Consultant Specialist
Shanghai, SH, CN, 200001
Some careers have more impact than others.
If you’re looking for a career where you can make a real impression, join HSBC and discover how valued you’ll be.
We are currently seeking an experienced professional to join our team in the role of Consultant Specialist.
Business: Cybersecurity
Principal responsibilities
• Develop applicable knowledge objects, procedures and secondary standards to support agreed upon SLA or project deliverables.
• Maintain and enhance the delivery of cryptographic technology, process and relevant controls.
• Ensure crypto related inventory controls (key and HSM) are maintained.
• Implement and operate effectiveness of cryptographic controls. Contribute to the risk reduction, escalation and reporting. Support the remediation of risk
items.
• Provide guidance and consultation in new crypto technology, process and control.
• Support the KCI/KPI metric and reporting.
• Report progress and identify and raise any issues/risks, escalating as appropriate to enable satisfactory resolution.
• Build trusting relationships with stakeholders by consistently meeting and delivering upon their business needs; demonstrating and being respected for
your domain knowledge.
• Deliver fair outcomes for our customers and ensure own conduct maintains the orderly and transparent operation of financial markets.
Those stakeholders include:
a. Supplier management analysts
b. Project managers from IT or the business
c. Management of Crypto Operation and Cybersecurity
• Support peers around the world who deliver and maintain the bank’s encryption technology and the projects consuming the services by understanding
their needs and delivering to them.
• Ensuring that work happens according to schedule and with minimal deviation from process.
• Ensuring that best practices are implemented and help the organisation meet its own and external standards.
• Develop and contribute in crypto knowledge objects, procedures, and standard review.
• Act transparently in line with all appropriate standards.
• Ensure that the appropriate internal and external standards are complied with and that the risk of cryptographic compromise is minimized at all times.
• Liaise with the cryptography team’s internal control function.
• Design, implement and maintain internal controls regarding crypto infrastructure and key management.
• Plan and execute on project to improve the operational effectiveness and sustainability via automation and tooling.
Knowledge & Experience/Qualifications
• Experienced Operational Cryptography background
• Hardware Security Module expertise with hands on experience including payments, general purpose, and Cloud HSM’s.
• Good understanding on IT Infrastructure technical platforms / technologies
• Experience on project prioritization and balance needs of various key stakeholders
• Operational effectiveness - delivers solutions that align to approved design patterns and security, risk and regulatory standards
• Mindset to follow defined procedure and following the cryptography compliance process
• Customer/stakeholder focus. Ability to build strong relationships with Internal/External Key stakeholders, cross functional IT and global/local IT teams
• Ability to work out of office hours
• Awareness of risk management
• Excellent communication skill (Chinese and English)
• Knowledge of Service management techniques including incident, problem, change, release management
• Knowledge of HSM and China local manufactured signature servers/security front end server/SSL gateways.
• Good working knowledge of Linux platforms and basic knowledge of network infrastructure.
• Knowledge of Agile tools, such as JIRA, Confluence and other related tools etc.
• End to End experience of Service Now -based application design and implementation
• Background understanding in crypto technologies applicable to financial service, cloud security, data security, internet and cyber security.
• Prefer PCI QSA, CISA/CISM, CISSP, ITIL or relevant college education.
• Working knowledge in industrial standard hardware based encryption a plus.
• Working knowledge in Internal Control. Cyber Security, Compliance a plus.
• Working knowledge in collaboration technologies such as Atlassian JIRA, Confluence, MS Team, Sharepoint is necessary.
• Prior experiences in development, IT services management and system administration a plus.
HSBCVZ/GZ*
About HSBC Technology China
We develop, implement and support software and IT services and processes that allow HSBC to remain at the forefront of high-quality banking systems.
Candidate with less relevant experience or skills may be offered a lower Global Career Band than stated above.
You’ll achieve more when you join HSBC.