Tech SME
Toluca, Mexico State, MX, 50071
Job description
Role purpose
The Technical Product Management job is accountable for enabling the technical development and run-time operation of products and services within a Product Group or a set of development teams.
Main activities
- End-to-end delivery and run support: Provide hands-on support across the full lifecycle (inception → build → test → release → run), flexing between software development, testing, and operational support based on demand.
- Product/service ownership: Take end-to-end accountability for a product or service, shaping and delivering the most appropriate technology solutions to meet customer needs across the customer journey.
- Direction-setting and stakeholder alignment: Liaise with engineers, architects, and business stakeholders to understand priorities, manage dependencies, and help drive the product/service roadmap and technical direction.
- Engineering excellence through automation: Establish a strong digital engineering environment and automate processes to reduce variation and deliver predictable, high-quality code and data (standards, templates, pipelines, quality gates).
- Quality engineering and test automation: Create and maintain technical test plans and evidence (unit, integration, regression, performance as needed) within automated test environments to ensure quality is built in.
- DevOps enablement across releases/changes: Support DevOps teams through all stages of release/change with a strong customer focus, ensuring excellent domain knowledge and smooth delivery.
- Operational readiness and defect prevention: Work with Ops, Dev, and Test Engineers to identify and address operational issues early (performance, alerting, operator intervention, design defects) throughout release/change.
- Incident and problem management: Support identification and resolution of incidents for the IT service, contributing to triage, restoration, root-cause analysis, and preventative fixes as directed by DevOps leadership.
- Resilience and recoverability: Ensure service resilience, sustainability, and RTO/RPO expectations are met, including failover, capacity, and recovery testing where applicable.
- CI/CD ownership and continuous improvement: Automate and continuously improve the CI/CD pipeline, driving a culture of continuous improvement and measurable engineering outcomes.
- Security, regulation, and risk: Stay current on tools/technologies and maintain strong awareness of cyber security and relevant regulations (e.g., data privacy, consent, data residency), applying them in design and delivery.
- AI-enabled engineering and delivery (added):
- Identify AI opportunities to improve customer journeys, engineering productivity, testing, and operations (e.g., smarter incident triage, log analysis, test generation).
- Integrate AI capabilities safely (via approved services/APIs), with appropriate guardrails, monitoring, and fallbacks.
- Use approved AI tools to accelerate development and documentation while validating outputs and maintaining quality/security controls.
- Apply Responsible AI practices (data handling, privacy, explainability, monitoring, auditability) in line with applicable HSBC governance and FIM guidance.
Requirements
Specialist Engineer – key responsibilities
- End-to-end delivery and run support: Provide hands-on support across the full lifecycle (inception → build → test → release → run), flexing between software development, testing, and operational support based on demand.
- Product/service ownership: Take end-to-end accountability for a product or service, shaping and delivering the most appropriate technology solutions to meet customer needs across the customer journey.
- Direction-setting and stakeholder alignment: Liaise with engineers, architects, and business stakeholders to understand priorities, manage dependencies, and help drive the product/service roadmap and technical direction.
- Engineering excellence through automation: Establish a strong digital engineering environment and automate processes to reduce variation and deliver predictable, high-quality code and data (standards, templates, pipelines, quality gates).
- Quality engineering and test automation: Create and maintain technical test plans and evidence (unit, integration, regression, performance as needed) within automated test environments to ensure quality is built in.
- DevOps enablement across releases/changes: Support DevOps teams through all stages of release/change with a strong customer focus, ensuring excellent domain knowledge and smooth delivery.
- Operational readiness and defect prevention: Work with Ops, Dev, and Test Engineers to identify and address operational issues early (performance, alerting, operator intervention, design defects) throughout release/change.
- Incident and problem management: Support identification and resolution of incidents for the IT service, contributing to triage, restoration, root-cause analysis, and preventative fixes as directed by DevOps leadership.
- Resilience and recoverability: Ensure service resilience, sustainability, and RTO/RPO expectations are met, including failover, capacity, and recovery testing where applicable.
- CI/CD ownership and continuous improvement: Automate and continuously improve the CI/CD pipeline, driving a culture of continuous improvement and measurable engineering outcomes.
- Security, regulation, and risk: Stay current on tools/technologies and maintain strong awareness of cyber security and relevant regulations (e.g., data privacy, consent, data residency), applying them in design and delivery.
- AI-enabled engineering and delivery (added):
- Identify AI opportunities to improve customer journeys, engineering productivity, testing, and operations (e.g., smarter incident triage, log analysis, test generation).
- Integrate AI capabilities safely (via approved services/APIs), with appropriate guardrails, monitoring, and fallbacks.
- Use approved AI tools to accelerate development and documentation while validating outputs and maintaining quality/security controls.
- Apply Responsible AI practices (data handling, privacy, explainability, monitoring, auditability) in line with applicable HSBC governance and FIM guidance.
Specialist Engineer – skills required
Core engineering
- Strong software engineering fundamentals (design, clean code, performance, maintainability).
- Ability to work across dev/test/run and switch focus quickly based on delivery needs.
- CI/CD, automation, and DevOps practices (pipelines, quality gates, deployment strategies).
- Observability and production support (monitoring, alerting, troubleshooting, RCA).
- Resilience engineering (capacity, failover patterns, recovery objectives).
Quality and testing
- Test strategy and automation (unit/integration, test data, environments, evidence).
- Defect prevention mindset and operational readiness validation.
Security and regulatory awareness
- Secure engineering practices, vulnerability management, and control-minded delivery.
- Working knowledge of privacy/consent/data residency requirements relevant to the service.
Collaboration and ownership
- Stakeholder management, clear communication, and strong domain knowledge.
- End-to-end accountability, continuous improvement, and customer-centric decision-making.
AI skills
- AI literacy (LLMs/embeddings/RAG basics, strengths/limitations, risk awareness).
- Prompting and evaluation (define acceptance criteria; validate accuracy and safety).
- AI integration skills (API integration, latency/cost considerations, resilience patterns).
- AI operationalisation (monitoring for drift/quality issues; guardrails and fallbacks).
- Security for AI (prompt injection awareness, data leakage prevention, safe output handling).
Regulatory skills
-
- Strong understanding of Mexican payments regulation relevant to SPEI/SPID and audit expectations
- Ability to translate compliance into technical requirements and measurable controls
- Experience managing multi-party audits and producing defensible evidence
- Knowledge of technology controls: IAM, cryptography, logging/SIEM, vulnerability management, SDLC/change, resilience/DR
- Excellent stakeholder management: able to influence across teams and drive timely delivery
Success measures (examples)
-
- Audit findings reduced and remediations closed on time
- Evidence produced quickly, consistently, and passes challenge
- Controls operate on schedule (access reviews, DR tests, monitoring SLAs)
- Fewer compliance-related incidents and smoother releases
If you share (1) your seniority level (analyst/manager/lead), (2) whether it’s more governance or hands-on technical, and (3) the main stakeholders (Ops/Cyber/Vendors), she/he can tailor this into a one-page JD or a CV-ready version.
Soft skills required:
- Customer-centric mindset: Keeps the end customer journey in view, prioritizing work that improves reliability, speed, and usability for customers and colleagues.
- Clear communication: Explains technical decisions, risks, and trade-offs in plain language; writes concise updates, runbooks, and technical notes that others can follow.
- Collaboration and teamwork: Works effectively in a pod and across teams (Ops, QA, architecture, security, product), building trust and momentum—no “over the wall” hand-offs.
Ownership and accountability: Takes responsibility for outcomes end-to-end (including production), Soft skills required:
- Customer-centric mindset: Keeps the end customer journey in view, prioritizing work that improves reliability, speed, and usability for customers and colleagues.
- Clear communication: Explains technical decisions, risks, and trade-offs in plain language; writes concise updates, runbooks, and technical notes that others can follow.
- Collaboration and teamwork: Works effectively in a pod and across teams (Ops, QA, architecture, security, product), building trust and momentum—no “over the wall” hand-offs.
- Ownership and accountability: Takes responsibility for outcomes end-to-end (including production), follows through on actions, and escalates early when risks emerge.
- Adaptability and learning agility: Moves between build/test/run activities as demand changes; learn new tools and domains quickly and share knowledge with others.
- Problem-solving and critical thinking: Uses structured approaches to diagnose issues, challenge assumptions, and make sound decisions under pressure.
- Influencing without authority: Brings others along on engineering standards, automation, and quality improvements through evidence, empathy, and practical proposals.
- Continuous improvement mindset: Looks for root causes, removes recurring pain points, and improves ways of working (automation, simplification, better controls).
- Resilience and composure: Stays calm during incidents and tight deadlines, focuses on restoring service safely, and supports the team through high-pressure moments.
- Inclusive behaviors: Values different perspectives, invites input from quieter voices, and creates a respectful environment where people can challenge ideas safely.
- Ethical judgement (including AI): Applies good judgement on data privacy, security, and responsible use of AI—knowing when to stop, check, or seek approval.
Major Challenges (The challenges inherent in the role that require a continual test of the role holder’s abilities)
Cross-boundary delivery at scale: Work effectively with central teams and colleagues across multiple countries, cultures, and different time zones, aligning priorities, standards, and ways of working.
Matrix reporting and competing priorities: Operate in a matrix management environment, balancing expectations from multiple reporting lines and stakeholders while maintaining clear ownership and delivery focus.
High stakeholder complexity: Manage and influence a wide range of stakeholders (business, product, architecture, security, operations, vendors/partners where applicable), translating technical detail into clear impacts, options, and decisions.
Multi-team support (local, regional, global): Provide engineering and operational support to multiple teams across local, regional, and global set-ups, ensuring consistent outcomes, effective handovers, and continuity of service.
- Own the translation of Mexican regulatory requirements (Banxico and related obligations) into clear technical controls for SPEI/SPID platforms, ensuring continuous compliance and audit readiness across Banxico, internal, and external audits. Key responsibilities
- Regulatory-to-technical translation: Interpret Banxico requirements and convert them into implementable technical controls (access, encryption, logging, monitoring, resilience, change management).
- Control design & governance: Define control objectives, control owners, testing cadence, and acceptance criteria; maintain a regulatory/control traceability matrix.
- Audit management: Coordinate end-to-end audit activities (Banxico, internal, external), including evidence collection, walkthroughs, remediation plans, and closure tracking.
- Evidence & documentation: Maintain up-to-date artefacts (policies/standards alignment, procedures, architecture diagrams, data flows, runbooks, DR plans, access reviews, incident records).
- Operational resilience: Ensure DR/BCP testing, monitoring coverage, incident response processes, and service availability meet regulatory and risk expectations.
- Change & release oversight: Embed compliance checks into SDLC and change processes; assess regulatory impact of changes and ensure approvals/testing evidence are complete.
- Risk & issue management: Identify control gaps, raise risks, drive remediation with accountable owners, and report status to governance forums.
- Stakeholder management: Act as the bridge between Technology, Operations, Cybersecurity, Risk/Compliance, and vendors to deliver consistent control outcomes.
Key deliverables (examples):
-
- Regulatory/control traceability matrix (requirement → control → system requirement → evidence → owner → test frequency)
- Audit packs and standardised evidence library
- Control testing schedule and results (access recertifications, DR tests, monitoring/alert reviews)
- Remediation plans with milestones and closure evidence
- Updated technical documentation (architecture, data flows, runbooks)
Role Context (The environment and operating conditions of the role including the extent of guidance and authority)
Business-critical payments service: Payments operates in a 24x7 model with high availability expectations and low tolerance for disruption.- On-site working: Engineering teams are primarily on-site, requiring strong collaboration, rapid decision-making, and effective coordination with remote/central stakeholders.
- Heightened cyber focus: The role operates in an environment with elevated cyber security requirements, requiring continuous attention to secure engineering, vulnerability management, and control compliance.
Management of Risk (Operational Risk / FIM requirements) - Business-critical payments service: Payments operates in a 24x7 model with high availability expectations and low tolerance for disruption.
- On-site working: Engineering teams are primarily on-site, requiring strong collaboration, rapid decision-making, and effective coordination with remote/central stakeholders.
- Heightened cyber focus: The role operates in an environment with elevated cyber security requirements, requiring continuous attention to secure engineering, vulnerability management, and control compliance.
Observation of Internal Controls (Compliance Policy / FIM requirements)
Maintain audit-ready evidence for key activities (e.g., change approvals, testing records, access reviews, incident RCA, vulnerability remediation).- Ensure segregation of duties and appropriate governance are followed throughout the delivery lifecycle.
Proactively identify control gaps and raise them early with the DevOps lead/control owners, driving remediation to closure.
Knowledge & Experience / Qualifications (For the role – not the role holder. Minimum requirements of the role.)
Knowledge: IT engineering career
Experience: 3 years on the role or similar roles of leadership.
Capabilities: High values and engagement, work under stress, conflict manager, resilience, self-motivation.
Qualifications and Accreditations: Engineering, Agile, Safe, Leadership, AI.
HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.