HSBC Global Services Limited
Cyber Lead - Group Functions Technology

How your CV stacks up
Upload your CV to see how well it fits this job role
?%
If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential - whether you want a career that could take you to the top, or an exciting new direction, we offer opportunities, support and rewards that will take you further.
We’re one of the largest banking and financial services organisations in the world, with a network that covers more than 50 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people fulfil their hopes and realise their ambitions.
This is a senior cybersecurity leadership role within Group Functions Technology (GFT), supporting the technology that underpins Risk, Finance and Treasury and a range of corporate functions. You’ll act as the cyber partner to GFT technology leadership and teams delivering and operating technology across Risk, Finance and Treasury, and wider corporate functions and tech centres.
The role ensures that cyber risk is identified, assessed, prioritised and managed within risk appetite, that controls are implemented and evidenced effectively, and that cyber design and technology considerations are embedded into change and operations proportionately. This is a balanced Cyber Lead role combining risk, governance and controls with a strong technical foundation.
As an HSBC employee in the UK, you’ll have access to tailored professional development opportunities and a competitive pay and benefits package. This includes private healthcare for all UK-based employees, enhanced maternity and adoption pay and support when you return to work, and a contributory pension scheme with a generous employer contribution.
In this role you’ll:
- Put the customer at the heart of everything we do in protecting the bank.
- Act as the senior cybersecurity partner for GFT domains (Risk/Finance/Treasury/Corporate Functions), advising leadership and delivery teams on material cyber risks, control expectations and risk-based trade-offs to meet business outcomes.
- Own and drive the cyber risk profile: maintain the risk register, ensure risks are clearly articulated (cause–event–impact), prioritised, and managed with accountable owners and timebound remediation plans.
- Lead control governance and assurance readiness: coordinate control assessments, thematic reviews and audit activity; ensure high-quality evidence, timely closure of findings and sustainable improvement plans.
- Embed proportionate security-by-design across change delivery: provide risk-based input to solution designs, delivery plans and acceptance criteria to reduce recurring risk patterns and improve control-by-default outcomes.
- Oversee supplier and SaaS cyber risk: support onboarding/renewals, drive mitigations for access, data protection, logging/monitoring, incident obligations, resilience and exit/lock-in risks.
- Strengthen in-service security posture by influencing technical and control priorities for identity and access risk (including privileged access), threat, exposure & vulnerability management, logging/monitoring coverage and configuration weaknesses.
- Provide cybersecurity leadership support during incidents and major service events, ensuring appropriate engagement with specialist teams and clear, risk-based decisions and communications.
- Produce concise, decision-grade reporting for senior stakeholders and governance forums, translating technical exposures into business impacts (e.g., financial reporting, payroll, liquidity activity, regulatory submissions).
Reasons to use Rodeo
I’m in my final year doing Economics and I don’t know whether to apply for grad schemes now or do a masters first. What do you think?
Honest answer — it depends on where you want to end up. A lot of top grad schemes (Big 4, civil service, banking) don’t need a masters. Let’s look at the ones you’d be competitive for now, and we can decide if a masters actually adds anything.
Also worth knowing: most autumn 2026 applications are open now. Timing matters more than you think.
Start with a chat, not a search bar
Grad scheme, placement, apprenticeship? Not sure what you want yet — that's fine. Your agent talks it through with you and turns "I have no idea" into a shortlist.
Graduate Consultant — 2026 Scheme
Why you're a good match
StrongYour economics background and your summer at a regional bank line up with what PwC looks for on the consulting scheme. Applications close in four weeks.
See breakdownIt searches the market for you
Every day your agent scans the market matching roles against what actually matters to you, not just keywords on a CV.
Why you're a good match
You’ve got the grades and the economics background, and your bank internship is exactly the experience this scheme looks for. Apply soon — deadlines close within the month.
Experience fit
Your summer at the bank plus your econometrics coursework map directly to the day-one responsibilities on this scheme — client modelling, market briefings, and deal support.
Only hits
No noise. No "maybe this fits." Just roles with a clear explanation of why they're right — and where to focus when applying.
To be successful in this role you should meet the following requirements:
- Significant experience in cybersecurity within a regulated organisation, with credibility to advise senior technology and business stakeholders.
- Strong cyber risk, governance and controls capability: risk identification and articulation, issue management, control mapping, remediation planning/tracking, and audit/assurance engagement.
- Solid technical foundation across enterprise security domains, such as identity and access, threat, exposure & vulnerability management, logging/monitoring, data protection, cloud/SaaS risk and third-party risk, application security & AI.
- Ability to translate technical findings into business impact and clear decision options.
- Strong written and spoken communication (fluent English), confident chairing/facilitating governance forums and challenging constructively.
- Collaborative, outcome-driven approach; able to drive delivery through influence in a complex stakeholder environment.


Get help with your application
Your very own career expert that helps elevate your application to the next level.
Desirable
- Certifications such as ISO27001, CISA, CISM, CISSP, CRISC, CEH (or equivalent).
- Experience supporting technology for Finance/Treasury/Risk domains and/or corporate functions, including sensitivity to financial controls and regulatory reporting.
- Experience with third-party assurance and SaaS security risk management.
- Familiarity with operational resilience and technology risk expectations within financial services.
Opening up a world of opportunity. Being open to different points of view is important for our business and the communities we serve. At HSBC, we’re dedicated to creating diverse and inclusive workplaces - no matter their gender, ethnicity, disability, religion, sexual orientation, socio-economic background or age. We are committed to removing barriers and ensuring careers at HSBC are inclusive and accessible for everyone to be at their best. We take pride in being a Disability Confident Leader and will offer an interview to people with disabilities, long term conditions or neurodivergent candidates who meet the minimum criteria for the role.
If you have a need that requires accommodations or changes during the recruitment process, please get in touch with our Recruitment Helpdesk via hsbc.recruitment@hsbc.com.
“It took my CV and asked me questions relevant to understanding what kind of jobs to suggest for me. Suggestions were almost perfect. Jobs were exactly what I’ve been looking for.”
Jessica, London
Skills