outcomes.
  • Budget performance, licensing optimization, and measurable vendor value.
  • Stronger leadership bench, succession readiness, and reduced dependency on SVP involvement in day-to-day operations.
  • Documentation coverage for critical systems and processes.

Qualifications

  • 12+ years in IT operations, cybersecurity, infrastructure, identity, or related technology leadership roles with progressively broader scope.
  • 5+ years leading teams and leaders, preferably across both internal teams and strategic service providers.
  • Demonstrated ownership of departmental strategy, budgets, organizational design, executive risk decisions, and material technology or cybersecurity incidents.
  • Strong experience with Microsoft 365/Entra ID, endpoint management (e.g., JumpCloud/Rippling/MDM), identity standards (SSO/SAML/OIDC/SCIM), and SaaS administration.
  • Working knowledge of modern security controls: endpoint protection, vulnerability management, logging/monitoring, IAM governance, and incident response.
  • Demonstrated ability to communicate clearly to non-technical stakeholders and executives.

Preferred qualifications

  • Experience supporting SOC 2, ISO 27001, or similar assurance programs.
  • Familiarity with financial services operational risk and vendor due diligence.
  • Experience managing MSP/MSSP relationships.

Operations and Technology

Remote (United States)

Deel met:

Algemene voorwaardenPrivacyCookiesPowered by Rippling