CISO CTO Infrastructure
Role details
Job location
Tech stack
Job description
As Chief Information Security Officer for CTO Infrastructure you'll define and drive the security posture of HSBC's global technology infrastructure estate across cloud, on-premises data centres, network, identity, endpoint and operational technology. You'll operate at the intersection of the CTO and CISO organisations to protect a complex, globally distributed environment across more than 40 jurisdictions. The role is directly relevant to the bank's obligations under DORA, PRA/FCA supervisory expectations, NIS2 and emerging AI Act requirements. You'll represent the bank before UK, EU and US regulators on infrastructure security matters and serve on the Group Security Leadership Committee. You'll lead a globally distributed team of c.8-12 specialists and manage an operating budget typically in the range of $25-50M. Success means measurable improvement in infrastructure security resilience, strong regulatory outcomes and security embedded into the bank's technology transformation.
What you will be doing
- Own the multi-year infrastructure security strategy aligned to technology transformation, cloud migration and AI adoption
- Define and govern Zero Trust architecture standards across hybrid cloud and on-premises environments
- Lead security architecture review and approval for major infrastructure programmes including cloud platform, SD-WAN, core network refresh and OT modernisation
- Set and enforce multi-cloud security posture across AWS, Azure, GCP and private cloud including CSPM, CNAPP and cloud workload protection
- Establish secure-by-default configuration standards and IaC guardrails across compute, storage, networking and container platforms
- Own infrastructure-layer identity controls including PAM, machine identity and secrets management across management and control planes
- Strengthen detection, resilience and response for infrastructure-layer threats including exercises, TLPT scope and P1/P2 incident leadership
- Govern security risk across critical infrastructure suppliers including DORA-aligned third-party monitoring and concentration risk assessments
Requirements
- Demonstrated security leadership experience including senior director-level leadership in a Tier 1 global financial institution or equivalent regulated enterprise
- Deep technical grounding across infrastructure security including network, multi-cloud, identity and PAM, endpoint and OT/ICS security
- Show accountability for a significant infrastructure security programme in a multi-jurisdictional regulated environment
- Evidence strong engagement with regulators including PRA, FCA, ECB, NYDFS and MAS on infrastructure security matters
- Lead major incident response for infrastructure security events including ransomware, nation-state intrusions or significant cloud incidents
- Design and implement Zero Trust architecture at enterprise scale
- Apply strong cloud security architecture expertise across AWS, Azure and GCP including CSPM, CNAPP, cloud IAM and network security
- Build and lead globally distributed security engineering teams and manage large budgets and vendor relationships with rigour
Desirable
- Secure agentic AI and LLM infrastructure including MCP server security, AI gateway controls and GPU cluster hardening
- Manage TIBER-EU / CBEST red team scoping and remediation programmes
- Plan quantum-safe cryptography transition for infrastructure components
- Hold CCSP or AWS/Azure Security Specialty certification or CREST or equivalent TLPT qualification