Cyber Lead - Group Functions Technology

HSBC Group

Sheffield

On-site

GBP 90,000 - 130,000

Full time

7 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Private healthcare
Pension scheme
Enhanced maternity & adoption pay

Job summary

HSBC Group is seeking a senior cybersecurity leader to act as the trusted partner for Group Functions Technology, shaping cyber risk, governance and control priorities across Risk, Finance, Treasury and corporate functions.

You will advise senior technology and business stakeholders, drive risk-based remediation, and ensure evidence-based assurance across complex SaaS and third-party environments.

Qualifications

  • Significant cybersecurity experience in a regulated organisation.
  • Experience advising senior technology and business stakeholders.
  • Strong cyber risk, governance and controls capability.
  • Excellent written and spoken English; ability to chair governance forums.

Responsibilities

  • Act as the senior cybersecurity partner for GFT domains, advising leadership on material cyber risks and trade-offs.
  • Own and drive the cyber risk profile, maintain risk registers and remediation plans.
  • Lead control governance and assurance readiness with timely evidence and closure of findings.
  • Embed security-by-design across change delivery and supplier/SaaS risk management.
  • Provide leadership during incidents and produce decision-grade reporting for senior stakeholders.
  • Translate technical exposures into business impacts for governance forums.

Skills

Cyber risk governance
Controls & assurance
Incident management
Executive reporting
Security-by-design
Identity & access
Threat management
Vulnerability management
Data protection
Cloud risk
Third-party risk
Audit liaison
Communication

Job description


  • Put the customer at the heart of everything we do in protecting the bank.

  • Act as the senior cybersecurity partner for GFT domains (Risk/Finance/Treasury/Corporate Functions), advising leadership and delivery teams on material cyber risks, control expectations and risk-based trade-offs to meet business outcomes.

  • Own and drive the cyber risk profile: maintain the risk register, ensure risks are clearly articulated (cause-event-impact), prioritised, and managed with accountable owners and timebound remediation plans.

  • Lead control governance and assurance readiness: coordinate control assessments, thematic reviews and audit activity; ensure high-quality evidence, timely closure of findings and sustainable improvement plans.

  • Embed proportionate security-by-design across change delivery: provide risk-based input to solution designs, delivery plans and acceptance criteria to reduce recurring risk patterns and improve control-by-default outcomes.

  • Oversee supplier and SaaS cyber risk: support onboarding/renewals, drive mitigations for access, data protection, logging/monitoring, incident obligations, resilience and exit/lock-in risks.

  • Strengthen in-service security posture by influencing technical and control priorities for identity and access risk (including privileged access), threat, exposure & vulnerability management, logging/monitoring coverage and configuration weaknesses.

  • Provide cybersecurity leadership support during incidents and major service events, ensuring appropriate engagement with specialist teams and clear, risk-based decisions and communications.

  • Produce concise, decision-grade reporting for senior stakeholders and governance forums, translating technical exposures into business impacts (e.g., financial reporting, payroll, liquidity activity, regulatory submissions).

    Significant experience in cybersecurity within a regulated organisation, with credibility to advise senior technology and business stakeholders.


  • Strong cyber risk, governance and controls capability: risk identification and articulation, issue management, control mapping, remediation planning/tracking, and audit/assurance engagement.

  • Solid technical foundation across enterprise security domains, such as identity and access, threat, exposure & vulnerability management, logging/monitoring, data protection, cloud/SaaS risk and third-party risk, application security & AI.

  • Ability to translate technical findings into business impact and clear decision options.

  • Strong written and spoken communication (fluent English), confident chairing/facilitating governance forums and challenging constructively.

  • Collaborative, outcome-driven approach; able to drive delivery through influence in a complex stakeholder environment.

  • Desirable

  • Certifications such as ISO27001, CISA, CISM, CISSP, CRISC, CEH (or equivalent).

  • Experience supporting technology for Finance/Treasury/Risk domains and/or corporate functions, including sensitivity to financial controls and regulatory reporting.

  • Experience with third-party assurance and SaaS security risk management.

  • Familiarity with operational resilience and technology risk expectations within financial services.

    If you're looking for a career that will help you stand out, join HSBC, and fulfil your potential - whether you want a career that could take you to the top, or an exciting new direction, we offer opportunities, support and rewards that will take you further. We're one of the largest banking and financial services organisations in the world, with a network that covers more than 50 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people fulfil their hopes and realisetheir ambitions. This is a senior cybersecurity leadership role within Group Functions Technology (GFT), supporting the technology that underpins Risk, Finance and Treasury and a range of corporate functions. You'll act as the cyber partner to GFT technology leadership and teams delivering and operating technology across Risk, Finance and Treasury, and wider corporate functions and tech centres. The role ensures that cyber risk is identified, assessed, prioritised and managed within risk appetite, that controls are implemented and evidenced effectively, and that cyber design and technology considerations are embedded into change and operations proportionately. This is a balanced Cyber Lead role combining risk, governance and controls with a strong technical foundation., Being open to different points of view is important for our business and the communities we serve. At HSBC, we're dedicated to creating diverse and inclusive workplaces - no matter their gender, ethnicity, disability, religion, sexual orientation, socio-economic background or age. We are committed to removing barriers and ensuring careers at HSBC are inclusive and accessible for everyone to be at their best. We take pride in being a Disability Confident Leader and will offer an interview to people with disabilities, long term conditions or neurodivergent candidates who meet the minimum criteria for the role. As an HSBC employee in the UK, you'll have access to tailored professional development opportunities and a competitive pay and benefits package. This includes private healthcare for all UK-based employees, enhanced maternity and adoption pay and support when you return to work, and a contributory pension scheme with a generous employer contribution.


Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Lead - DevSecOps (CTO)
Cyber Lead - DevSecOps (CTO)

HSBC • Sheffield

On-site
GBP 90,000 - 130,000
Private healthcare for all UK-based em
Enhanced maternity and adoption pay
Contributory pension scheme
Senior Control Manager
Senior Control Manager

HSBC Group • Sheffield

On-site
GBP 90,000 - 120,000
Head of Portfolio & Accountability Management, Cybersecurity
Head of Portfolio & Accountability Management, Cybersecurity

HSBC • Sheffield

On-site
GBP 80,000 - 100,000
Senior Control Manager
Senior Control Manager

HSBC • Sheffield

On-site
GBP 90,000 - 130,000
Private healthcare
Pension scheme
Head of Infrastructure Security Controls and Delivery Oversight
Head of Infrastructure Security Controls and Delivery Oversight

HSBC • Sheffield

On-site
GBP 120,000 - 150,000
Technology Delivery Manager
Technology Delivery Manager

HSBC • Sheffield

Hybrid
GBP 45,000 - 75,000
Senior Manager, ERM Risk Steward HCIB and CIB
Senior Manager, ERM Risk Steward HCIB and CIB

HSBC • Glasgow

On-site
GBP 95,000 - 130,000
Private healthcare for UK employees
Enhanced maternity and adoption pay
Contributory pension scheme
Senior Manager, ERM Risk Steward HCIB and CIB
Senior Manager, ERM Risk Steward HCIB and CIB

HSBC • Birmingham

On-site
GBP 90,000 - 130,000
Senior Data Risk Manager
Senior Data Risk Manager

HSBC • Greater London

On-site
GBP 110,000 - 150,000
Senior Manager, ERM Risk Steward HCIB and CIB
Senior Manager, ERM Risk Steward HCIB and CIB

HSBC • Sheffield

On-site
GBP 90,000 - 130,000