Lead Cybersecurity Analyst

HSBC
Shanghai, 上海市
全职
1天前
Job description

Some careers have more impact than others.
If you’re looking for a career where you can make a real impression, join HSBC and discover how valued you’ll be.

We are currently seeking an experienced professional to join our team in the role of Lead Cybersecurity Analyst.

Business: Cybersecurity

Principal responsibilities
Customers / Stakeholders

  • Report progress and identify and raise any issues/risks, escalating as appropriate to enable satisfactory resolution.
  • Build trusting relationships with stakeholders by consistently meeting and delivering upon their business needs; demonstrating and being respected for your domain knowledge.
  • Deliver fair outcomes for our customers and ensure own conduct maintains the orderly and transparent operation of financial markets. Those stakeholders include:
a. Supplier management analysts
b. Project managers from IT or the business
c. Management of Crypto Operation and Cybersecurity
Leadership & Teamwork
  • As part of a global team, support peers around the world who deliver and maintain the bank’s cryptographic technology and the projects consuming the services by understanding their needs and delivering to them.
  • Ensuring that work happens according to schedule and with minimal deviation from process.
  • Ensuring that best practices are implemented and help the organization meet its own and external standards.
  • Develop and contribute to crypto knowledge objects, procedures, and standard review.

Operational Effectiveness & Control:

  • Act transparently in line with all appropriate standards.
  • Ensure that the appropriate internal and external standards are complied with and that the risk of cryptographic compromise is always minimized.
  • Liaise with the cryptography team’s internal control function.
  • Design, implement and maintain internal controls regarding crypto infrastructure and key management.
  • Plan and execute on project to improve the operational effectiveness and sustainability via automation and tooling.
  • Ensure crypto related inventory controls (Safe, Key and HSM) are maintained.
  • Plan and perform oversight review using the Internal Change Review Process, perform crypto assessments, review crypto related control process and procedures in accordance to global crypto standards.
Management of Risk (Operational Risk / FIM requirements)
  • The jobholder will ensure the fair treatment of our customers is at the heart of everything we do, both personally and as an organization.
  • This will be achieved by consistently displaying the behaviors that form part of the HSBC Values and culture and adhering to HSBC risk policies and procedures, including notification and escalation of any concerns and taking required action in relation to points raised by audit and/or external regulators.
  • The jobholder is responsible for managing and mitigating operational risks in their day-to-day operations. In executing these responsibilities, the Group has adopted risk management and internal control structure referred to as the ‘Three Lines of Defense’. The jobholder should ensure they understand their position within the Three Lines of Defense, and act accordingly in line with operational risk policy, escalating in a timely manner where they are unsure of actions required.
  • Through the implementation the Global AML, Sanctions and ABC Policies, supporting Guidance, and Line of Business Procedures the jobholder will make informed decisions in accordance with the core principles of HSBC's Financial Crime Risk Appetite.
  • The following statement is only for roles with core responsibilities in Operational Risk Management (Risk Owner, Control Owner, Risk Steward, BRCM, and Operational Risk Function.
  • The jobholder has responsibility for overseeing and ensuring that Operational risks are managed in accordance with the Group Standards Manual, Risk FIM, & relevant guidelines & standards.
  • The jobholder should comply with the detailed expectations and responsibilities for their core role in operational risk management through ensuring all actions take account of operational risks, and through using the Operational Risk Management Framework appropriately to manage those risks.
This will be achieved by:
  • Continuously reassessing risks associated with the role and inherent in the business, taking account of changing economic or market conditions, legal and regulatory requirements, operating procedures and practices, management restructurings, and the impact of new technology.
  • Ensuring all actions take account of the likelihood of operational risk occurring, addressing areas of concern in conjunction with Risk and relevant line colleagues, and also by ensuring that actions resulting from points raised by internal or external audits, and external regulators, are correctly implemented in a timely fashion.
Observation of Internal Controls
  • The jobholder will adhere to, and be able to demonstrate adherence to, internal controls and will implement the Group compliance policy by adhering to all relevant processes/procedures.
  • The term ‘compliance’ embraces all relevant financial services laws, rules and codes with which the business has to comply. This will be achieved by adherence to all relevant procedures, keeping appropriate records and, where appropriate, by the timely implementation of internal and external audit points, including issues raised by external regulators.
Able to align with existing ITIL process i.e.: Change Management, Incident Management, Release Management, Knowledge Management
Requirements
Knowledge & Experience / Qualifications
  • Proven management of Information Technology, Cybersecurity and/or Cryptography technology.
  • Proven ability to manage and deliver tasks and initiatives independently following DevOps of similar practices.
  • Ability to communicate and collaborate with colleagues, stakeholder and 3rd parties locally and around the world. Proven business level proficiency in English and Mandarin, Cantonese would be a plus.
  • Ability to lead and sustain changes to ensure lasting benefits.
  • Ability to prioritize, report and resolve complex technical and business issue.
  • Minimum 5 year of IT system management or project experience with emphasis in cryptography related technology such as hardware security modules, software encryption and key management solution. To ensure a successful career, the following IT experience combination are highly desired:
1. Hands on experience in development or deployment of cryptographic solutions.
2. Manage a sustain operation of on-premises IT assets
3. Design and implement IT solutions to ensure data security
4. Working knowledge in Unix/Linux and basic knowledge of networking
  • Minimum 5 years of professional working experience in financial services industry, large corporations, technology vendors or international professional service firms.
  • Ability to work off hours (Especially in weekends)
  • Ability to commute to and from office and data centers.


HSBCVZ/GZ*

About HSBC Technology China

We develop, implement and support software and IT services and processes that allow HSBC to remain at the forefront of high-quality banking systems.

Candidate with less relevant experience or skills may be offered a lower Global Career Band than stated above.

(Due to the urgent hiring need, candidates with immediate right to work locally and no relocation need will be prioritised.)

You’ll achieve more when you join HSBC.

HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.”

Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.

申请
其他职位推荐:

Sales Program &Incentive Management Senior Analyst

Accenture
澳門, 澳門
3.有分析背景/有商业/excel/Power BI / salesforce.洞察能力强 ,专家分享; 团队管理经验是Better to Have
1周前

HR Service Delivery Senior Analyst-ES

Accenture
澳門, 澳門
1. 员工入职管理: 2. 员工在职管理: 3. 员工离职管理: 4. 员工数据管理: 5. 跨部门协作:
4天前

HR Service Delivery Senior Analyst-Payroll

Accenture
澳門, 澳門
1. 独立负责公司员工薪资核算及发放,确保及时性及准确性; 2. 独立完成工资报表的制作、复核及异常数据分析,编制并优化人员费用分析报告,为人力成本控制提供数据支持; 3....
4天前

Associate Director, Cybersecurity Specialist

HSBC
澳門
  • Green field opportunity, working with our transformation...
  • Acting as a pioneer to prove the developing approach you...
2周前

Steward-Lead

Marriott International
澳門, 澳門
艾美酒店以令人神往的旅遊時代為靈感,以歐洲文化對享受精彩人生的經典追求呈現每一種文化。我們的賓客是心懷好奇、滿蘊創意的大都會文化愛好者。他們期待每一次建立聯繫的機會,也喜歡放慢腳步細品當地風情。艾美酒店願為賓客提供令人難忘的特色服務與體驗,鼓舞他們享受精彩人生...
3周前

Officer-Loss Prevention-Lead

Marriott International
離島區, 香港
加入喜来登大家庭,成为我们全球社区的一员。自 1937 年以来,喜来登便是人们相聚一堂与彼此联谊的社群空间。喜来登员工在世界各地超过 400...
3周前

Baker-Lead

Marriott International
澳門
艾迪逊酒店能够在酒店行业颠覆传统定义、带来崭新体验,离不开精品酒店经营人伊恩·施拉格 (Ian Schrager)...
2周前

Sales Engineer, IOL

ZEISS Group
澳門
1. Finance Target :Own Order/ sales / AR / Loan budget in the territory 2. Sales Activity 3. Sales support on dealer 4. Operation...
1天前

Customer Transformation and Innovation Supervisor/Manager-Shanghai

Pfizer
Shanghai, 上海市
  • Support on BU strategy to go-to market model transforming...
  • Understand and apply the principles, practices, and ethics...
1天前

Supervisor-Kitchen

Marriott International
澳門, 澳門
JW 萬豪酒店是萬豪國際集團旗下的奢華飯店品牌,在全球各大城市和知名度假勝地擁有 100 多間飯店及度假飯店。JW 堅持以人為本的品牌文化,深信員工是我們的立足之本,有了快樂的員工,才有滿意的賓客。JW...
1天前