Job description

Some careers have more impact than others. 

 If you’re looking for further opportunities to develop your career, take the next step in fulfilling your potential right here at HSBC. 

HSBC is one of the largest banking and financial services organizations in the world, with operations in 62 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realize their ambitions. 

We are currently seeking an experienced professional to join our team in the role of Global Head of Data Protection. 

Location: Pune / Hyderabad

Department Background:  

Our Cybersecurity team helps maintain a strong, secure technology and data infrastructure – using industry leading techniques, real-time data analytics and controls to enhance protection against cyber-attacks. 

The Opportunity: 

  • Our Technology teams work closely with HSBC’s Global Businesses to design, build and run digital services that allow millions of our customers around the world to bank quickly, simply and securely. We run and manage our Technology infrastructure, data centers and core banking systems that power the world’s leading international bank, with one of the largest technology estates in the industry. 
  • We are looking for a Cybersecurity leader to join us to shape our long-term strategy, and turbo-charge delivery, as the accountable owner for Data Protection across the bank. This senior role reports directly into the Global Head of Cyber Technology & Engineering. 

What you’ll do: 

  • Strategy: Define and maintain the capability strategy for Data Protection, supported by engineers, architects and multiple Control Owners, enabling business success, meeting regulatory expectation and best practice, whilst responding to current and likely threat actor evolution. A customer-centric and engineering-led approach includes: the use of machine-learning for data identification, pattern maturity, blended security tooling across assets and channels and related meta-policy and behavioral analytics.
  • Delivery: Own the investment roadmap for Data Protection and Data Security and its successful delivery across multiple partners. Ensure the transparent prioritization of a common backlog to drive risk reduction, simplification and wider strategic needs. Ensure risk-risk trade-offs are managed, particularly risk mitigation and operational needs.
  • Innovation: Empower HSBC to successfully navigate cyber risk with innovative, responsive and frictionless technologies and services, both those delivered in-house and from external partners. Foster and empower a culture of innovation, experimentation, and continuous improvement.
  • Partnership: Form close partnerships with engineering teams: as design partners – for how capabilities will be implemented and operated, at times in novel ways; as customers – understanding their needs as they consume data protection services or implement mandates, and as delivery partners prioritizing change within respective Cyber Engineering teams, and to drive bank-wide adoption of uplifts. Close and successful partnership with the Data Office and CTO teams is essential to maintaining robust proactive mechanisms. Partner with external technology providers and security specialists to integrate best practice and leverage or build cutting-edge tooling.
  • Services: ensure mature, consistent and high-quality centralized data protection consultancy and operations services are delivered in partnership with the service delivery team.
  • Oversight: Ensure Data Protection is overseen end-to-end, robustly and throughout the organization: from software development, federated control operation through to secure erasure. Drive a data-centric approach to observability and assessment, wherever possible supported by automation, measures and analytics.
  • Accountability: Ensure regulatory and risk management outcomes are being maintained or robustly managed. Ownership of High-Risk Audit, Regulator and self-identified issues. Ownership of the capability budget, balancing run and change investment. As a senior leader, contribute to and champion change across both Cybersecurity and Technology, occasionally outside of your primary remit.
  • Talent: Lead, manage, invest in, recruit and inspire a team of highly skilled and performant SMEs across the globe. A culture driven by empowerment, experimentation, learning, partnership and delivery. A place where colleagues thrive, solving meaningful problems that keep the bank and its customers safe. 
Requirements

What you will need to succeed in the role: 

  • Expert knowledge of data protection and data security including discovery techniques, information classification, data leakage and protection controls across human-centric channels inc. e-mail and collaboration tooling, privacy enhancing technologies inc. masking and tokenization, advanced threat actor methods is-use to exfil data, use of machine-learning in data protection and, layered control strategies for the protection of stored sensitive data among others. 

  • Strong data security practice & data protection using machine learning to enhance privacy, masking / tokenization, advanced threat methods. 

  • Should have cyber-security background and some bit of automation. 

  • Work closely with data engineering support team and will have a small team of 8 individuals. Good understanding of cyber security framework, standards and methodologies 

  • Robust understanding of common industry cyber security frameworks, standards, and methodologies, including PCI DSS, FFIEC guidelines, CIS and NIST standards. 

  • Strong analytical skills to identify and resolve complex problems, often with risk-risk trade-offs. 

  • Proven experience in technology leadership roles, running high performing technology teams and working in a large scale, multi-national and technologically diverse environments. 

  • Ability to engage with and influence senior peers and leadership. Managing, developing and retaining high-performing individuals in different geographies, often remotely. 

  • Proven ability to collaborate across industry, academia and government to solve complex problems. Ability to prepare concise presentations, reports and updates for senior management. 

  • Possess strong leadership skills to bring out the best in a team. This includes both direct leadership and cross-functional capabilities. 

  • Experience within fast-moving, complex and demanding corporate environments and able to provide appropriate direction to the team whilst dealing with ambiguity and change. 

  • Act as a role-model for more junior members of Cybersecurity and Technology. Knowledge and exposure of the application of Risk and Control Management and associated frameworks. 

  • Ability to articulate technical threats, scenarios, controls and risks to both technical and business stakeholders.  

  • Influential, credible and persuasive, active listener, embraces HSBC Values, shows good judgement and demonstrates high level of communication skills to achieve effective stakeholder management. 

  • An inquisitive approach, always asking how to achieve goals in a smarter and more effective way. 

  • An ability and interest to learn and experiment with new approaches to achieve business and cybersecurity outcomes, in different and often challenge contexts. 

  • A customer-centric approach, understanding how the balance between risk, control and business need can be transparently and robustly met, including via novel solutions. 

 You’ll achieve more when you join HSBC. 

HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role. 

 Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website. 

 

                                                             ***Issued By HSBC Technology (India) Private LTD***