Cyber Lead - DevSecOps (CTO)

HSBC Group

Sheffield

On-site

GBP 40,000 - 75,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Private healthcare
Enhanced maternity & adoption pay
Contributory pension
Professional development

Job summary

HSBC Group in the United Kingdom seeks a Senior Vice President to lead divisional information security, owning the application security programme and governance for technology, platforms and AI. You will embed security-by-design across SDLC and DevSecOps, oversee SBOM and dependency risk, and report to CISO-level governance with strong business impact translations.

You will collaborate with ET CISO, central cyber teams, and engineering stakeholders to triage vulnerabilities and mentor teams on

Qualifications

  • Significant information security experience with depth in application security, DevSecOps, platform security, and/or technical cyber consulting in a regulated environment.
  • Hands-on AppSec tooling and practices, including SAST, DAST, SCA, secrets management, secure SDLC, and threat modelling.
  • Working knowledge of software supply chain security, including SBOM and dependency risk governance.
  • Solid understanding of AI and ML security risks, including prompt injection, training data integrity risks, model extraction, and agentic AI threats.
  • Ability to communicate technical risk clearly to senior stakeholders, translating it into business impact, regulatory exposure, and remediation priorities.
  • Strong written and spoken communication in fluent English for technical and non-technical audiences.
  • Confidence operating within information security governance, policy, and risk expectations, including risk register management, escalation, and reporting.
  • Ability to partner with Cyber Delivery and central cyber functions to align prioritisation, elevate delivery issues, and contribute to path-to-green control improvement initiatives.

Responsibilities

  • Act as the cybersecurity SME for the assigned technology organisation, providing technical advisory across programmes, projects, incidents, and IT outages.
  • Build strong partnerships across the ET CISO organisation, central cyber teams, and technology stakeholders such as Architecture and engineering teams.
  • Own the divisional application security programme, embedding security-by-design across SDLC and DevSecOps, including SAST, DAST, SCA, and secrets management in CI/CD.
  • Define and maintain secure coding standards, security acceptance criteria, and threat modelling processes for engineering teams.
  • Partner with engineering teams to triage and prioritise vulnerabilities, ensuring remediation SLAs are met using CVSS and EPSS-informed prioritisation.
  • Oversee penetration testing scope and manage findings through to remediation with clear CISO-level reporting on security posture.
  • Govern the security of the internal developer platform and toolchain, including source control, build systems, package registries, container platforms, secrets management, and internal API gateways.
  • Establish and run the divisional software supply chain security programme, including SBOM generation, open-source dependency risk, and third-party component governance aligned to DORA and NCSC guidance.
  • Shape the divisional AI security function, including AI threat models and governance aligned to the EU AI Act, our AI risk framework, and relevant PRA and FCA guidance.
  • Own the divisional information security risk register, providing tailored reporting to senior stakeholders and supporting regulatory engagement, internal audit, and second-line reviews.

Skills

Information security
Regulated environments
Communication to senior stakeholders

Tools

SAST
DAST
SCA
Secrets management
Secure SDLC
Threat modelling

Job description

Salary: £40,000 - 75,000 per year

Requirements:
  • We require significant information security experience with depth in application security, DevSecOps, platform security, and/or technical cyber consulting in a regulated environment.
  • We require hands-on AppSec tooling and practices, including SAST, DAST, SCA, secrets management, secure SDLC, and threat modelling.
  • We require working knowledge of software supply chain security, including SBOM and dependency risk governance.
  • We require a solid understanding of AI and ML security risks, including prompt injection, training data integrity risks, model extraction, and agentic AI threats.
  • We require the ability to communicate technical risk clearly to senior stakeholders, translating it into business impact, regulatory exposure, and remediation priorities.
  • We require strong written and spoken communication in fluent English for both technical and non-technical audiences.
  • We require confidence operating within information security governance, policy, and risk expectations, including risk register management, escalation, and reporting.
  • We require the ability to partner effectively with Cyber Delivery and central cyber functions to align prioritisation, elevate delivery issues, and contribute to path-to-green control improvement initiatives.
Responsibilities:
  • We act as the cybersecurity SME for the assigned technology organisation, providing technical advisory across programmes, projects, incidents, and IT outages.
  • We build strong partnerships across the ET CISO organisation, central cyber teams, and technology stakeholders such as Architecture and engineering teams.
  • We own the divisional application security programme, embedding security-by-design across SDLC and DevSecOps, including SAST, DAST, SCA, and secrets management in CI/CD.
  • We define and maintain secure coding standards, security acceptance criteria, and threat modelling processes for engineering teams.
  • We partner with engineering teams to triage and prioritise vulnerabilities, ensuring remediation SLAs are met using CVSS and EPSS-informed prioritisation.
  • We oversee penetration testing scope and manage findings through to remediation with clear CISO-level reporting on security posture.
  • We govern the security of the internal developer platform and toolchain, including source control, build systems, package registries, container platforms, secrets management, and internal API gateways.
  • We establish and run the divisional software supply chain security programme, including SBOM generation, open-source dependency risk, and third-party component governance aligned to DORA and NCSC guidance.
  • We shape the divisional AI security function, including AI threat models and governance aligned to the EU AI Act, our AI risk framework, and relevant PRA and FCA guidance.
  • We own the divisional information security risk register, providing tailored reporting to senior stakeholders and supporting regulatory engagement, internal audit, and second-line reviews.
Technologies:
  • Agentic AI
  • AI
  • API
  • CI/CD
  • DevSecOps
  • Support
  • Network
  • Security
  • DevOps
  • Embedded
More:

We are HSBC, one of the largest banking and financial services organisations in the world, with a network covering more than 50 countries and territories. This senior Vice President role sits within Enterprise Technology engineering in the 1st Line of Defence, combining Cybersecurity Technical Lead and Business Information Security Officer accountabilities for Technology, Platforms & AI. We offer opportunities, support, and rewards that help careers go further, along with tailored professional development, private healthcare for UK-based employees, enhanced maternity and adoption pay, and a contributory pension scheme with a generous employer contribution. We are committed to diversity, inclusion, and accessible careers, and we support candidates who meet the minimum criteria.

last updated 36 week of 2026

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Lead - DevSecOps (CTO)
Cyber Lead - DevSecOps (CTO)

HSBC • Sheffield

On-site
GBP 90,000 - 130,000
Private healthcare for all UK-based em
Enhanced maternity and adoption pay
Contributory pension scheme
Senior DevSecOps & AI Security Lead
Senior DevSecOps & AI Security Lead

HSBC • Sheffield

On-site
GBP 90,000 - 130,000
Private healthcare for all UK-based em
Enhanced maternity and adoption pay
Contributory pension scheme
Technical Cyber Security Advisory, Vice President
Technical Cyber Security Advisory, Vice President

State Street Corporation • Greater London

Hybrid
GBP 140,000 - 200,000
Senior DevSecOps Lead – AI & SBOM Security
Senior DevSecOps Lead – AI & SBOM Security

HSBC Group • Sheffield

On-site
GBP 40,000 - 75,000
Private healthcare
Enhanced maternity & adoption pay
Contributory pension
+1
Senior Cyber Threat & Vulnerability Manager
Senior Cyber Threat & Vulnerability Manager

McCabe & Barton • Eastbourne

Hybrid
GBP 110,000 - 150,000
Excellent benefits
Flexible working
Head of Cyber Security - Global Investment Firm
Head of Cyber Security - Global Investment Firm

Orbis Group • Greater London

On-site
GBP 160,000 - 200,000
Competitive bonus
Cyber Security Lead
Cyber Security Lead

Chambers & Partners • Greater London

Hybrid
GBP 90,000 - 130,000
Technical Cyber Security Advisory, Vice President
Technical Cyber Security Advisory, Vice President

State Street • Greater London

Hybrid
GBP 140,000 - 230,000
Security Technical Delivery Manager - VP Level
Security Technical Delivery Manager - VP Level

Computappoint • City Of London

Hybrid
GBP 110,000 - 130,000
Hybrid working
Bonus opportunities
Competitive benefits
Lead Cyber Security Engineer
Lead Cyber Security Engineer

Huxley Associates • Greater London

On-site
GBP 140,000 - 190,000