> Markdown version of [/jobs/ext/2286444-head-of-infrastructure-security-controls-and-delivery-oversight](https://www.wearedevelopers.com/jobs/ext/2286444-head-of-infrastructure-security-controls-and-delivery-oversight). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Head of Infrastructure Security Controls and Delivery Oversight - **Company:** HSBC Group - **Location:** Sheffield, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Agile Methodology, Information Technology - **Published:** August 29, 2026 - **Apply:** https://dejobs.org/x/x/AA8CB40D30944C43BEC4F043BAC36F2C/job/ ## About the Role * Hands-on and robust Infrastructure Security experience and knowledge. * Strong technology background with a solid understanding of IT infrastructure and operations. * Demonstrable experience in cybersecurity controls governance / control ownership (proven success operating within a 2LoD or 3LoD team is beneficial). * Experience overseeing delivery across multiple initiatives (portfolio/programme governance), including interdependencies, risks, issues, and benefits realisation. * Excellent stakeholder management skills, including engagement with audit, risk, and regulatory-facing teams. * Strong communication skills: able to translate complex technical/control requirements into clear expectations, decisions, and outcomes. * Proven problem-solving capability: able to identify control/process gaps and drive pragmatic remediation through the right teams. * Bachelor's degree and/or equivalent experience in cybersecurity, technology, risk, or related disciplines. * Working knowledge of industry control frameworks (e.g., CIS/NIST-aligned approaches). * Understanding of project and delivery methodologies (e.g., Agile/Waterfall); formal qualification beneficial but not mandatory given the oversight nature of the role. * Inclusive, collaborative leadership style; open to challenge and constructive in driving solutions. * Takes responsibility and ownership; escalates appropriately while driving outcomes at pace. * Comfortable operating with ambiguity; able to define plans and actions in the absence of perfect information. * Builds partnerships across global and local teams to get outcomes delivered and embedded. ## Description * Provide risk and controls leadership within the Infrastructure Security domain (e.g., platform and OS hardening, secure configuration), in partnership with wider technology control owners. This includes how key security controls are embedded into infrastructure (people, process and technology), for example opportunities for MFA, and automated certificate management etc are embedded into OS, and supporting the oversight and challenge of the adequacy of security-focused ITOP control requirements, in partnership with the ITOP Control Owner. * Risk management: maintain the accuracy and alignment of assigned controls to the bank's Risk Control Framework, including control intent, scope, applicability, and ownership. * Control design and continuous control monitoring: drive enhancements to monitoring points / operating instructions where relevant and maintain and/or challenge a clear control effectiveness rationale. * Measurement: manage, report, and improve relevant control-centric metrics (e.g., KRIs/KCIs/KPIs), driving remediation plans where performance is off-track. * Compliance and assurance support: ensure controls align with relevant regulations, standards, and industry best practice; maintain internal control standards, including timely implementation of internal and external audit actions and responses to regulatory observations (in partnership with relevant teams). * Provide specialist input to ensure control requirements are translated into cogent and practical engineering outcomes to support Infrastructure Security delivery. Enable the voice-of-the-engineer to feature in control redesign, supporting more effective ways to achieve control outcomes such as as-code approaches, in partnership with Engineering Enablement and B/GI engineering PEs. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [ShapeShift: Reinventing Agile for a B2B SaaS Scale-Up](https://www.wearedevelopers.com/videos/1655-shapeshift-reinventing-agile-for-a-b2b-saas-scale-up) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [From Punch Cards to AI-assisted Development](https://www.wearedevelopers.com/videos/611-from-punch-cards-to-ai-assisted-development) - [It's not easy being green](https://www.wearedevelopers.com/videos/558-it-s-not-easy-being-green) ## Related Articles - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [UK Business Culture and Etiquette](https://www.wearedevelopers.com/magazine/326-uk-business-culture-and-etiquette) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [IT Salaries in UK](https://www.wearedevelopers.com/magazine/288-it-salaries-in-uk)