Back to ByteDance jobs
B
Chief Information Security Officer
London
RegularCorporate Function / SupportJob Description
Team Introduction The Global Payment team of ByteDance provides payment solutions - including payment acquisitions, disbursements, transaction monitoring, payment method management, foreign exchange conversion, accounting, reconciliations, and so on to ensure that our users have a smooth and secure payment experience on ByteDance platforms including TikTok.
Responsibilities:
- Own IT service management and operations for systems supporting e-money issuance, payment services, safeguarding, customer servicing, finance, and regulatory reporting;
- Implement and maintain IT governance, risk, and control frameworks proportionate to the business, covering infrastructure, access, change, backup/recovery, monitoring, and vulnerability remediation; support risk assessments, control attestations, and governance reporting for senior management and committees;
- Partner with Information Security and business stakeholders to embed security controls across IAM, privileged access, endpoints, logging, patching, encryption, and backup protection;
- lead operational resilience, BCP, and DR arrangements, including asset mapping, failover testing, single-point-of-failure identification, and remediation;
- Oversee change management and systems delivery, ensuring all IT changes are assessed, approved, tested, and documented; manage outsourcing and third-party technology arrangements, monitoring service performance, security, control reports, concentration risk, and contractual obligations for critical providers;
- Serve as the key IT operational contact for audits, regulatory reviews, and major incident escalation; coordinate evidence collection, regulatory reporting, and senior management reporting on IT performance and risks; set objectives and performance standards for managed service partners and ensure adequate staffing, skills coverage, and training.
This role will be based onsite at our office and will require a 5-day onsite work arrangement.
Qualifications Minimum Qualification(s):
- Bachelor's degree in Information Technology, Computer Science, Information Security, Engineering, or a related discipline (or equivalent professional experience);
- 5+ years of relevant experience in IT operations, infrastructure, service management, or technology risk & control roles;
- Experience in a regulated financial services firm — preferably an EMI, payment institution, bank, fintech, or other FCA-regulated environment;
- Experience supporting governance forums, management reporting, and cross-functional remediation programmes;
- Proficient in both English and Chinese to facilitate effective communication and collaboration with Chinese-speaking stakeholders across the business.
Preferred Qualification(s):
- Relevant certifications such as ITIL, ISO 27001, COBIT, CISSP, CISM, CRISC, or cloud platform certifications are preferred.