Sr. Associate Director, Controls

Location: 

Guangzhou, GD, CN, 510620


Brand:  HSBC
Area of Interest:  Technology
Closing Date:  Hybrid Worker
Date:  4 Sept 2026

Job description

Some careers have more impact than others.

If you’re looking for a career where you can make a real impression, join HSBC and discover how valued you’ll be.

We are currently seeking an experienced professional to join our team in the role of Sr. Associate Director, Controls.

 

Business: SecSvcs & Digital Assets Tech

Job ID: 58798

Principal responsibilities:

  • Drive a proactive risk culture, shifting focus from remediation to prevention through thematic reviews and departmental training.
  • Support the departmental external Assurance obligations, including ISAE 3402.
  • Consult on projects, providing subject matter expertise during audits
  • Share best practise with the CIB Risk and Control Organisation
  • Provide training sessions for key staff to uplift risk awareness
  • Provide guidance and help to delivery teams in regards to security solutions to enable faster delivery of Systems
  • Collaborating with project teams working closely in a DevOps and agile development processes
  • Partner with the CIB business areas and Risk Functions to promote and provide guidance to relevant policies, standards and governance within CIB
  • Provide regional stakeholder updates with respect to Control uplift programs
  • Support engagement with internal / external / client audit and Regulatory Exams, including oversight of field work, collation of artefacts and partnership with CCO to remediate issues
  • Attend relevant regional governance forums and where applicable provide appropriate MI
  • Communicate residual risk through reporting, business governance processes and forums
  • Own the risk & control agenda for region
  • Lead the delivery of risk & control projects and programmes for the region
  • Assist service/project owners in responding appropriately and effectively to firm-wide risk, cyber and corporate control initiatives
  • Partner with service owners and Asset Class RCOs to identify and assess controls, determine mitigating actions and remediation activities, and understand the overall risk profile
  • Advocate and support initiatives to improve accuracy across all Enterprise Golden Source data repositories
  • Provide visibility of status of action plans and external/internal audit issues
  • Drive ownership and accountability for Risk Issue and Action Plan Ownership within region
  • Challenge where appropriate, decisions made on control implementation
  • Review allocation of issues to SSV sectors and agree categorization of high/medium/low
  • Approve the raising and closure of regional IT issues, action plans, but look to automate process
  • Fulfil DBIRO responsibilities for the region
  • Advocate security policies and standards to the respective region
  • Integrate into the development process, attending scrums and owning security use cases and stories
  • Support initial risk assessment process and providing consultancy and guidance
  • Support where necessary key CIB security uplift initiatives
  • Contribute to review of security standards and procedures

 

Knowledge & Experience/Qualifications:

  • Proven experience in technology risk and controls within a complex, regulated environment.
  • Strong background in third party risk management, including oversight of internal service agreements and associated controls/monitoring.
  • Demonstrated ability to manage and influence stakeholders up to executive level.
  • Extensive client-facing experience, including due diligence, assurance, and audit activities.
  • Excellent presentation and communication skills, with the ability to convey complex risk topics to diverse audiences.
  • Experience acting as a deputy or second-in-command within a risk, assurance, or due diligence function is highly desirable.
  • Influencing skills.
  • Stakeholder management.
  • General interest in Technology including awareness of trends.

 

What additional skills will be good to have?

  • Consult on projects, providing subject matter expertise during audits and regulatory exams.
  • Share best practices with the wider Risk and Control Organisation.
  • Support engagement with internal/external/client audit and regulatory exams, including oversight of fieldwork and remediation.
  • Advocate for continuous improvement in data accuracy and control effectiveness across all enterprise data repositories.

 

Job Board Tags:

/WX/51/LP

 

You’ll achieve more when you join HSBC.

 

HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.

 

Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.

 

***Issued By HSBC Software Development (GuangDong) Limited***