Associate Director, Crew Lead
HSBC View all jobs
- Xi'an, Shaanxi
- Permanent
- Full-time
- Lead/perform and own the design and delivery of penetration tests across variety of technologies.
- Work within virtual teams of security and technical specialists to ensure quality delivery of world class security solutions to the business.
- Lead penetration tests designed to highlight and clearly articulate risk to the business, in terms the business can understand.
- Drive and lead penetration tests and resulting deliverables, to aid in ensuring that the Bank operates within defined risk appetite
- Represent Cybersecurity function as technical SME in internal and external discussions.
- Help drive the maturity of Cybersecurity function by continuously improving quality of our services and removing inefficiencies, in line with wider Cybersecurity strategy.
- Ensure adherence to the three lines of defence organisational model, with clear lines of responsibility, accountability and segregation of duties.
- Ensure compliance with internal audit and external regulators, to ensure that any organisational changes are fit for purpose and meet their expectations.
- Collaborate with relevant stakeholders to enhances the delivery of a Cybersecurity strategy to secure the bank’s technology, protecting and enhancing HSBC’s values, reputation and stakeholder value.
- Provide supervision, guidance and mentor less experienced members of a team
- Perform highly technical/analytical security assessments of custom mobile applications, widely understood infrastructure and networks, web services and APIs. This covers manual penetration testing, source code and configuration review.
- Clearly and professionally document root cause and risk analysis of all findings
- Adhere to the security testing process and raise any gaps or opportunities for improvement with manager.
- Work closely with the DevOps teams to ensure that the security testing requirements are met and help automate repetitive tasks.
- Develop understanding of business functionality and apply testing methodology as appropriate to technologies and risks
- Code and demonstrate basic proof-of-concept exploits of vulnerabilities when required.
- Assist with coordination of security testing projects according to a structured process, including writing test plans, test cases and test reports.
- Advise on vulnerability remediation, control implementation and secure development practices
- Assess product release risk and complexity and identify potential misuse scenarios through review of business requirements and design specifications
- Assist with tracking, remediation, and risk acceptance for identified security vulnerabilities.
- Assist in planning, test execution and vulnerability mitigation
- Ensure that company security policies are implemented, enforced, and enhanced when appropriate
- Participate in team discussions to formulate new or enhance existing processes and standards
- Assist in security incident response activities
- Adhere strictly to compliance and operational risk controls in accordance with company and regulatory standards, policies and practices; report control weaknesses, compliance breaches and operational loss events
- Run evaluations of new security testing technologies and provide recommendations.
- Monitor security industry information sources and keep abreast of events, research, and developments.
- Identify opportunities to improve our processes, quality of the work and efficiencies.
- Mentor junior team members
- Other responsibilities as assigned.