Cyber Security Risk & Controls Lead/Sr. Associate Director, Cybersecurity Specialist
Hyderabad, TG, IN, 500032
Job description
Some careers shine brighter than others.
If you’re looking for a career that will help you stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.
HSBC is one of the largest banking and financial services organizations in the world, with operations in 64 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realize their ambitions.
We are currently seeking an experienced professional to join our team in the role of Sr. Associate Director, Cybersecurity Specialist.
In this role, you will
- Support and enhance cybersecurity across all HSBC UK RBW entities, ensuring robust risk management, regulatory compliance, and alignment with business objectives.
- Support the UK RBW CISO with information security, translating complex concepts into actionable guidance and supporting business growth within risk appetite and a constantly evolving cyber threat landscape.
- You’ll work closely with business and technology teams to maintain robust risk and control standards ensuring that the cyber team is engineering led in their approach.
- This role is based in India and reports to the UK RBW CISO, supporting the UK RBW Technology and Business teams.
- Principal Accountabilities: Support delivery of the UK RBW cybersecurity strategy aligned to business goals and risk appetite, driving continuous improvement of controls, processes and security technologies with a strong customer focus.
- Manage cybersecurity risk, governance and compliance activities (NIST, ISO 27001, GDPR, FCA), coordinating audits/assessments, maintaining evidence and reporting for senior management, and supporting external engagement as required.
- Lead day-to-day stakeholder engagement, incident management and security culture initiatives, coordinating response to major incidents under UK RBW CISO direction
- Developing team capability, and contributing to policy, standards and awareness programmes.
To be successful in this role, you should meet the following requirements:
- Technical & Regulatory Experience: Practical engineering experience supporting the design and implementation of security controls and tooling (including exposure to AI-enabled solutions). Solid knowledge of cybersecurity, technology and risk management, with working familiarity of security frameworks (NIST, ISO 27001) and regulatory requirements (GDPR, FCA).
- Stakeholder Management: Experience working in complex, fast-paced environments, managing cybersecurity issues and coordinating with senior stakeholders, risk/compliance partners and (where required) supporting regulator-facing activities.
- Leadership: Demonstrated experience leading junior team members and delivering cybersecurity initiatives, improving control standards and contributing to function maturity and transformation outcomes.
- Essential Capabilities: Commercially aware decision-maker: Uses business and market insight to spot emerging trends and translate them into practical plans and priorities for their area. Action-oriented leader who delivers through others: Works at pace, coordinates across teams, and supports an inclusive environment to deliver agreed outcomes.
- Influential and accountable in complexity: Builds alignment with stakeholders, raises and resolves issues constructively, and delivers reliably in ambiguous situations.
- Leadership experience (8+ years): Demonstrated experience contributing to and delivering security strategy, leading teams and programmes, and applying strong security risk methodologies and engineering practices.
- Governance, frameworks and certifications: Strong working knowledge of ISO/IEC 27001 and NIST, supported by a relevant degree (or equivalent experience) and one or more professional certifications (e.g., CISSP/CISM/CISA/CRISC) or progress towards them.
- Senior stakeholder communication and influence: Clear written and verbal communication skills, able to engage and influence senior stakeholders and explain security risk and control decisions in practical business terms. Willingness to travel as required
You’ll achieve more when you join HSBC.
HSBC is committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and opportunities to grow within an inclusive and diverse environment. Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
Issued by – HSBC Software Development India