Cloud Security Controls Lead

2 tygodni temu


Kraków, Lesser Poland HSBC Service Delivery Pełny etat

Technologies-expected : AWS Microsoft Azure GCP about-project : Whilst the job holder will be based in Krakow, Poland, this is a Global role covering Cybersecurity Controls applicable to public Cloud (including Alibaba, AWS, Azure, GCP) across all countries and legal entities.

The 'Cloud Security Control Lead' reports directly to the 'Cloud Security Engineering and Delivery Lead'.

Key to this role are HSBC's Vision '27 goals - Speed, Scale, Resilience and People.

responsibilities :

Collaborate with Control Owners, 2 Lo D, Global Cloud Services (GCS) Platform teams and other key stakeholders, to ensure that Cybersecurity owned controls in the Risk and Controls Library are designed according to the Bank's requirements and industry standards and best practices (e.g., NIST and ensure that, where appropriate, the Controls make specific, explicit provision in their applicability for public Cloud use cases.


Collaborate with Control Owners and other stakeholders to ensure that Cybersecurity control measurements are defined in accordance with HSBC's KCI Design Framework and industry best practices (CIS).


Existing KCIs must be suitably adapted and new KCIs created as required ensuring effective coverage of public Cloud use cases.


Work with CRCS teams to ensure that the defined controls are compliant with Legal/Regulatory Mandatory requirements and that measurements provide sufficient data for stakeholder reports.


With specific reference to public Cloud use-cases, work with 2 Lo D, CCO Technology, Audit (internal and external), GCS platform teams and other key stakeholders to ensure that the Cybersecurity owned controls are monitored, assessed, and tested according to the Bank's requirements, Risk Management Framework (RMF) and other external regulatory bodies.


Review and challenge the existing Risk and Control Library, Policies, Procedures and Standards for Cybersecurity controls with specific reference to applicability for public Cloud use cases.


Proactively identify gaps in the existing frameworks and propose remediation solutions in line with the industry standards and best practices.


Provide regular, timely, suitable data, reporting and content describing the status, coverage and effectiveness of Cybersecurity Controls, with specific reference to public Cloud for delivery to senior management forums (e.g., Risk and Controls Management Meeting).

requirements-expected : Risk and

Controls Background:

Strong understanding of Security Controls in particular, how these are applied in the context of public Cloud; Ability to translate difficult IT concepts into business-friendly language; Experience with Technology risks and controls.


Technical background:
Broad knowledge of Cybersecurity – concepts, requirements, operations; Broad knowledge of Cloud (esp.

public Cloud), principles, operations, concepts; Understanding of metrics and measures in managing risks and controls (KCIs, KRIs, KPIs).


Technical writing skills and highly proficient use of written English is required to ensure quality output to articulate Control, Policies, Procedure and Standards gaps and requirements with particular reference to public Cloud.


Excellent written and verbal communication skills with an ability to: Communicate with impact, ensuring complex information and data is articulated in a meaningful way to wide and varied audiences and stakeholders including senior management; Produce clear and concise reports and control documentation for targeted audiences across internal and external stakeholders; Influence, challenge and manage senior stakeholders.

Flexible approach to shifting or competing priorities.

Strong technical problem-solving and trouble-shooting skills.


Strong technical awareness of Cloud, Cyber Security tools and concepts (ideally with a Cloud certification(s)) and one or more industry-recognised cybersecurity-related certifications including CISSP, CRISC, CISM or Cloud Security Certifications would be nice to have.


offered :
Competitive salary Annual performance-based bonus Additional bonuses for recognition awards Multisport card Private medical care Life insurance One-time reimbursement of home office set-up (up to 800 PLN)

Corporate parties & events CSR initiatives Nursery discounts Financial support with trainings and education Social fund Flexible working hours Free parking (Cracow office) benefits :
sharing the costs of sports activities private medical care sharing the costs of professional training & courses life insurance remote work opportunities flexible working time integration events corporate sports team doctor's duty hours in the office retirement pension plan corporate library no dress code coffee / tea parking space for employees leisure zone extra social benefits employee referral program opportunity to obtain permits and licenses charity initiatives family picnics extra leave In-office gym

  • Kraków, Lesser Poland Hsbc Service Delivery Pełny etat

    About-project : Operating within the Cybersecurity Global Defence function and under the management of the Global Head of Cybersecurity Operations, the Global Cybersecurity Operations (GCO) team provides a coordinated suite of "Network Defence" related services and are responsible for the detection and response to information and cybersecurity threats across...


  • Kraków, Lesser Poland GPC Global Technology Center Pełny etat

    As we continue to scale and evolve, it has become increasingly important for us to protect our applications. That's why we're looking for an experienced Lead Application Security Engineer in the area of application security for AI systems. Join our GenAI team and contribute to developing our latest products and services.ResponsibilitiesUse technical skills...


  • Kraków, Lesser Poland Motorola Solutions Pełny etat

    At Motorola Solutions, we're guided by a shared purpose - helping people be their best in the moments that matter - and we live up to our purpose every day by solving for safer. Because people can only be their best when they not only feel safe, but are safe. We're solving for safer by building the best possible technologies across every part of our safety...

  • Cloud DevSecOps Engineer

    2 tygodni temu


    Kraków, Lesser Poland Motorola Solutions Pełny etat

    Job Description We are seeking a strong Cloud Engineering Team Lead to help the development, deployment, and management of cybersecurity components safeguarding our SaaS Infrastructure running in AWS, Azure, and GCP. Responsibilities: Lead the team responsible for the security posture and monitoring of our deployments primarily in our cloud...

  • Cloud Security Engineer

    2 tygodni temu


    Kraków, Lesser Poland Euroclear Pełny etat

    Expected, Cloudflare, HTTP, HTTPS, SSL, TLS/mTLS, PythonOptional, Agile, Scrum, DevOpsOperating system, Windows, LinuxAbout the project, As a global critical financial infrastructure, the protection of Euroclear information and assets is fundamental to the companys' business. Security is at the core of our services, firmly embedded in the management systems...


  • Kraków, Lesser Poland Zendesk Pełny etat

    By clicking "Apply Now," I understand and agree that Zendesk and its affiliates will collect and process my information in accordance with Zendesk's Candidate Privacy Notice.Job Description The Security Compliance Team at Zendesk supports the business by maturing, growing, and maintaining its compliance with security and privacy certifications for its...


  • Kraków, Lesser Poland Zendesk Pełny etat

    By clicking "Apply Now," I understand and agree that Zendesk and its affiliates will collect and process my information in accordance with Zendesk's Candidate Privacy Notice.Job Description The Security Compliance Team at Zendesk supports the business by maturing, growing, and maintaining its compliance with security and privacy certifications for its...


  • Kraków, Lesser Poland Zendesk Pełny etat

    By clicking "Apply Now," I understand and agree that Zendesk and its affiliates will collect and process my information in accordance with Zendesk's Candidate Privacy Notice.Job Description The Security Compliance Team at Zendesk supports the business by maturing, growing, and maintaining its compliance with security and privacy certifications for its...

  • Cloud DevSecOps Engineer

    2 tygodni temu


    Kraków, Lesser Poland Motorola Solutions Pełny etat

    At Motorola Solutions, we're guided by a shared purpose - helping people be their best in the moments that matter - and we live up to our purpose every day by solving for safer. Because people can only be their best when they not only feel safe, but are safe. We're solving for safer by building the best possible technologies across every part of our safety...


  • Kraków, Lesser Poland ITDS Business Consultants Pełny etat

    Security Engineer – Antimalware Endpoint SecurityJoin us, and enhance security across global infrastructuresKrakow-based opportunity with the possibility to work 100% remotelyAs a Security Engineer – Antimalware Endpoint Security, you will be working for our client, a global financial services organization focused on safeguarding its vast network and...


  • Kraków, Lesser Poland NTIATIVE sp. z o.o. Pełny etat

    Senior Security Specialist Kraków, Lesser Poland Voivodeship technologies-expected :about-project :We are looking for a Senior Security Specialist who would be responsible for overseeing security for digital infrastructure and support services at Metso. Responsibilities include ensuring compliance with security directives, providing technical expertise,...


  • Kraków, Lesser Poland Ntiative Sp. Z O.o. Pełny etat

    Technologies-expected : Microsoft Azure Defender about-project : We are looking for a Senior Security Specialist who would be responsible for overseeing security for digital infrastructure and support services at Metso.Responsibilities include ensuring compliance with security directives, providing technical expertise, leading vulnerability management, and...

  • Cloud Security Architect

    2 tygodni temu


    Kraków, Lesser Poland Pertemps ERP Pełny etat

    TasksCloud Security Architect Opportunity - B2B or UoPLocation: RemoteExperience Required: Minimum 5 years in Cloud AWS implementations, AWS Cloud certifications, CCSP or CISSP, solid skills in cloud security concepts, access management, firewalls, monitoring, scripting languages, and DevOps toolsEmployment Type: B2B or UoPStart Date:...

  • Cloud Security Architect

    2 tygodni temu


    Kraków, Lesser Poland Pertemps ERP Pełny etat

    TasksCloud Security Architect - B2B or UoPlocation: remoteexperience needed: 5 years in Cloud AWS implementations, AWS Cloud certifications, CCSP or CISSP, strong skills in cloud security concepts, access management, firewalls, monitoring etc., scripting languages, DevOps toolsemployment: B2B or UoPstart: asapRequirementsPlease, apply today and I will share...


  • Kraków, Lesser Poland Metso Pełny etat

    Join an industry leader and contribute to the sustainable use of the world's natural resources. Together, we aim to revolutionize the business and propel the industry towards a greener future.At Metso, you will thrive in our inclusive culture and connect with colleagues worldwide. Join us on a journey of personal growth where you can unlock your full...


  • Kraków, Lesser Poland NTIATIVE Finance Recruitment Pełny etat

    Join an industry leader and make a positive change in the sustainable use of the world's natural resources. Together, we will transform the business and drive the industry toward a greener future.At Metso, you will be supported by our inclusive culture and a network of colleagues from around the world. With us, you will embark on a personal growth journey...


  • Kraków, Lesser Poland GFT Technologies Pełny etat

    You will work with and learn from top IT experts. You will join a crew of experienced engineers: 70% of our employees are senior level. You will be part of QA community composed of over 100 engineers.Interested in the cloud ? You will enjoy our full support in developing your skills: training programs, certifications and our internal community of experts. We...

  • Security Analyst

    2 tygodni temu


    Kraków, Lesser Poland Software Mind Pełny etat

    Software Mind A software house that provides software development services to boost product engineering and digital transformation capabilities. View company page We are Software Mind, an awesome team of engineers who are ready to ramp up any top-notch company's projects Our aim? To always be one step ahead. Become part of a multicultural company in...

  • Security Risk Analyst

    2 tygodni temu


    Kraków, Lesser Poland Experis ManpowerGroup Sp. z o.o. Pełny etat

    Conducting risk assessments (ideally of third-party vendors) against security standards, such as ISO 27001 and NIST Understanding of concepts of cyber security controls in IT areas (e.g. Access management, Application security) Knowledge of security assessments methodology Analyzing and evaluating security controls and documentation policies (evidence) ...

  • Cloud Architect

    2 tygodni temu


    Kraków, Lesser Poland SoftwareONE Deutschland GmbH Pełny etat

    Why SoftwareOne?SoftwareOne is powered by SwomiesEvery day, over SoftwareOne colleagues – we call ourselves "Swomies" – solve demanding business challenges with intelligence and grit. And every day, 400+ Tech Experts in 20+ countries build and operate the systems that run SoftwareOne. They deliver 24/7 support through different time zones and work in a...