Cyber Lead - Group Functions Technology

HSBC Group
Sheffield, UK
3 days ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours
Languages
English
Job source

Tech stack

Microsoft Access Artificial Intelligence Software as a Service Cloud Computing Security Data Logging Software Security

Job description

  • Put the customer at the heart of everything we do in protecting the bank.
  • Act as the senior cybersecurity partner for GFT domains (Risk/Finance/Treasury/Corporate Functions), advising leadership and delivery teams on material cyber risks, control expectations and risk-based trade-offs to meet business outcomes.
  • Own and drive the cyber risk profile: maintain the risk register, ensure risks are clearly articulated (cause-event-impact), prioritised, and managed with accountable owners and timebound remediation plans.
  • Lead control governance and assurance readiness: coordinate control assessments, thematic reviews and audit activity; ensure high-quality evidence, timely closure of findings and sustainable improvement plans.
  • Embed proportionate security-by-design across change delivery: provide risk-based input to solution designs, delivery plans and acceptance criteria to reduce recurring risk patterns and improve control-by-default outcomes.
  • Oversee supplier and SaaS cyber risk: support onboarding/renewals, drive mitigations for access, data protection, logging/monitoring, incident obligations, resilience and exit/lock-in risks.
  • Strengthen in-service security posture by influencing technical and control priorities for identity and access risk (including privileged access), threat, exposure &vulnerability management, logging/monitoring coverage and configuration weaknesses.
  • Provide cybersecurity leadership support during incidents and major service events, ensuring appropriate engagement with specialist teams and clear, risk-based decisions and communications.
  • Produce concise, decision-grade reporting for senior stakeholders and governance forums, translating technical exposures into business impacts (e.g., financial reporting, payroll, liquidity activity, regulatory submissions).

Requirements

  • Significant experience in cybersecurity within a regulated organisation, with credibility to advise senior technology and business stakeholders.
  • Strong cyber risk, governance and controls capability: risk identification and articulation, issue management, control mapping, remediation planning/tracking, and audit/assurance engagement.
  • Solid technical foundation across enterprise security domains, such as identity and access, threat, exposure &vulnerability management, logging/monitoring, data protection, cloud/SaaS risk and third-party risk, application security & AI.
  • Ability to translate technical findings into business impact and clear decision options.
  • Strong written and spoken communication (fluent English), confident chairing/facilitating governance forums and challenging constructively.
  • Collaborative, outcome-driven approach; able to drive delivery through influence in a complex stakeholder environment.

Desirable

  • Certifications such as ISO27001, CISA, CISM, CISSP, CRISC, CEH (or equivalent).
  • Experience supporting technology for Finance/Treasury/Risk domains and/or corporate functions, including sensitivity to financial controls and regulatory reporting.
  • Experience with third-party assurance and SaaS security risk management.
  • Familiarity with operational resilience and technology risk expectations within financial services.

Benefits & conditions

As an HSBC employee in the UK, you’ll have access to tailored professional development opportunities and a competitive pay and benefits package. This includes private healthcare for all UK-based employees, enhanced maternity and adoption pay and support when you return to work, and a contributory pension scheme with a generous employer contribution.

About the company

If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential - whether you want a career that could take you to the top, or an exciting new direction, we offer opportunities, support and rewards that will take you further.

We’re one of the largest banking and financial services organisations in the world, with a network that covers more than 50 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people fulfil their hopes and realisetheir ambitions.

This is a senior cybersecurity leadership role within Group Functions Technology (GFT), supporting the technology that underpins Risk, Finance and Treasury and a range of corporate functions. You’ll act as the cyber partner to GFT technology leadership and teams delivering and operating technology across Risk, Finance and Treasury, and wider corporate functions and tech centres.

The role ensures that cyber risk is identified, assessed, prioritised and managed within risk appetite, that controls are implemented and evidenced effectively, and that cyber design and technology considerations are embedded into change and operations proportionately. This is a balanced Cyber Lead role combining risk, governance and controls with a strong technical foundation., Being open to different points of view is important for our business and the communities we serve. At HSBC, we’re dedicated to creating diverse and inclusive workplaces - no matter their gender, ethnicity, disability, religion, sexual orientation, socio-economic background or age. We are committed to removing barriers and ensuring careers at HSBC are inclusive and accessible for everyone to be at their best. We take pride in being a Disability Confident Leader and will offer an interview to people with disabilities, long term conditions or neurodivergent candidates who meet the minimum criteria for the role.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:39 min

Navigating strict environments for enterprise banking

Lea Fragner · LIVE

1:10 min

Exposing sensitive information through partial search logs

Dennis Schulz Dennis Schulz +1 · World Congress 2026 Europe

3:24 min

Testing applications with Microsoft accessibility insights tool

Dennie Declercq · LIVE

1:30 min

The universal and shared team responsibility of software security

Julia Wilson Julia Wilson +1 · World Congress 2025

1:44 min

Background and career journey in regulated software systems

Martin Hynie · Coffee With Developers

1:56 min

Discovering incidents using logs, metrics, and traces

Nele Uhlemann · World Congress 2023

Videos

See all

Related articles

See all