ABOUT THE PROJECT
Global Defense – Cybersecurity Engineering and Operations is responsible for fielding solutions that help defend the companyagainst a wide range of threats to the business as well as its customers, clients, partners, and staff. The team works in concert, with partner teams across, to implement novel defensive capabilities that are effective and adaptable against a constantly evolving threat landscape. The function operates under the vision: “Enabling they to be safely successful everywhere the Firm chooses to do business”
Global Defense – Cybersecurity Engineering and Operations is comprised of several inter-joined team. Together, the function enables an adaptive and constantly evolving capacity to address risks borne through an ever-shifting threat landscape. The function serves as an engine for innovation and problem solving with partner teams across the Firm who share a common imperative to be the best for our customers and drive the Global they Purpose of “Opening up a world of opportunity”.
YOUR RESPONSIBILITIES
The Cybersecurity Controls SME role-holder is charged with protecting the company brand, shareholder value, information and financial assets, across the globe in the following ways:
– Supporting the delivery and operating Strategy
– Providing key representation for and source of expertise on all issues.
– Support the delivery of tooling to implement controls ensuring compliance with HSBC Information Security policies and standards globally including any regulatory requirements.
– Collaborate to drive the implementation of the enterprise wide and regional / business level IT Strategy.
– Ensure information security requirements are adhered to globally by ensuring effective compliance and measures are in place.
– Work closely with the team as the 1LOD function and understand strategy while maintaining visibility of their IT security risk profile, exposures and control effectiveness and to provide robust challenge to the same audience when information security risk appetites are breached.
– Drive engagement with all relevant regional and global stakeholders (cyber security colleagues across Strategy and Architecture, Security Shared Services, Security Engineering and business and IT Functions).
REQUIRED
– Strong knowledge of Network Security and related risks
– Good understanding and knowledge of common industry cyber security frameworks, standards and methodologies, including; OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines, CIS and NIST standards.
– Wide range of cyber experience across Cybersecurity Technology
– Proven experience of successful operational management, utilising relevant tools and techniques to ensure consistent delivery
– A minimum of 2/3 years Cyber experience would be beneficial
SKILLS & EXPERIENCE WE REQUIRE
Skills
– An enabler who drives change and improvement initiatives.
– Practices the art of simplification.
– Ability to listen and understand others challenges and drive solutions.
– Ability to build strong internal and external relationships with a global team.
– Instinctive and creative.
– Strong problem-solving and trouble-shooting skills.
– Strong communication and interpersonal skills, with proven ability to communicate technical topics to diverse audiences.
– Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
– Ability to learn quickly through hands on experience.
– Ability to document bugs, proposed fixes, and operational instructions.
– Experience defining and refining operational procedures, workflows and processes to support the team in consistent, quality execution of monitoring and detection
– An understanding of business needs and commitment to delivering high-quality, prompt and efficient service to the business.
– An understanding of organisational mission, values and goals and consistent application of this knowledge.
– Self-motivated and possessing of a high sense of urgency and personal integrity.
– Highest ethical standards and values.
– Knowledge of cyber security principles, global financial services business models, regional compliance regulations and laws.
– Ability to speak, read and write in English, in addition to your local language.
Technical Skills
– Strong knowledge of Network Security and related risks
OPTIONAL
– Formal education in Information Security, Cybersecurity, Computer Science or similar and/or commensurate demonstrated work experience.
– Experience working in a highly regulated environment
– Promoted and led best practice in risk and compliance management in a similar organization
– A track record of making strategic business decisions, considering relevant risks, long term implications, commercial realities, and stakeholders&needs
– Comprehensive understanding of security in context of wider industry trends and direction
– Experience of working in a financial organisation would be beneficial
WHAT WE OFFER
– Stable job in professional team,
– Interesting path of career in an international organization,
– Consistent scope of responsibilities,
– Private health care, employees’ benefits.
Note: Prepare your CV in English (PDF), fill in the form and apply!
Please include in your CV the following clause necessary for the recruitment process:
I agree to the processing of personal data that I have made available voluntarily in the recruitment process by the Administrator of personal data, i.e. Dotcommunity Spółka z ograniczoną odpowiedzialnością [Ltd.] based in Cracow, 15 Żabiniec Street, 31-215 Cracow, registered in Poland, the Cracow’s District Court – Śródmieście, XI Commercial Division of the National Court Register under number 0000468484, VAT number: 9452174499, (“Dotcommunity”) in order to carry out the recruitment process for the Network Security Controls Analyst position on the basis of Art.6 item 1a of the Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
Dotcommunity jest zarejestrowana w Rejestrze agencji zatrudnienia (KRAZ) pod numerem 9904.