This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Head of Cloud Device Protection is responsible for developing and leading policy and strategies to protect device and processes hosted in “Cloud” ecosystems (Cattle, Containers and Serverless etc) and that they are working in line with HSBC Cloud strategies. They are responsible for ensuring that the right processes and escalations are in place and consistent across the different Cloud environments to ensure effective operation of capabilities. Key activities include implementation and oversight of the Group’s Risk Management Framework, ongoing and targeted controls assessments, implementing and maintaining robust risk governance, and championing a proactive risk culture. GCIO CCO works closely with partners across all lines of defence and is responsible for maintaining positive relationships with our regulators and external partners.
Job Responsibility:
Developing and leading policy and strategies to protect device and processes hosted in “Cloud” ecosystems (Cattle, Containers and Serverless etc) and that they are working in line with HSBC Cloud strategies
Ensuring that the right processes and escalations are in place and consistent across the different Cloud environments to ensure effective operation of capabilities
Implementation and oversight of the Group’s Risk Management Framework
Ongoing and targeted controls assessments
Implementing and maintaining robust risk governance
Championing a proactive risk culture
Maintaining positive relationships with our regulators and external partners
Managing relationships with key stakeholders with in the relevant Cloud Service Provider Teams within HSBC
Reviewing Coverage and Compliance across the Cloud Environments and Escalating as required
Collaborating with other Cloud related Security teams like Security Operations, Incident Management and Cloud Security to ensure joined up decisions are made
Tracking and oversight to completion for formal risk tickets
Respond to queries from Audits and regulators on the protections in place and their effectiveness
Analyse available data related to issue (which could include native logs or captured telemetry to assist in driving issue remediations
Requirements:
A background in information systems, technology, architecture, design, and service delivery of defense-in-depth capabilities
Strong stakeholder management skills, with experience of understanding and meeting the needs of multiple stakeholders
An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily understood, authoritative and actionable manner
Likely from a technology or engineering background with developed understanding of Technology Delivery Lifecycle, engineering practices, underlying infrastructure, tooling and architecture & design principles
Deep SME knowledge of containers
Experience working in a highly regulated, large multi-national environment
Ability to understand the potential business impact of security decisions and align initiatives with business needs
Strong inter-personal skills to work effectively with other areas inside and outside of cyber
What we offer:
Additional car allowance in the amount of 4,620 PLN (monthly, gross)
Variable pay
Comprehensive and competitive package of benefits covering healthcare, family friendly leaves, pension and life assurance
Competitive salary
Annual performance-based bonus
Additional bonuses for recognition awards
Multisport card
Private medical care
Life insurance
One-time reimbursement of home office set-up (up to 800 PLN)