About this role
Some careers have more impact than others.
If you’re looking for further opportunities to develop your career, take the next step in fulfilling your potential right here at HSBC.
HSBC is one of the largest banking and financial services organizations in the world, with operations in 58 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realize their ambitions.
We are currently seeking an experienced professional to join our team in the role of Head of AppSec.
The Opportunity
We are seeking a modern, visionary, pragmatic, and collaborative Head of Application Security to transform our global AppSec function. Operating across multiple geographies, your mandate is to secure a vast, hybrid technology estate—ranging from core on-premises systems to modern cloud-native platforms—while actively tackling enterprise tech debt.
In this highly influential matrixed leadership role, you will bridge the gap between engineering velocity and rigorous financial-grade security. Success requires seamless cross-functional orchestration across Cyber, CTO (Chief Technology Officer), CIO (Chief Information Officers in Global Businesses), and the CRO (Chief Risk Officer) organizations to embed security into the DNA of our software delivery lifecycle (SDLC).
What you’ll do
- Strategic & Modern AppSec Transformation
- Shift-Left at Scale: Evolve traditional gatekeeping security practices into a developer-empowered, automated or autonomous "DevSecOps" model that integrates seamlessly into continuous delivery pipelines.
- Tech Debt & Risk Navigation: Formulate pragmatic, risk-based strategies to remediate vulnerabilities across legacy on-premise architectures and modern cloud environments without stifling business innovation.
- Unified Tooling & Automation: Drive the strategy and implementation of modern Application Security Testing (AST) capabilities—including SAST, DAST, SCA, IAST, and Secrets Management—with high signal-to-noise ratios.
- Engineering Leadership: Truly bring an engineering mindset to problem solving and is not afraid to build in house, built with speed and purpose to learn, and think enterprise grade and demonstrates ambition in problem solving.
- Matrixed Collaboration & Stakeholder Management
- Cross-Functional Orchestration: Act as the central nexus between Cyber (threat intelligence and architecture), CTO/CIO (engineering, platform, and infrastructure delivery), and CRO (regulatory compliance and operational risk).
- Influence Without Authority: Navigate a complex matrixed organizational structure to align competing priorities, secure executive buy-in, and drive accountability across global engineering teams.
- Developer Advocacy: Build a culture of "security champions" by fostering trust, providing continuous feedback loops, and delivering actionable, developer-friendly remediation guidance.
- Think Enterprise: Thinks and builds for the enterprise. Anticipates interlocks and connects across functions within Cyber and in larger Tech organization and works to bridge and collaborate for impact.
- Governance, Risk, and Compliance (GRC) in a Global Bank
- Regulatory Alignment: Ensure the AppSec framework satisfies multi-jurisdictional compliance mandates (e.g., global central bank regulations, PCI-DSS, GDPR, regional data sovereignty laws).
- Quantitative Risk Reporting: Translate technical vulnerability data into executive-level risk metrics, communicating business impact clearly to the CRO and operational risk committees.
- Third-Party & Open-Source Risk: Establish robust controls for managing supply chain security, open-source software dependencies, and third-party vendor components.
What you will need to succeed in the role
Technical Leadership
- Deep Architectural Fluency: Hands-on background in software engineering or secure architecture, with comprehensive knowledge of both legacy on-premise infrastructure (mainframe, monolithic apps) and modern cloud environments (AWS, Azure, GCP, Kubernetes, Microservices).
- Modern AppSec Stack Mastery: Proven track record of scaling modern AppSec tooling, API security gateways, cloud-native application protection platforms (CNAPP), and automated vulnerability orchestration pipelines.
- Threat Modeling Expertise: Strong command of threat modeling methodologies (e.g., STRIDE, PASTA) tailored for complex, interconnected banking applications.
Functional & Cultural Leadership
- Matrix Leadership in Scale: Experience in cybersecurity, with senior leadership role within a highly regulated, matrixed enterprise (ideally global financial services).
- Exceptional Communicator: Ability to fluently translate complex security metrics into business language for executive stakeholders (CIO, CTO, CRO) while maintaining technical credibility with elite engineering teams.
- Pragmatic Risk Mindset: An understanding that perfection is the enemy of progress in a legacy-heavy banking environment; ability to balance risk mitigation with business agility and speed-to-market.
- People Developer: Demonstrated success in building, mentoring, and inspiring globally distributed, high-performing engineering and security teams.
Education & Certifications
- Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
- Relevant industry certifications (e.g., CISSP, CISM, CSSLP, AWS/Azure Security Certifications) are preferred.
You’ll achieve more when you join HSBC.
HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.
Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
***Issued By HSBC Software Development (India) Limited***