Head of Infrastructure Security Controls and Delivery Oversight

Location: 

Sheffield, GB, S1 4NB


Brand:  HSBC
Area of Interest: 
Closing Date: 
Date:  21 Aug 2026

Job description

If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential - whether you want a career that could take you to the top, or an exciting new direction, we offer opportunities, support and rewards that will take you further.

 

We’re one of the largest banking and financial services organisations in the world, with a network that covers more than 50 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people fulfil their hopes and realise their ambitions.

 

We are seeking a Head of Infrastructure Security Controls and Delivery Oversight

As an HSBC employee in the UK, you’ll have access to tailored professional development opportunities and a competitive pay and benefits package. This includes private healthcare for all UK-based employees, enhanced maternity and adoption pay and support when you return to work, and a contributory pension scheme with a generous employer contribution.

In this fantastic role, provide risk and controls leadership within the infrastructure security domain.

 

In this role, you will:

  • Provide risk and controls leadership within the Infrastructure Security domain (e.g., platform and OS hardening, secure configuration), in partnership with wider technology control owners. This includes how key security controls are embedded into infrastructure (people, process and technology), for example opportunities for MFA, and automated certificate management etc are embedded into OS, and supporting the oversight and challenge of the adequacy of security-focused ITOP control requirements, in partnership with the ITOP Control Owner.
  • Risk management: maintain the accuracy and alignment of assigned controls to the bank’s Risk Control Framework, including control intent, scope, applicability, and ownership.
  • Control design and continuous control monitoring: drive enhancements to monitoring points / operating instructions where relevant and maintain and/or challenge a clear control effectiveness rationale.
  • Measurement: manage, report, and improve relevant control-centric metrics (e.g., KRIs/KCIs/KPIs), driving remediation plans where performance is off-track.
  • Compliance and assurance support: ensure controls align with relevant regulations, standards, and industry best practice; maintain internal control standards, including timely implementation of internal and external audit actions and responses to regulatory observations (in partnership with relevant teams).
  • Provide specialist input to ensure control requirements are translated into cogent and practical engineering outcomes to support Infrastructure Security delivery. Enable the voice-of-the-engineer to feature in control redesign, supporting more effective ways to achieve control outcomes such as as-code approaches, in partnership with Engineering Enablement and B/GI engineering PEs.

To be successful in this role you should have the following skills:

  • Hands-on and robust Infrastructure Security experience and knowledge.
  • Strong technology background with a solid understanding of IT infrastructure and operations.
  • Demonstrable experience in cybersecurity controls governance / control ownership (proven success operating within a 2LoD or 3LoD team is beneficial).
  • Experience overseeing delivery across multiple initiatives (portfolio/programme governance), including interdependencies, risks, issues, and benefits realisation.
  • Excellent stakeholder management skills, including engagement with audit, risk, and regulatory-facing teams.
  • Strong communication skills: able to translate complex technical/control requirements into clear expectations, decisions, and outcomes.
  • Proven problem-solving capability: able to identify control/process gaps and drive pragmatic remediation through the right teams.
  • Bachelor’s degree and/or equivalent experience in cybersecurity, technology, risk, or related disciplines.
  • Working knowledge of industry control frameworks (e.g., CIS/NIST-aligned approaches).
  • Understanding of project and delivery methodologies (e.g., Agile/Waterfall); formal qualification beneficial but not mandatory given the oversight nature of the role.
  • Inclusive, collaborative leadership style; open to challenge and constructive in driving solutions.
  • Takes responsibility and ownership; escalates appropriately while driving outcomes at pace.
  • Comfortable operating with ambiguity; able to define plans and actions in the absence of perfect information.
  • Builds partnerships across global and local teams to get outcomes delivered and embedded.

Being open to different points of view is important for our business and the communities we serve. At HSBC, we’re dedicated to creating diverse and inclusive workplaces - no matter their gender, ethnicity, disability, religion, sexual orientation, socio-economic background or age. We are committed to removing barriers and ensuring careers at HSBC are inclusive and accessible for everyone to be at their best. We take pride in being a Disability Confident Leader and will offer an interview to people with disabilities, long term conditions or neurodivergent candidates who meet the minimum criteria for the role. 

If you have a need that requires accommodations or changes during the recruitment process, please contact the Recruiter.