Head of CSAT Transformation, Risk and Assurance

HSBCPune, MaharashtraOn-siteFull-timeListed 1 hour ago

Apply now

About this role

If you’re looking for further opportunities to develop your career, take the next step in fulfilling your potential right here at HSBC.

HSBC is one of the largest banking and financial services organizations in the world, with operations in 58 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realize their ambitions.

We are currently seeking an experienced professional to join our team in the role of Cyber Security Assessment and Testing Head of CSAT Risk, Governance and Assurance .

The Opportunity

Global Cybersecurity is responsible for enabling businesses and functions to manage their information, technology and cybersecurity risks by ensuring these are well-understood, and that controls used the manage such events are defined, assessed and implemented appropriately. Cybersecurity delivers this via objective, independent, professional and specialized subject matter experts. The role forms part of the 1LoD in relation to risk management framework.

The Cybersecurity Assessment and Testing (CSAT) function, part of Global Cybersecurity, is accountable for Vulnerability Management, Secure Development, Threat and Controls Assessment (threat modelling), Third Party Security Assessment and Offensive Security and Cyber research. The function drives the identification, capture, assessment, testing and ultimately the remediation of threats, security defects, gaps and vulnerabilities across HSBC’s estate in concert with business and technology teams – on-premise, in the Cloud and resulting from third party engagements.

What you’ll do

The role will lead and provide expertise covering activities including implementation and oversight of the Group’s Risk Management Framework applied to CSAT through ongoing and targeted risk and controls assessments, implementing and maintaining robust risk governance, and championing a proactive risk culture. They would work closely with partners across all lines of defence and is responsible for maintaining positive relationships with our regulators and external partners as needed.

- The role holder will report to the Global Head of CSAT to oversee the risk and control portfolio related to CSAT function in Group CISO. Their primary stakeholder will be all the capability(control) owners within CSAT, designated lead from Chief Controls Office (CCO), Audit and Cyber Risk (2nd line)
- Enabling the Businesses and Regions to execute their strategic growth objectives in a safe and secure way
- Supporting business CISO’s to make decisions based on data to actively manage HSBC’s residual risk
- Providing clear understanding of Cyber risks and the role they play in mitigating these risks
- Partnership with Risk and Control Owners to ensure risk positions are understood and reflected in the design and operation of control activities managed by CSAT
- Identifying, growing and supporting talent
- The role will have global responsibility and will partner with Regions and Countries as required
- The role holder will lead the CSAT Risk and Governance team to a values-based and outcome focussed way of working, including driving cultural change to deliver strong integrated risk management across.

Governance and Committee Memberships

- Member of Cybersecurity Assessment and Testing Leadership Teams
- Delegated Lead for the CSAT RCMM representing Global Head CSAT
- Attend the Cyber RCMM

Stakeholder Management

- Act as a primary point of contact for Global Head of CSAT for all matters related to risk & controls
- Manage executive updates within and outside Cyber for all things representing CSAT as a function
- Effectively manage relationships across CCO and 2LOD/3LOD partners – drive risk and audit reviews and subsequent actions through to resolution by partnering with the respective Cyber and CTO/CIO teams
- Work to break down siloes across functions to deliver a holistic, end-to-end controls environment

Functional Risk & Controls lead for  CSAT

- Accountable for managing and governing the risk portfolio for the Global Head of Cybersecurity Assessments and Testing
- Drive risk and control decision-making based on quality data and commercial analysis, actively challenging poor, inefficient or excessive controls, related tasks and behaviors.
- Lead a structured approach to identifying, documenting and resolving key control issues in CSAT
- Drive strategic enhancements to the design and implementation of the Risk Framework in the 1st line and through partnership and influence with ERM
- Oversee emerging risks, strategic business initiatives and local change activity
- Drive consistent and insightful reporting and escalation of identified issues and their status across the lifecycle
- Drive consistent communication, clarifying impacts of change on the risk and control environment for HSBC
- Partner with relevant services to design and implement future-fit risk management and regulatory requirements
- Embed risk culture and change delivery capability across the GCIO CCO function

External environment

- Identify trends to anticipate future developments in the risk and control environment
- Stay educated and aware of developments in the broader technology environment and industry
- Ensure ongoing awareness of the Regulatory environment and its impact on Cybersecurity and Technology

Leadership & Team Management

- Lead the team within CSAT to manage operational risk through risk assessments, control environment reviews, issue lifecycle management and provide specialist risk and control knowledge and insights
- Lead by example, demonstrate core behaviour and values including professionalism, teamwork, determination, and continuous improvement
- Continuously invest in the team’s technical skills through ongoing learning, development and coaching
- Lead the definition and delivery of a team strategy, aligned to HSBC and the GCIO Cyber function’s objectives
- Define core delivery targets for the Team and ensure team delivery on commitments made
- Coach team members to enable performance improvement and career development at HSBC

Leadership & Teamwork

- Develop and maintain long term relationships with critical stakeholders internally and externally of all seniorities
- Experience managing and coordinating a globally dispersed team
- Experience managing within a complex matrix environment
- Experience working across cultures

What you will need to succeed in the role

- Should have proven track record in technology risk management or cybersecurity leadership roles within the financial services industry, preferably within multinational banks
- Demonstrated experience in managing technical cyber or infrastructure Risk & Control Teams, with a track record of driving results in a complex, matrixed organisation
- Technical experience operating within a globally diverse, heterogenous technology environment preferred.
- Strong leadership background with a proven track-record of managing a wide range of diverse stakeholders across all seniorities
- In-depth technical knowledge of Network Cybersecurity and related infrastructure security concepts, implementations and products
- Detailed knowledge of design and implementation of cybersecurity controls at the application and infrastructure layers preferred
- Demonstrated understanding of Non-Financial Risk frameworks, relevant industry standards (e.g. NIST) and key regulatory themes in major markets (e.g. UK, US, HK, SG, etc.)
- Experience in performing structured and repeatable risk and control reviews
- Proven experience in a 2nd or 3rd line function with related oversight is also beneficial
- Ability to work well under pressure, demonstrate flexibility and adapt to rapidly changing priorities
- Ability to lead change and prioritise conflicting demands and problem solve in a dynamic environment
- Proven track record of increasing business performance i.e. developing, aligning and translating strategies & plans to achieve business and functional goals
- Proven ability to articulate complex issues concisely and in simple language to support problem analysis
- Proven project management experience with an ability to influence senior stakeholders
- Experience in writing and presenting board papers

You’ll achieve more when you join HSBC.

HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.

Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.

***Issued By HSBC Software Development (India) Limited***