> Markdown version of [/jobs/ext/2667978-cyber-lead-group-functions-technology](https://www.wearedevelopers.com/jobs/ext/2667978-cyber-lead-group-functions-technology). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cyber Lead - Group Functions Technology - **Company:** HSBC Group - **Location:** Sheffield, UK - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Access, Artificial Intelligence, Software as a Service, Cloud Computing Security, Data Logging, Software Security - **Published:** September 2, 2026 - **Apply:** https://dejobs.org/x/x/76F2855A4AF14C89A6DD86FAEF11F39B/job/ ## About the Role * Significant experience in cybersecurity within a regulated organisation, with credibility to advise senior technology and business stakeholders. * Strong cyber risk, governance and controls capability: risk identification and articulation, issue management, control mapping, remediation planning/tracking, and audit/assurance engagement. * Solid technical foundation across enterprise security domains, such as identity and access, threat, exposure &vulnerability management, logging/monitoring, data protection, cloud/SaaS risk and third-party risk, application security & AI. * Ability to translate technical findings into business impact and clear decision options. * Strong written and spoken communication (fluent English), confident chairing/facilitating governance forums and challenging constructively. * Collaborative, outcome-driven approach; able to drive delivery through influence in a complex stakeholder environment. Desirable * Certifications such as ISO27001, CISA, CISM, CISSP, CRISC, CEH (or equivalent). * Experience supporting technology for Finance/Treasury/Risk domains and/or corporate functions, including sensitivity to financial controls and regulatory reporting. * Experience with third-party assurance and SaaS security risk management. * Familiarity with operational resilience and technology risk expectations within financial services. ## Description * Put the customer at the heart of everything we do in protecting the bank. * Act as the senior cybersecurity partner for GFT domains (Risk/Finance/Treasury/Corporate Functions), advising leadership and delivery teams on material cyber risks, control expectations and risk-based trade-offs to meet business outcomes. * Own and drive the cyber risk profile: maintain the risk register, ensure risks are clearly articulated (cause-event-impact), prioritised, and managed with accountable owners and timebound remediation plans. * Lead control governance and assurance readiness: coordinate control assessments, thematic reviews and audit activity; ensure high-quality evidence, timely closure of findings and sustainable improvement plans. * Embed proportionate security-by-design across change delivery: provide risk-based input to solution designs, delivery plans and acceptance criteria to reduce recurring risk patterns and improve control-by-default outcomes. * Oversee supplier and SaaS cyber risk: support onboarding/renewals, drive mitigations for access, data protection, logging/monitoring, incident obligations, resilience and exit/lock-in risks. * Strengthen in-service security posture by influencing technical and control priorities for identity and access risk (including privileged access), threat, exposure &vulnerability management, logging/monitoring coverage and configuration weaknesses. * Provide cybersecurity leadership support during incidents and major service events, ensuring appropriate engagement with specialist teams and clear, risk-based decisions and communications. * Produce concise, decision-grade reporting for senior stakeholders and governance forums, translating technical exposures into business impacts (e.g., financial reporting, payroll, liquidity activity, regulatory submissions). ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Crypto-secure Data Management with In-Database Blockchain](https://www.wearedevelopers.com/videos/632-crypto-secure-data-management-with-in-database-blockchain) - [Blazing Accessibility Basics](https://www.wearedevelopers.com/videos/568-blazing-accessibility-basics) - [Software Security 101: Secure Coding Basics](https://www.wearedevelopers.com/videos/220-software-security-101-secure-coding-basics) - [Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?](https://www.wearedevelopers.com/videos/712-unleashing-the-power-of-developers-why-cybersecurity-is-the-missing-piece) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Engineer Salary UK](https://www.wearedevelopers.com/magazine/253-data-engineer-salary-uk)