This role combines Vulnerability Management Assessment and Vulnerability Management Operations responsibilities. You will help protect HSBC by delivering high-quality assessments, effective remediation governance, accurate reporting, and strong cross-team coordination.
You will partner with Cyber Security Assessment Testing Teams, Cyber Threat Intelligence, Incident Management & Response, Perimeter Security, Cloud teams, Federated Control Owners and CCO Technology stakeholders. The role operates as part of the 1LoD in relation to the risk management framework.
As part of maintaining strong governance, support internal and external audits and regulatory responses, working with the VM Governance team and 2LoD providing clear, well‑evidenced documentation.
Key accountabilities:
- Use Claude and GitHub Copilot to support delivery and productivity.
- Understanding of the NIST AI Risk Management approved Framework.
- Have knowledge of agent/harness fundamentals and how they enable repeatable workflow automation.
- Apply strong data analytics to improve insight, prioritisation and reporting quality.
- Support vulnerability growth driven by Frontier AI models.
- Track remediation end-to-end, ensuring plans are maintained by key stakeholders within the central planning platform and driving actions via regular discussions.
- Improve VM operating models; identify gaps and define uplift plans, roadmaps and future state to improve customer satisfaction.
- Look for opportunities to utilise Automation and AI to enhance and streamline existing processes.
- Monitor operational channels, triage issues and coordinate updates with Cybersecurity Engineering and stakeholders.
- Engagement with the Red Team to strengthen the remediation approach.
- Respond promptly to emerging threats using relevant intelligence and analysis.
- Apply knowledge and or experience of application security scanning techniques aligned to attacker tactics, techniques and procedures.
- Perform reviews and provide consultancy across Infrastructure, SDLC Platforms (SAST, MAST, DAST, FOSS)
- Ensure outcomes are satisfactory, managed and documented for governance, audit and continuous improvement.
- Lead stakeholder consultancy to ensure requirements are understood end-to-end, bridging technical and non-technical perspectives to drive effective assessment outcomes. For both infrastructure and application related weaknesses.
Essential Knowledge, Skills and Experience:
- Experience in threat & vulnerability management (or similar).
- Understand LLMs, including core inference concepts and practical use.
- Understand Attack Surface Management and attack paths.
- Business analytical skills to improve insight, prioritisation and reporting quality.
- Experience with using AI such as Claude, Frontier and other LLMs, plus Copilot.
- Understanding of Cloud technologies.
- Experience with Teams, JIRA, ServiceNow, SharePoint, GitHub, Confluence.
- Knowledge of standards and sources: CVEs, CWEs, CISA, NVD, MITRE, CVSS.
- Strong stakeholder management and communication; ability to produce Senior Management-ready updates.
- Work accurately under pressure; sound judgement and decision-making.
- High integrity and strong ethical values.
We offer:
- A full-time contract (B2B also possible)
- All necessary work equipment is provided by us (computer, monitor etc).
- Certification and training opportunities
- After completion of the project, opportunity to engage in a subsequent one within the company.
- Medicover medical care with dental care
- Medicover Benefits platform / Medicover Sport card
- Collaboration with Mistral AI
- Employee referral program
- Group life insurance
- Opportunity to relocate and work in different ALTEN Polska branches