GSC: Vulnerability Management Response Lead
Some careers shine brighter than others.
If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.
Your career opportunityOur Technology teams work closely with HSBC’s global businesses to help design and build digital services that allow our millions of customers around the world: to bank quickly, simply and securely. We also run and manage our IT infrastructure, data centres and core banking systems that power the world’s leading international bank.
Our multi-disciplined Technology teams include amongst others:
Dev Sec Ops engineers, IT architects, front and back-end developers, infrastructure specialists, cybersecurity experts, and delivery, project and programme managers.
Global Cybersecurity is responsible for enabling businesses and functions to manage their information, technology and cybersecurity risks by ensuring these are well-understood, and that controls used to manage such events are defined, assessed and implemented appropriately. Cybersecurity predominantly delivers this via objective, independent, professional and specialized subject matter experts. The role forms part of the 1
LoD in relation to the risk management framework.
The Cybersecurity Assessment and Testing (CSAT) function, part of Global Cybersecurity, is accountable for Vulnerability Management, Secure Development (inc. Dev Sec Ops ), Threat and Controls Assessment (inc. Threat Modelling) Application Security (App Sec)/ Penetration Testing, Third Party Security Review (TPSR) and Red team/ Security Research. The function drives the identification, capture, assessment, testing/ verification and ultimately the remediation of security defects, gaps and vulnerabilities across HSBC’s estate in concert with business and technology teams - on-premise, within the Cloud and for those resulting from 3rd party engagements.
The Vulnerability Response Lead is a key role within the Vulnerability Management Response & Remediation team and the wider Cyber Security Vulnerability Management function. The role will report into the Head of Vulnerability Management Response & Remediation.
What you’ll do- Support the remediation efforts of newly discovered vulnerabilities, where the risk score is deemed critical and an immediate risk to HSBC.
- Monitor external threat feeds and Cyber Intelligence Threat Analysis to identify any newly reported external risks.
- Manage the documentation of FRTF and ITAG initiatives and providing / identifying expert advice & guidance on remediation approaches. Track and report of ITAG and FRTF initiatives, as well as producing closure reports for completed ITAG’s and FRTF’s.
- Follow operational processes and ensure that they provide the most streamlined and efficient method of operations, whilst identifying opportunities for improvement. Support thematic reviews to drive and systematic uplifts and enhancements to services that help protect the bank. Maintain operational documentation on what reports are available and how / where to access them.
- Conduct holistic reviews of the overall baseline security posture.
- Contribute to and inform requests from Regulators, Internal/ External Audit, and 2
LOD challenges/ Papers. - Support the commentary for routine governance submissions e.g. Cybersecurity Executive Committee Monthly Update, Risk Map, KCIs, KRIs.
- Support Imminent threat review sessions, and deputising for the chair when required.
- Support the Head of Vulnerability Management Response and Remediation in leading the Vulnerability Management Response Team. Engage with the Global Head of Vulnerability Management, and other relevant team leads to review and gain approval for submissions, to ensure information requests are aligned with the group risk appetite providing the expected responses.
- Minimum of 3-5 years’ experience in working in IT Security or similar role. Experience of working in roles within Cyber Security Operations, Risk Management, and Governance,…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).