ome careers shine brighter than others.
If you’re looking for a career that will help you stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.
HSBC is one of the largest banking and financial services organisations in the world, with operations in 64 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realise their ambitions.
Our Technology teams work closely with HSBC’s global businesses to help design and build digital services that allow our millions of customers around the world; to bank quickly, simply and securely. We also run and manage our IT infrastructure, data centres and core banking systems that power the world’s leading international bank.
Our multi-disciplined Technology teams include amongst others: DevSecOps engineers, IT architects, front and back-end developers, infrastructure specialists, cybersecurity experts, and delivery, project and programme managers.
Following extensive investment across our Technology and Digital domains and with plans for continued expansion, we are seeking a Lead Consultant for “Threat and Controls Assessment”, to join the HSBC Cybersecurity team within Technology.
.
Brief overview of the business areas
Global Cybersecurity is responsible for enabling businesses and functions to manage their information, technology and cybersecurity risks by ensuring these are well-understood, and that controls used the manage such events are defined, assessed and implemented appropriately. Cybersecurity deliver this via objective, independent, professional and specialized subject matter experts. The role forms part of the 1LoD in relation to risk management framework.
The Cybersecurity Assessment and Testing (CSAT) function, part of Global Cybersecurity, is accountable for Vulnerability Management, Secure Development, Threat and Controls Assessment (threat modelling) and Third Party Security Assessment. The function drives the identification, capture, assessment, testing and ultimately the remediation of security defects, gaps and vulnerabilities across HSBC’s estate in concert with business and technology teams – on premise, within the Cloud and resulting from 3rd party engagements.
What you will be doing;
The Threat and Controls Assessment Lead Consultant role will work as part of the global team to perform Threat Modelling on HSBC services.
This is a senior role reporting into the Threats and Controls Assessment Regional Lead, closely collaborating with peers across Penetration Testing; Secure Development, Third Party Security Assessment and Cybersecurity business and regional leads, enabling effective end-to-end vulnerability identification.
Key Responsibilities:
· Perform effective threat and control assessments for complex services and platforms across the HSBC estate. This will include cloud platform reviews for Azure, AWS and GCP
· Liaise with Developers, Architects and other Technical Leads to understand the end to end service and identify where there are any control gaps
· Work with the CSAT management team to enhance the Threats and Controls Assessment Service.
· Provide cybersecurity consultancy with HSBC Business and Functions
· Manage the team of resources and take responsibility that their deliveries are meeting the quality expectations.
· Stay up to date within the industry of new trends and best practices
· Provide supervision, guidance and mentor less experienced members of the global team
· Act as a point of contact and source of advice on issues relating to Cybersecurity within the team
What you will bring to the role;
To be successful in this role you should have proven experience within the Technology sector with knowledge of the following skills:
Mindset
· An inquisitive approach, always asking how to achieve goals in a smarter and more effective way
· An ability and interest to learn and experiment with new approaches to vulnerability management, in different contexts, across the amazing scale that HSBC brings.
· Stay up to date within the industry of new trends, and best practices
Good Risk and Controls understanding
· Knowledge and exposure of Risk and Control Management
· Ability to understand and assess both threats, controls and vulnerabilities, articulating these to both technical and business stakeholders.
· Knowledge of different frameworks and methodologies including Threat Modelling using STRIDE and the MITRE ATT&CK Framework.
· Desirable to have one or more industry-recognised cybersecurity-related certifications including CISSP, CRISC, CISM or Cloud Security Certifications
Strong Technical background
· Expert hands on knowledge in one or more of the main Cloud Service Providers – Azure, AWS or GCP
· Proven experience in general security concepts and principles and application specific security concepts and principles.
· Proven experience working in a large scale, multi-national and technologically diverse environment
· Hands on experience with threat modelling and strong technical understanding and experience of assessing vulnerabilities and identifying weaknesses in diverse enterprise IT assets
- Strong understanding of applications design and architecture
- Strong understanding of Software Development Life Cycle (SDLC) with a focus on security
- Knowledge and experience with network, host and application security practices
· Understanding of emerging technologies and corresponding security threats
Strong stakeholder management and communications skills
· Experience of working in international and diverse environments
· Experience in engaging with business, technology, regional and regulator stakeholders
· Ability to communicate to executive leadership – effectively translating technical gaps into business risk
· Ability to prepare concise presentations and updates for senior management
· Ability to support hiring activities, manage the team of resources
Interpersonal Skills
· Influential, credible and persuasive, active listener, embraces HSBC Values, shows good judgement and demonstrates high level of communication skills in order to achieve effective stakeholder management
Some travel will be required – expected once to twice a year.
Come Power a Business that Defines How to Power the World
As a business operating in markets all around the world, we believe diversity brings benefits for our customers, our business and our people. This is why HSBC is committed to being an inclusive employer and encourages applications from all suitably qualified applicants irrespective of background, circumstances, age, disability, gender identity, ethnicity, religion or belief and sexual orientation.
We want everyone to be able to fulfil their potential which is why we provide a range of flexible working arrangements and family friendly policies.
As an HSBC employee, you will have access to tailored professional development opportunities and a competitive pay and benefits package.
You’ll achieve more when you join HSBC.
HSBC is committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and opportunities to grow within an inclusive and diverse environment. Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
Issued by – HSBC Software Development India