Head of IT

EmbankmentCopenhagenthehubpublished 09/28/2026
Must-have:AISecuritySeniorLead
Nice-to-have:Google Cloud

About Embankment Fund operations still run on manual processes, spreadsheets, fragmented systems and a great deal of human coordination. Embankment is a tech-enabled fund administrator replacing that with software and increasingly autonomous systems. We are Series A funded, regulated in Denmark and Luxembourg, and we work with institutional investors and fund managers who expect us to run a tight ship internally as well as for them. We are now hiring our first Head of IT.

The role You own internal IT at Embankment end to end: Identity and access in Entra ID, Microsoft 365, our Intune-managed Mac and Windows fleet, network and office IT, SaaS and licences, onboarding and off-boarding, and vendors. You work closely with our IT compliance function and report to the CTO. IT is part of our tech organisation, alongside engineering and product. Until now it has been handled by the engineers as one responsibility among many. We have grown to the point where it deserves a dedicated owner, and a regulated business that goes through client due diligence and regulatory inspections needs one. Much of the job is judgement. Small requests, incidents, security gaps and compliance findings arrive together, and you decide what gets fixed now, what gets fixed properly, and what gets logged and weighed against everything else later. You're hands-on. There's nobody to hand the laptop to on day one, and we expect you to like that. You're also expected to build the function: the processes and, increasingly, the agents that let a small team run IT for a growing regulated company.

What you will do Run IT so nobody has to think about it: A new hire has a working laptop and the right access on their first morning, access requests are handled the same day, and off-boarding is complete and evidenced the day someone leaves. Meeting rooms, printers and Wi-Fi works

Own and harden our Microsoft tenant: Entra ID, Conditional Access, privileged access, device compliance in Intune, managed applications, Defender, Purview and the rest of Microsoft 365. You set a security baseline (Secure Score, CIS or your own), close the gaps in priority order and keep configuration from drifting back.

Build agents that do IT work: Our agents already build and support our software; you extend them to everyday IT support and tenant hardening, with every change approved and logged, and you stay accountable for what they do.

Make the estate meet our controls: Our IT compliance function defines what DORA, ISO 27001, our AI governance framework (ISO 42001) and other regulatory frameworks we are subject to requires of us, and translates auditors and client due diligence requests into necessary evidence and controls. You make sure the IT estate meets it, and you decide how remediation is prioritised against everything else IT has to do.

Manage the estate and the money: SaaS inventory, licences, hardware lifecycle, vendors and contracts. Know what we pay for, who uses it and what we can switch off.

Shape the function: IT is a small team today, but over time, and with projected growth, you’ll decide what it should look like and who it needs.

What we are looking for As an IT Manager or Senior IT Lead in a scale-up or a larger company, you've been through growth, an audit or a regulatory process there. You know what good looks like at 200 people and can build towards it without imposing it on day one.

You know your way around Entra ID, Intune and Microsoft 365, because that is where our identity and devices live, but you are a generalist at heart. You would rather script than click, in PowerShell when Microsoft leaves no choice and in whatever fits elsewhere.

You fix small things small. You can tell an incident from a project from a compliance finding, and you treat them differently. You're fine parking a known imperfection with a note in the backlog and moving on.

You're hands-on and want to stay that way. You may be ready to run the function, but you have no wish to stop doing the work.

You use agents every day and have opinions about them. You want to build agents that provision, audit and remediate under your oversight, and you take responsibility for what they do, the same as if you'd done it yourself.

You communicate plainly, whether it is a new colleague who can't log in, an auditor who wants evidence or leadership who want a one-line answer.

Nice to have: experience with DORA, ISO 27001, ISO 42001 or ISAE 3000, a background in financial services or another regulated industry, familiarity with GCP. Danish is not required; our working language is English.

How we work We move fast and we're ambitious about what a small team can do with good tooling and agents. In return we're flexible about how and where the work gets done, within what a regulated business and an on-site IT function allow. We measure ourselves on delivery cadence and on real-world impact. Output matters. Impact matters more.

What we offer A function that is yours to build, with the mandate and budget to match

Agents and automation as part of the day job

Flexible working hours

Pension plan

Central Copenhagen office close to public transport

Skill development, including certifications

Social gatherings and colleagues who like each other