The health and safety of our employees and candidates is very important to us. Due to the current situation related to the Novel Coronavirus (2019-nCoV), we’re leveraging our digital capabilities to ensure we can continue to recruit top talent at HSBC. As your application progresses, you may be asked to use one of our digital tools to help you through your recruitment journey. If so, one of our Resourcing colleagues will explain how our video-interviewing technology will be used throughout the recruitment process and will be on hand to answer any questions you might have.
Some careers have more impact than others.
If you’re looking for a career where you can make a real impression, join HSBC and discover how valued you’ll be. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.
HSBC Digital Business Services is a pivotal part of the Group, providing essential operational and technical support to our global businesses and helping improve customer service and efficiency. Digital Business Services combines global expertise and technology to help keep us ahead of the competition.
We are currently seeking a high calibre professional to join our team as an SI&O Lead Analyst
- Building relationships with the operational leadership teams to understand the processes, procedures, control gaps and threats HSBC face.
- Liaising between the operational teams and its partners to drive change and improvement initiatives that benefit all parties and align to the CISO vision.
- Identifying solutions to the problems and challenges raised by the operational teams; designing automation pipelines, processes and procedures.
- Reviewing and quality assuring new automation pipelines, processes and procedures.
- Supporting and coaching the SI&O Analysts with their workload, designs and initiatives.
- Prioritising improvement initiatives and projects, following agile methodology.
- Conducting Operational Impact Assessments and planning deployments.
- Acting as an engagement point into GCO for all ‘change’ requests from stakeholders and partners
- Working with third parties and Cybersecurity Engineering to identify and productions new features.
- Ensuring the operational teams are prepared, and have the appropriate documentation and training needed to ensure a successful, uneventful go-live.
- Researching emerging threats and vulnerabilities to aid in the identification and automated response of cyber incidents.
- Contributing to the continued evolution of hunting, monitoring, detection, analysis and response capabilities and processes.
- Training, developing and mentoring colleagues in area(s) of specialism.
- Collaborating with the wider Cybersecurity (and IT) teams to ensure that the core, underlying technological capabilities that underpin an effective and efficient operational response to current and anticipated threats and trends remain fit for purpose.
- Promoting a self-critical and continuous assessment and improvement culture whereby identification of weaknesses in the bank’s control plane (people, process and technology) are brought to light and addressed in an effective and timely manner.
- Supporting engagement in support of HSBC Global Businesses and Functions to drive a global up-lift in cyber-security awareness and help to evangelize HSBC Cybersecurity efforts and success.
- An enabler who drives change and improvement initiatives.
- Practices the art of simplification.
- Ability to listen and understand others challenges and drive solutions.
- Ability to build strong internal and external relationships with a global team.
- Instinctive and creative.
- Strong problem-solving and trouble-shooting skills.
- Strong communication and interpersonal skills, with proven ability to communicate technical topics to diverse audiences.
- Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
- Ability to learn quickly through hands on experience.
- Ability to document bugs, proposed fixes, and operational instructions.
- Experience defining and refining operational procedures, workflows and processes to support the team in consistent, quality execution of monitoring and detection
- An understanding of business needs and commitment to delivering high-quality, prompt and efficient service to the business.
- An understanding of organisational mission, values and goals and consistent application of this knowledge.
- Self-motivated and possessing of a high sense of urgency and personal integrity.
- Highest ethical standards and values.
- Knowledge of cyber security principles, global financial services business models, regional compliance regulations and laws.
- Good understanding and knowledge of common industry cyber security frameworks, standards and methodologies, including; OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines, CIS and NIST standards.
- Ability to speak, read and write in English, in addition to your local language
- Excellent knowledge and demonstrated experience working with complex cross domain or cross product designs.
- Excellent knowledge of agile project methodology.
- Demonstrated experience in Python Programming or similar.
- Demonstrated experience in SQL Query Language or similar.
- Excellent knowledge and demonstrated experience in managing change and deployments that impact a global team in an enterprise scale organisation.
- Excellent knowledge and demonstrated experience of Security Automation, Orchestration and Response (SOAR) tools, common log management suites, Security Information and Event Management (SIEM) tools, use of Big Data and Cloud-based solution for the collection and real-time analysis of security information.
- Good knowledge and demonstrated experience of common cybersecurity technologies such as; IDS / IPS / HIPS, Advanced Anti-malware prevention and analysis, Firewalls, Proxies, MSS, etc.
- Good knowledge and demonstrated experience in incident response tools, techniques and process for effective threat containment, mitigation and remediation.
- Good knowledge of key information risk management and security related standards including OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines and NIST standards
- Functional knowledge and technical experience of 3rd party cloud computing platforms such as AWS, Azure and Google.
Industry Experience and Qualifications
Candidates will be evaluated primarily upon their ability to demonstrate the competencies required to be successful in the role, as described above. For reference, the typical work experience and educational background of candidates in this role are as follows:
- 3+ years of experience in similar cyber security or software development role
- Experience within an enterprise scale organisation; including hands-on experience of complex data centre environments, preferably in the finance or similarly regulated sector
- Formal education and advanced degree in Information Security, Cyber-security, Computer Science or similar and/or commensurate demonstrated work experience in the same
You’ll achieve more when you join HSBC.
HSBC is committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and opportunities to grow within an inclusive and diverse environment. Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
Issued by The Hongkong and Shanghai Banking Corporation Limited.