×
Register Here to Apply for Jobs or Post Jobs. X

Cyber Lead - DevSecOps; CTO

Job in Sheffield, South Yorkshire, S5, England, UK
Listing for: HSBC Group
Full Time position
Listed on 2026-09-12
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant
Salary/Wage Range or Industry Benchmark: 40000 - 75000 GBP Yearly GBP 40000.00 75000.00 YEAR
Job Description & How to Apply Below
Position: Cyber Lead - DevSecOps (CTO)

Salary: £40,000 - 75,000 per year

Requirements:
  • We require significant information security experience with depth in application security, Dev Sec Ops , platform security, and/or technical cyber consulting in a regulated environment.
  • We require hands-on App Sec tooling and practices, including SAST, DAST, SCA, secrets management, secure SDLC, and threat modelling.
  • We require working knowledge of software supply chain security, including SBOM and dependency risk governance.
  • We require a solid understanding of AI and ML security risks, including prompt injection, training data integrity risks, model extraction, and agentic AI threats.
  • We require the ability to communicate technical risk clearly to senior stakeholders, translating it into business impact, regulatory exposure, and remediation priorities.
  • We require strong written and spoken communication in fluent English for both technical and non-technical audiences.
  • We require confidence operating within information security governance, policy, and risk expectations, including risk register management, escalation, and reporting.
  • We require the ability to partner effectively with Cyber Delivery and central cyber functions to align prioritisation, elevate delivery issues, and contribute to path-to-green control improvement initiatives.
Responsibilities:
  • We act as the cybersecurity SME for the assigned technology organisation, providing technical advisory across programmes, projects, incidents, and IT outages.
  • We build strong partnerships across the ET CISO organisation, central cyber teams, and technology stakeholders such as Architecture and engineering teams.
  • We own the divisional application security programme, embedding security-by-design across SDLC and Dev Sec Ops , including SAST, DAST, SCA, and secrets management in CI/CD.
  • We define and maintain secure coding standards, security acceptance criteria, and threat modelling processes for engineering teams.
  • We partner with engineering teams to triage and prioritise vulnerabilities, ensuring remediation SLAs are met using CVSS and EPSS-informed prioritisation.
  • We oversee penetration testing scope and manage findings through to remediation with clear CISO-level reporting on security posture.
  • We govern the security of the internal developer platform and toolchain, including source control, build systems, package registries, container platforms, secrets management, and internal API gateways.
  • We establish and run the divisional software supply chain security programme, including SBOM generation, open-source dependency risk, and third-party component governance aligned to DORA and NCSC guidance.
  • We shape the divisional AI security function, including AI threat models and governance aligned to the EU AI Act, our AI risk framework, and relevant PRA and FCA guidance.
  • We own the divisional information security risk register, providing tailored reporting to senior stakeholders and supporting regulatory engagement, internal audit, and second-line reviews.
Technologies:
  • Agentic AI
  • AI
  • API
  • CI/CD
  • Dev Sec Ops
  • Support
  • Network
  • Security
  • Dev Ops
  • Embedded
More:

We are HSBC, one of the largest banking and financial services organisations in the world, with a network covering more than 50 countries and territories. This senior Vice President role sits within Enterprise Technology engineering in the 1st Line of Defence, combining Cybersecurity Technical Lead and Business Information Security Officer accountabilities for Technology, Platforms & AI. We offer opportunities, support, and rewards that help careers go further, along with tailored professional development, private healthcare for UK-based employees, enhanced maternity and adoption pay, and a contributory pension scheme with a generous employer contribution.

We are committed to diversity, inclusion, and accessible careers, and we support candidates who meet the minimum criteria.

last updated 36 week of 2026

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary