Under the management of the Head of Global Cybersecurity Operations (GCO), the Cybersecurity Operations team are responsible for providing a coordinated suite of security focussed defence services and capabilities designed to monitor, detect, respond and mitigate information and cyber-security threats to HSBC global assets and businesses. This responsibility includes dedicated functions for the monitoring and detection of threats within the global estate as well as cybersecurity incident management and response activities. These two principal functions are supported by additional internal GCO capabilities in; Cyber Intelligence and Threat Analysis, Cybersecurity Sciences and Client Engagement and Support Services. Critical to the success of GCO is its close partnerships and collaborative working practices across all Cybersecurity teams, IT Infrastructure Delivery, and Global Business and Function clients. The overall GCO mission is placed under the purview of the Group Chief Information Security Officer (CISO).
The Cybersecurity Operations Manager is charged with the management of all globally aligned, security focussed defence services within a specific operational site. This includes the overall efficiency and effectiveness of the site, the detection, management and response to global information and cybersecurity incidents during active hours of operation and the complete handover of duties from the previous site and to the next as part of a 24/7 global capability.
The Cybersecurity Operations Manager is accountable for:
- Leading a team of 8-20 highly skilled security professionals, providing a global service supporting the response to cyber security threats.
- Developing, managing and maintaining a highly skilled, efficient and effective local team across all Cybersecurity Operations service lines. Including the definition, management and continuous improvement of core functions and processes that underpin a successful, effective and globally scaled monitoring, alerting and security incident response capability.
- Maintaining an up to date awareness and intelligence-led understanding of the current and predicted threat landscape so that impact to HSBC businesses or services can be anticipated and where possible, pre-emptive monitoring, alerting and response capabilities can be deployed.
- Owning and managing collaboration with the wider Cybersecurity (and IT) teams to ensure that the core, underlying technological capabilities that underpin an effective and efficient operational response to current and anticipated threats and trends remain fit for purpose
- Identification of processes that can be automated and orchestrated to ensure maximum efficiency of global Cybersecurity Operations resources.
- Ensuring analysis time is efficiently focused on the more challenging and potentially higher risk problems and tasks, not on high-volume/low risk, repetitive tasks or processes, thus helping to effectively reduce false positive and false negative events.
- Managing and owning the collaboration with the wider Cybersecurity teams (and wider business / function teams where applicable) in the production and maintenance of efficient and effective security event monitoring and alerting use-cases and incident response playbooks.
- Maintaining a global view of the GCO mission and work with local stakeholders in region and country to bring together both the global perspective, as well as the more local message in a clear and effective way that demonstrates the team’s commitment and value.
- Promoting a “self-critical” and continuous assessment and improvement culture, whereby identification of weaknesses in the bank’s control plane (people, process and technology) are brought to light and addressed in an effective and timely manner.
- Embedding a culture of individual self-improvement, development and self-directed learning whereby staff are expected to maintain subject matter expertise within their area of focus and within the realm of cyber security more broadly.
- Directed engagement in support of HSBC Global Businesses and Functions to drive a global up-lift in cyber-security awareness and help to evangelise HSBC Cybersecurity efforts and success.
- Participation in the GCO Leadership Team ensuring that the voice of Cybersecurity Operations staff is heard, concerns are raised and addressed and the function continues to evolve at pace with the threat landscape and business requirements.
- Identification and development of high quality and meaningful cyber security related Management Information (MI) that is data driven, contextual, appropriate to the target audience and supported by experienced analysis in order to drive informed debate and decision making.
Engagement within the Lines of Defence Risk Management framework adopted by HSBC to ensure complete transparency and effective working relationship across all lines of defence.
Skills
- Excellent understanding of HSBC cyber security principles, global financial services business models, regional compliance regulations and laws.
INTERNAL - Excellent understanding and knowledge of common industry cyber security frameworks, standards and methodologies, including; OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines, CIS and NIST standards.
- Proven ability and experience of working in a high-pressure, fast paced environment where bold, time critical decision making is essential.
- Proven experience in identifying and responding to advanced attacker methodologies both within the corporate environment as well as external attack infrastructures, ideally with offensive experience and / or deception environment development (tripwire systems, honeypots, honey-token/accounts, etc.) using open source, vendor purchased and bespoke/in-house developed solutions.
- Excellent communication and interpersonal skills with the ability to produce clear and concise reports for targeted audiences across internal and external stakeholders.
- Solid understanding of business finance as well as effective management of budgets and expenditures.
- Experience in a leadership position within a cyber-security operations team to include team and capability development, staff development, career management and recruitment.
- Ability to orchestrate, manage and successfully implement major procedural and technological change within a complex and global organisation
Technical Skills- Expert level knowledge and demonstrated experience of common intelligence sharing platforms / protocols and experience operating within a collective defence environment with internal stakeholders and external partners.
- Expert level knowledge of common enterprise technology infrastructure, platforms and tooling, including; Windows, Linux, infrastructure management and networking hardware.
- Expert level knowledge of intelligence analysis principles either though formal education / training or equivalent professional experience.
- Expert level knowledge and demonstrated experience in analysis and dissection of advanced attacker tactics, techniques and procedures in order to inform adjustments to the control plane.
- Expert level knowledge of scripting, programming and/or development of bespoke tooling or solutions to solve unique problems.
- Ability to identify, develop and track key performance indicator (KPI) metrics for accurate and contextual evaluation of operational effectiveness as well as providing recommendations for control improvement and mitigating control adjustments.
- Expert knowledge and technical experience of 3rd party cloud computing platforms such as AWS, Azure and Google.
Industry Experience and Qualifications - Industry recognised cyber security related certifications including; CEH, EnCE, SANS, CISSP, CISM, CRISC and/or CISA.
- Formal education and advanced degree in Information Security, Cyber security, Computer Science or similar and/or commensurate demonstrated work experience in the same.
- Experience in a technical authority or leadership position within an enterprise scale organisation; including hands-on experience of complex data centre environments.
- 8+ years of experience in Cyber security operations management, Cyber security management in a leadership position.
Due to the urgent hiring need, candidates with immediate right to work locally and no relocation need will be prioritised.
At HSBC we offer our colleagues a greater number of leave days so that they can fully enjoy their wedding, take care of the new member of the family, or grieve the loss of a family member. Our paid leave package is at the forefront in Mexico, now you have one more reason to be HSBC and proudly live a culture of well-being, balance and care.
HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.
Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
***Issued By HSBC Electronic Data Process Mexico Private LTD***