Cybersecurity Operations Manager - HSBC Operations, Services and Technology

  • Competitive
  • Hong Kong
  • Festanstellung, Vollzeit
  • HSBC
  • 18 Jan 19

Cybersecurity Operations Manager - HSBC Operations, Services and Technology

Join our fast-growing Asia Wealth Management teams

HSBC Operations, Services and Technology is a pivotal part of the Group, providing essential operational and technical support to our global businesses and helping improve customer service and efficiency. HOST combines global expertise and technology to help keep us ahead of the competition.

We are currently seeking a high caliber professional to join our team as Cybersecurity Operations Manager .

Principal responsibilities​

  • Leading a team of 8 to 20 highly skilled security professionals, providing a global service supporting the response to cyber security threats.
  • Developing, managing and maintaining a highly skilled, efficient and effective local team across all Cybersecurity Operations service lines. Including the definition, management and continuous improvement of core functions and processes that underpin a successful, effective and globally scaled monitoring, alerting and security incident response capability.
  • Maintaining an up to date awareness and intelligence led understanding of the current and predicted threat landscape so that impact to HSBC businesses or services can be anticipated and where possible, pre-emptive monitoring, alerting and response capabilities can be deployed.
  • Owning and managing collaboration with the wider Cybersecurity and IT teams to ensure that the core, underlying technological capabilities that underpin an effective and efficient operational response to current and anticipated threats and trends remain fit for purpose.
  • Identification of processes that can be automated and orchestrated to ensure maximum efficiency of global Cybersecurity Operations resources.
  • Ensuring analysis time is efficiently focused on the more challenging and potentially higher risk problems and tasks, not on high volume or low risk, repetitive tasks or processes, thus helping to effectively reduce false positive and false negative events.
  • Managing and owning the collaboration with the wider Cybersecurity teams and wider business or function teams where applicable, in the production and maintenance of efficient and effective security event monitoring and alerting use-cases and incident response playbooks.
  • Maintaining a global view of the GCO mission and work with local stakeholders in region and country to bring together both the global perspective, as well as the more local message in a clear and effective way that demonstrates the team's commitment and value.
  • Promoting a self-critical and continuous assessment and improvement culture, whereby identification of weaknesses in the bank's control plane people, process and technology are brought to light and addressed in an effective and timely manner.
  • Embedding a culture of individual self-improvement, development and self-directed learning whereby staff are expected to maintain subject matter expertise within their area of focus and within the realm of cyber security more broadly.
  • Directed engagement in support of HSBC Global Businesses and Functions to drive a global up lift in cyber security awareness and help to evangelise HSBC Cybersecurity efforts and success.
  • Participation in the GCO Leadership Team ensuring that the voice of Cybersecurity Operations staff is heard, concerns are raised and addressed and the function continues to evolve at pace with the threat landscape and business requirements.
  • Identification and development of high quality and meaningful cyber security related Management Information that is data driven, contextual, appropriate to the target audience and supported by experienced analysis in order to drive informed debate and decision making.

Requirements ​
  • Excellent understanding of HSBC cyber security principles, global financial services business models, regional compliance regulations and laws.
  • Excellent understanding and knowledge of common industry cyber security frameworks, standards and methodologies, including OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines, CIS and NIST standards.
  • Proven ability and experience of working in a high pressure, fast paced environment where bold, time critical decision making is essential.
  • Proven experience in identifying and responding to advanced attacker methodologies both within the corporate environment as well as external attack infrastructures, ideally with offensive experience and or deception environment development tripwire systems, honeypots, honey token accounts, using open source, vendor purchased and bespoke inhouse developed solutions.
  • Excellent communication and interpersonal skills with the ability to produce clear and concise reports for targeted audiences across internal and external stakeholders.
  • Solid understanding of business finance as well as effective management of budgets and expenditures.
  • Experience in a leadership position within a cybersecurity operations team to include team and capability development, staff development, career management and recruitment.
  • Ability to orchestrate, manage and successfully implement major procedural and technological change within a complex and global organisation.
  • Expert level knowledge and demonstrated experience of common intelligence sharing platforms protocols and experience operating within a collective defence environment with internal stakeholders and external partners.
  • Expert level knowledge of common enterprise technology infrastructure, platforms and tooling, including Windows, Linux, infrastructure management and networking hardware.
  • Expert level knowledge of intelligence analysis principles either though formal education training or equivalent professional experience.
  • Expert level knowledge and demonstrated experience in analysis and dissection of advanced attacker tactics, techniques and procedures in order to inform adjustments to the control plane.
  • Expert level knowledge of scripting, programming and or development of bespoke tooling or solutions to solve unique problems.
  • Ability to identify, develop and track key performance indicator KPI metrics for accurate and contextual evaluation of operational effectiveness as well as providing recommendations for control improvement and mitigating control adjustments.
  • Expert knowledge and technical experience of third party cloud computing platforms such as AWS, Azure and Google.
  • Industry recognised cyber security related certifications including, CEH, EnCE, SANS, CISSP, CISM, CRISC and or CISA.
  • Formal education and advanced degree in Information Security, Cyber security, Computer Science or similar and or commensurate demonstrated work experience in the same.
  • Experience in a technical authority or leadership position within an enterprise scale organisation including hands on experience of complex data centre environments.
  • Expert level of experience in Cyber security operations management, Cyber security management in a leadership position.

You'll achieve more when you join HSBC.

Candidate with less relevant experience or skills may be offered a lower Global Career Band than stated above.

HSBC is committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and opportunities to grow within an inclusive and diverse environment. Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.