×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Head of Infrastructure Security Controls and Delivery Oversight

Job in Sheffield, South Yorkshire, S5, England, UK
Listing for: HSBC Group
Full Time position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Cybersecurity
Job Description & How to Apply Below
If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential - whether you want a career that could take you to the top, or an exciting new direction, we offer opportunities, support and rewards that will take you further.

We’re one of the largest banking and financial services organisations in the world, with a network that covers more than 50 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people fulfil their hopes and realise their ambitions.

We are seeking a Head of Infrastructure Security Controls and Delivery Oversight As an HSBC employee in the UK, you’ll have access to tailored professional development opportunities and a competitive pay and benefits package. This includes private healthcare for all UK-based employees, enhanced maternity and adoption pay and support when you return to work, and a contributory pension scheme with a generous employer contribution.

In this fantastic role, provide risk and controls leadership within the infrastructure security  this role, you will:

Provide risk and controls leadership within the Infrastructure Security domain (e.g., platform and OS hardening, secure configuration), in partnership with wider technology control owners. This includes how key security controls are embedded into infrastructure (people, process and technology), for example opportunities for MFA, and automated certificate management etc are embedded into OS, and supporting the oversight and challenge of the adequacy of security-focused ITOP control requirements, in partnership with the ITOP Control Owner.

Risk management:

maintain the accuracy and alignment of assigned controls to the bank’s Risk Control Framework, including control intent, scope, applicability, and ownership.

Control design and continuous control monitoring: drive enhancements to monitoring points / operating instructions where relevant and maintain and/or challenge a clear control effectiveness rationale.

Measurement: manage, report, and improve relevant control-centric metrics (e.g., KRIs/KCIs/KPIs), driving remediation plans where performance is off-track.

Compliance and assurance support: ensure controls align with relevant regulations, standards, and industry best practice; maintain internal control standards, including timely implementation of internal and external audit actions and responses to regulatory observations (in partnership with relevant teams).Provide specialist input to ensure control requirements are translated into cogent and practical engineering outcomes to support Infrastructure Security delivery. Enable the voice-of-the-engineer to feature in control redesign, supporting more effective ways to achieve control outcomes such as as-code approaches, in partnership with Engineering Enablement and B/GI engineering PEs.To

be successful in this role you should have the following skills:

Hands-on and robust Infrastructure Security experience and knowledge.

Strong technology background with a solid understanding of IT infrastructure and operations.

Demonstrable experience in cybersecurity controls governance / control ownership (proven success operating within a 2

LoD or 3

LoD team is beneficial).Experience overseeing delivery across multiple initiatives (portfolio/programme governance), including interdependencies, risks, issues, and benefits realisation.

Excellent stakeholder management skills, including engagement with audit, risk, and regulatory-facing teams.

Strong communication skills: able to translate complex technical/control requirements into clear expectations, decisions, and outcomes.

Proven problem-solving capability: able to identify control/process gaps and drive pragmatic remediation through the right teams.

Bachelor’s degree and/or equivalent experience in cybersecurity, technology, risk, or related disciplines.

Working knowledge of industry control frameworks (e.g., CIS/NIST-aligned approaches).Understanding of project and delivery methodologies (e.g., Agile/Waterfall); formal qualification beneficial but not mandatory given the oversight nature of the role.

Inclusi…
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary