Cyber Lead - DevSecOps (CTO)
Sheffield, GB, S1 4NB
Job description
If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential - whether you want a career that could take you to the top, or an exciting new direction, we offer opportunities, support and rewards that will take you further.
We’re one of the largest banking and financial services organisations in the world, with a network that covers more than 50 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people fulfil their hopes and realise their ambitions.
This role combines Cybersecurity Technical Lead and Business Information Security Officer - Technology, Platforms & AI accountabilities into one senior position embedded in Enterprise Technology engineering. Working at Vice President grade in the 1st Line of Defence you’ll act as the security partner and technical authority for teams spanning application development, developer platforms and AI capabilities.
You’ll support the CISO and Deputy CISO by ensuring security is designed-in from inception and cyber risk is managed within risk appetite and regulatory obligations. The role brings hands-on security engineering depth into major programmes and day-to-day decision-making including incident and outage scenarios. Success looks like secure-by-design delivery across SDLC DevSecOps developer tooling and AI lifecycle controls with clear reporting that connects technical risk to business impact.
As an HSBC employee in the UK, you’ll have access to tailored professional development opportunities and a competitive pay and benefits package. This includes private healthcare for all UK-based employees, enhanced maternity and adoption pay and support when you return to work, and a contributory pension scheme with a generous employer contribution
In this role you will:
- Act as the cybersecurity SME for the assigned technology organisation providing technical advisory across programmes projects incidents and IT outages
- Build strong partnerships across the ET CISO organisation central cyber teams and technology stakeholders such as Architecture and engineering teams
- Own the divisional application security programme embedding security-by-design across SDLC and DevSecOps including SAST DAST SCA and secrets management in CI/CD
- Define and maintain secure coding standards security acceptance criteria and threat modelling processes for engineering teams
- Partner with engineering teams to triage and prioritise vulnerabilities ensuring remediation SLAs are met using CVSS and EPSS-informed prioritisation
- Oversee penetration testing scope and manage findings through to remediation with clear CISO-level reporting on security posture
- Govern security of the internal developer platform and toolchain including source control build systems package registries container platforms secrets management and internal API gateways
- Establish and run the divisional software supply chain security programme including SBOM generation open-source dependency risk and third-party component governance aligned to DORA and NCSC guidance
- Shape the divisional AI security function including AI threat models and governance aligned to the EU AI Act the organisation’s AI risk framework and relevant PRA and FCA guidance
- Own the divisional information security risk register providing tailored reporting to senior stakeholders and supporting regulatory engagement internal audit and second-line reviews
To be successful in this role you should meet the following requirements:
- Bring significant information security experience with depth in application security DevSecOps platform security and or technical cyber consulting in a regulated environment
- Demonstrate hands-on AppSec tooling and practices including SAST DAST SCA secrets management secure SDLC and threat modelling
- Apply working knowledge of software supply chain security including SBOM and dependency risk governance
- Show a solid understanding of AI and ML security risks including prompt injection training data integrity risks model extraction and agentic AI threats
- Communicate technical risk clearly to senior stakeholders translating it into business impact regulatory exposure and remediation priorities
- Produce strong written and spoken communication in fluent English for both technical and non-technical audiences
- Operate confidently within information security governance policy and risk expectations including risk register management escalation and reporting
- Partner effectively with Cyber Delivery and central cyber functions to align prioritisation escalate delivery issues and contribute to path-to-green control improvement initiatives
Opening up a world of opportunity.
Being open to different points of view is important for our business and the communities we serve. At HSBC, we’re dedicated to creating diverse and inclusive workplaces - no matter their gender, ethnicity, disability, religion, sexual orientation, socio-economic background or age. We are committed to removing barriers and ensuring careers at HSBC are inclusive and accessible for everyone to be at their best. We take pride in being a Disability Confident Leader and will offer an interview to people with disabilities, long term conditions or neurodivergent candidates who meet the minimum criteria for the role.
If you have a need that requires accommodations or changes during the recruitment process, please get in touch with our Recruitment Helpdesk via hsbc.recruitment@hsbc.com.