Job description

Business: Cybersecurity

Open positions: 1
Recruiter Name :  Veronica Zhong


Why join us?

The HSBC Cryptography team manage the encryption technology and key material which protects, validates and assures critical functions and billions of pounds worth of transactions across the organization.
Dynamic and varying demands on the cryptography team mean an interface to IT and the broader business is necessary. 

   


The Opportunity: 

The Cryptography Operations team directly impact the business by implementing the cryptographic solutions required to a standard in line with the business’ risk appetite. This role involves managing the cryptographic hardware and related software used in cryptography and its configuration, crypto-load and installation into data centres and/or external hosting environment.


What you’ll do: 

• Develop applicable knowledge objects, procedures and secondary standards to support agreed upon SLA or project deliverables.

• Maintain and enhance the delivery of cryptographic technology, process and relevant controls.

• Ensure crypto related inventory controls (key and HSM) are maintained.

• Implement and operate effectiveness of cryptographic controls.  Contribute to the risk reduction, escalation and reporting. Support the remediation of risk

items.

• Provide guidance and consultation in new crypto technology, process and control.

• Support the KCI/KPI metric and reporting.

• Report progress and identify and raise any issues/risks, escalating as appropriate to enable satisfactory resolution.

• Build trusting relationships with stakeholders by consistently meeting and delivering upon their business needs; demonstrating and being respected for

your domain knowledge.

• Deliver fair outcomes for our customers and ensure own conduct maintains the orderly and transparent operation of financial markets.

Those stakeholders include:

a. Supplier management analysts

b. Project managers from IT or the business

c. Management of Crypto Operation and Cybersecurity

• Support peers around the world who deliver and maintain the bank’s encryption technology and the projects consuming the services by understanding

their needs and delivering to them.

• Ensuring that work happens according to schedule and with minimal deviation from process.

• Ensuring that best practices are implemented and help the organisation meet its own and external standards.

• Develop and contribute in crypto knowledge objects, procedures, and standard review.

• Act transparently in line with all appropriate standards.

• Ensure that the appropriate internal and external standards are complied with and that the risk of cryptographic compromise is minimized at all times.

• Liaise with the cryptography team’s internal control function.

• Design, implement and maintain internal controls regarding crypto infrastructure and key management.

• Plan and execute on project to improve the operational effectiveness and sustainability via automation and tooling.

Requirements

What you will need to succeed in the role:

• Experienced Operational Cryptography background

• Hardware Security Module expertise with hands on experience including payments, general purpose, and Cloud HSM’s.

• Good understanding on IT Infrastructure technical platforms / technologies

• Experience on project prioritization and balance needs of various key stakeholders

• Operational effectiveness - delivers solutions that align to approved design patterns and security, risk and regulatory standards

• Mindset to follow defined procedure and following the cryptography compliance process

• Customer/stakeholder focus. Ability to build strong relationships with Internal/External Key stakeholders, cross functional IT and global/local IT teams

• Ability to work out of office hours

• Awareness of risk management

• Excellent communication skill (Chinese and English)

• Knowledge of Service management techniques including incident, problem, change, release management

• Knowledge of HSM and China local manufactured signature servers/security front end server/SSL gateways.

• Good working knowledge of Linux platforms and basic knowledge of network infrastructure.

• Knowledge of Agile tools, such as JIRA, Confluence and other related tools etc.

• End to End experience of Service Now -based application design and implementation

What additional skills will be good to have?

• Background understanding in crypto technologies applicable to financial service, cloud security, data security, internet and cyber security.  
• Prefer PCI QSA, CISA/CISM, CISSP, ITIL or relevant college education.
• Working knowledge in industrial standard hardware based encryption a plus.
• Working knowledge in Internal Control. Cyber Security, Compliance a plus.  
• Working knowledge in collaboration technologies such as Atlassian JIRA, Confluence, MS Team, Sharepoint is necessary.  
• Prior experiences in development, IT services management and system administration a plus.

    Link to Candidate User Guide: 
    https://hsbchrdirect.service-now.com/esc?id=kb_article&table=kb_knowledge&sysparm_article=KB0171506&sys_kb_id=9991a4861bc399d4517b10e3b24bcbc8

    You’ll achieve more at HSBC

    HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.” 

    Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website. 

    * The information contained in this job description is a true and accurate reflection of the job as specified.

    Nom du recruteur
    Xiao Yu Zhong
    E-mail du recruteur
    veronica.x.y.zhong@hsbc.com.cn