Some careers have more impact than others.
If you’re looking for further opportunities to develop your career, take the next step in fulfilling your potential right here at HSBC.
HSBC is one of the largest banking and financial services organisations in the world, with operations in 62 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realise their ambitions.
We are currently seeking an experienced professional to join our team in the role of Head of Web Application Security Protection.
Location: Pune / Hyderabad
Department Background:
Our Cybersecurity team helps maintain a strong, secure technology anddata infrastructure–usingindustry leading techniques, real-time data analytics and controlsto enhanceprotection against cyber-attacks.
The Opportunity:
Our Technology teams work closely with HSBC’s Global Businesses and Markets to design, build and run digital services that allow millions of our customers around the world to bank quickly, simply and securely. We run and manage Technology infrastructure, data centers and core banking systems that power the world’s leading international bank, with one of the largest technology estates in the industry.We are looking for a Cybersecurity leader to join us to shape our long-term strategy, and turbo-charge delivery, as the accountable owner for Web Application Security Protection (WASP) across the bank. This senior role reports directly to the Global Head of Network Security.What you’ll do:
Strategy: Define and maintain our global strategy for WASP, supported by engineers, platform owners, architects and Control Owners, enabling business success, meeting regulatory expectation and best practice, whilst responding to current and likely threat actor evolution.Delivery: Own the investment roadmap for WASP and its successful delivery across multiple partners. Ensure the transparent prioritisation of a common backlog to drive risk reduction, simplification and wider strategic needs. Ensure risk-risk trade-offs are managed, particularly risk mitigation and operational needs.Innovation: Empower HSBC to successfully navigate cyber risk with innovative, responsive and frictionless technologies and services, both those delivered in-house and from external partners. Foster and empower a culture of innovation, experimentation, and continuous improvement.Partnership: Develop with colleagues throughout technology and the business innovative technical solutions that meet both current and future business needs, ensuring the bank’s infrastructure remains scalable and resilient. Drive the shift-left of WASP in partnership with DevOps. Partner with external technology providers and security specialists to integrate best practice and leverage or build cutting-edge tooling.Services: define, operate and mature a business service supporting adoption and tuning of protections, as well as being a trusted advisor and point of escalation for technical and business teams managing online services, ensuring security requirements are understood and effectively implemented.Oversight: Ensure WASP is overseen end-to-end, robustly and throughout the organisation: from platform acquisition, service deployment through to federated operation. Drive a data-centric approach to observability and assessment, wherever possible supported by automation, measures and analytics. Accountability: Ensure regulatory and risk management outcomes are being maintained or robustly managed. Ownership of High-Risk Audit, Regulator and self-identified issues. Ownership of the capability budget, balancing run and change investment. As a senior leader, contribute to and champion change across both Cybersecurity and Technology, occasionally outside of your primary remit. Talent: Lead, manage, invest in, recruit and inspire a team of highly skilled and performant SMEs across the globe. A culture driven by empowerment, experimentation, learning, partnership and delivery. A place where colleagues thrive, solving meaningful problems that keep the bank and its customers safe.