Cyber Lead - Group Functions Technology

Location: 

Sheffield, GB, S1 4NB


Brand:  HSBC
Area of Interest: 
Closing Date:  Hybrid Worker
Date:  1 Sept 2026

Job description

If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential - whether you want a career that could take you to the top, or an exciting new direction, we offer opportunities, support and rewards that will take you further.

 

 

We’re one of the largest banking and financial services organisations in the world, with a network that covers more than 50 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people fulfil their hopes and realise their ambitions.

 

 

This is a senior cybersecurity leadership role within Group Functions Technology (GFT), supporting the technology that underpins Risk, Finance and Treasury and a range of corporate functions. You’ll act as the cyber partner to GFT technology leadership and teams delivering and operating technology across Risk, Finance and Treasury, and wider corporate functions and tech centres. 

 

The role ensures that cyber risk is identified, assessed, prioritised and managed within risk appetite, that controls are implemented and evidenced effectively, and that cyber design and technology considerations are embedded into change and operations proportionately. This is a balanced Cyber Lead role combining risk, governance and controls with a strong technical foundation. 

 

As an HSBC employee in the UK, you’ll have access to tailored professional development opportunities and a competitive pay and benefits package. This includes private healthcare for all UK-based employees, enhanced maternity and adoption pay and support when you return to work, and a contributory pension scheme with a generous employer contribution.

 

 

In this role you’ll: 

 

  • Put the customer at the heart of everything we do in protecting the bank. 
  • Act as the senior cybersecurity partner for GFT domains (Risk/Finance/Treasury/Corporate Functions), advising leadership and delivery teams on material cyber risks, control expectations and risk-based trade-offs to meet business outcomes. 
  • Own and drive the cyber risk profile: maintain the risk register, ensure risks are clearly articulated (cause–event–impact), prioritised, and managed with accountable owners and timebound remediation plans. 
  • Lead control governance and assurance readiness: coordinate control assessments, thematic reviews and audit activity; ensure high-quality evidence, timely closure of findings and sustainable improvement plans. 
  • Embed proportionate security-by-design across change delivery: provide risk-based input to solution designs, delivery plans and acceptance criteria to reduce recurring risk patterns and improve control-by-default outcomes. 
  • Oversee supplier and SaaS cyber risk: support onboarding/renewals, drive mitigations for access, data protection, logging/monitoring, incident obligations, resilience and exit/lock-in risks. 
  • Strengthen in-service security posture by influencing technical and control priorities for identity and access risk (including privileged access), threat, exposure & vulnerability management, logging/monitoring coverage and configuration weaknesses. 
  • Provide cybersecurity leadership support during incidents and major service events, ensuring appropriate engagement with specialist teams and clear, risk-based decisions and communications. 
  • Produce concise, decision-grade reporting for senior stakeholders and governance forums, translating technical exposures into business impacts (e.g., financial reporting, payroll, liquidity activity, regulatory submissions). 

 

To be successful in this role you should meet the following requirements: 

 

  • Significant experience in cybersecurity within a regulated organisation, with credibility to advise senior technology and business stakeholders. 
  • Strong cyber risk, governance and controls capability: risk identification and articulation, issue management, control mapping, remediation planning/tracking, and audit/assurance engagement. 
  • Solid technical foundation across enterprise security domains, such as identity and access, threat, exposure & vulnerability management, logging/monitoring, data protection, cloud/SaaS risk and third-party risk, application security & AI. 
  • Ability to translate technical findings into business impact and clear decision options. 
  • Strong written and spoken communication (fluent English), confident chairing/facilitating governance forums and challenging constructively. 
  • Collaborative, outcome-driven approach; able to drive delivery through influence in a complex stakeholder environment. 

 

Desirable 

 

  • Certifications such as ISO27001, CISA, CISM, CISSP, CRISC, CEH (or equivalent). 
  • Experience supporting technology for Finance/Treasury/Risk domains and/or corporate functions, including sensitivity to financial controls and regulatory reporting. 
  • Experience with third-party assurance and SaaS security risk management. 
  • Familiarity with operational resilience and technology risk expectations within financial services. 

 

 

Opening up a world of opportunity.

Being open to different points of view is important for our business and the communities we serve. At HSBC, we’re dedicated to creating diverse and inclusive workplaces - no matter their gender, ethnicity, disability, religion, sexual orientation, socio-economic background or age. We are committed to removing barriers and ensuring careers at HSBC are inclusive and accessible for everyone to be at their best. We take pride in being a Disability Confident Leader and will offer an interview to people with disabilities, long term conditions or neurodivergent candidates who meet the minimum criteria for the role.

 

If you have a need that requires accommodations or changes during the recruitment process, please get in touch with our Recruitment Helpdesk via hsbc.recruitment@hsbc.com.