×
Register Here to Apply for Jobs or Post Jobs. X

GCS: NSEC Controls SME

Job in Town of Poland, Jamestown, Chautauqua County, New York, 14701, USA
Listing for: HSBC
Full Time position
Listed on 2025-12-18
Job specializations:
  • IT/Tech
    Cybersecurity, Systems Engineer
Job Description & How to Apply Below
Location: Town of Poland

Some careers shine brighter than others.

If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.

Your career opportunity

Technology teams in the UK work closely with our global businesses to help design and build digital services that allow our millions of customers around the world, to bank quickly, simply and securely. They also run and manage our IT infrastructure, data centres and core banking systems that power the world’s leading international bank.

Our multi-disciplined teams include Dev Ops engineers, IT architects, front and back-end developers, infrastructure specialists, cyber experts, as well as project and programme managers.

Cybersecurity is responsible for fielding solutions that help defend HSBC against a wide range of threats to the business as well as its customers, clients, partners, and staff. The team works in concert, with partner teams across HSBC, to implement novel defensive capabilities that are effective and adaptable against a constantly evolving threat landscape. The function operates under the vision: “Enabling HSBC to be safely successful everywhere the Firm chooses to do business.”

Cybersecurity Technology and Engineering (CTE) – Cybersecurity Engineering and Operations is comprised of several inter-joined teams:
Technical Directors Office (TDO), Site Reliability Engineering (SRE), CTE Governance & Delivery, Global Cybersecurity Operations (GCO) and Cybersecurity Intelligence & Threat Analysis (CITA). Together, the function enables an adaptive and constantly evolving capacity to address risks borne through an ever-shifting threat landscape. The function serves as an engine for innovation and problem solving with partner teams across the Firm who share a common imperative to be the best for our customers and drive the Global HSBC Purpose of “Opening up a world of opportunity.”

What

you’ll do
  • Play a key role in the design and maintenance of the Cybersecurity control environment.
  • Define and maintain operational controls instances, their measurements as well as Policies, Standards and Procedures for Group Cybersecurity.
  • Work with Control Owners, 2

    LoD and CCO Technology to ensure that the Cybersecurity owned controls in the Risk and Controls Library are designed according to the Bank’s requirements and industry standards and best practices (e.g. NIST 800-53).
  • Support the Control Owners and other stakeholders to ensure that Cybersecurity control measurements are defined in accordance with HSBC’s KCI Design Framework and industry best practices (CIS).
  • Work with CTE and CMT teams to ensure that the defined controls are compliant with Legal/Regulatory Mandatory requirements and that measurements provide sufficient data for stakeholder reports.
  • Support the NSEC Control Owner with the design, management and maintaining Policies, Standards and Procedures for Cybersecurity controls, covering all areas across Engineering, Operations and Security Assessment and Testing.
  • Organisational reporting:
    The role will report functionally and organisationally into the Cybersecurity Technology and Engineering Governance unit.
What you need to have to succeed in this role
  • Strong Risk and Controls Background:
    Subject matter expertise in Control Management. This includes but is not limited to controls design and implementation and control assessment;
    Ability to translate IT concepts into business-friendly language.
  • Technical background:
    Knowledge of Cybersecurity – at least a generalist with specialist area expertise welcome. Well understanding of Network Security Domain will be a plus;
    Possession of recognised certificates will be an advantage;
    Understanding of metrics and measures in managing risks and controls (KCIs, KRIs, KPIs) is an advantage;
    Technical writing skills and highly proficient use of written English is required to ensure quality output for Control, Policies, Procedure and Standards design and maintenance.
  • Strong stakeholder engagement and communications skills:

    Expe…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary