Cloud Security Controls Lead

5 dni temu


Krakow, Polska HSBC Service Delivery (Polska) Sp. z o.o. Pełny etat

technologies-expected :
AWS
Microsoft Azure
GCP

about-project :
Whilst the job holder will be based in Krakow, Poland, this is a Global role covering Cybersecurity Controls applicable to public Cloud (including Alibaba, AWS, Azure, GCP) across all countries and legal entities.
The ‘Cloud Security Control Lead’ reports directly to the ‘Cloud Security Engineering and Delivery Lead’. Key to this role are HSBC’s Vision ’27 goals - Speed, Scale, Resilience and People.

responsibilities :
Collaborate with Control Owners, 2LoD, Global Cloud Services (GCS) Platform teams and other key stakeholders, to ensure that Cybersecurity owned controls in the Risk and Controls Library are designed according to the Bank’s requirements and industry standards and best practices (e.g., NIST 800-53) and ensure that, where appropriate, the Controls make specific, explicit provision in their applicability for public Cloud use cases.
Collaborate with Control Owners and other stakeholders to ensure that Cybersecurity control measurements are defined in accordance with HSBC’s KCI Design Framework and industry best practices (CIS). Existing KCIs must be suitably adapted and new KCIs created as required ensuring effective coverage of public Cloud use cases.
Work with CRCS teams to ensure that the defined controls are compliant with Legal/Regulatory Mandatory requirements and that measurements provide sufficient data for stakeholder reports.
With specific reference to public Cloud use-cases, work with 2LoD, CCO Technology, Audit (internal and external), GCS platform teams and other key stakeholders to ensure that the Cybersecurity owned controls are monitored, assessed, and tested according to the Bank’s requirements, Risk Management Framework (RMF) and other external regulatory bodies.
Review and challenge the existing Risk and Control Library, Policies, Procedures and Standards for Cybersecurity controls with specific reference to applicability for public Cloud use cases.
Proactively identify gaps in the existing frameworks and propose remediation solutions in line with the industry standards and best practices.
Provide regular, timely, suitable data, reporting and content describing the status, coverage and effectiveness of Cybersecurity Controls, with specific reference to public Cloud for delivery to senior management forums (e.g., Risk and Controls Management Meeting).

requirements-expected :
Risk and Controls Background: Strong understanding of Security Controls in particular, how these are applied in the context of public Cloud; Ability to translate difficult IT concepts into business-friendly language; Experience with Technology risks and controls.
Technical background: Broad knowledge of Cybersecurity – concepts, requirements, operations; Broad knowledge of Cloud (esp. public Cloud), principles, operations, concepts; Understanding of metrics and measures in managing risks and controls (KCIs, KRIs, KPIs).
Technical writing skills and highly proficient use of written English is required to ensure quality output to articulate Control, Policies, Procedure and Standards gaps and requirements with particular reference to public Cloud.
Excellent written and verbal communication skills with an ability to: Communicate with impact, ensuring complex information and data is articulated in a meaningful way to wide and varied audiences and stakeholders including senior management; Produce clear and concise reports and control documentation for targeted audiences across internal and external stakeholders; Influence, challenge and manage senior stakeholders.
Flexible approach to shifting or competing priorities.
Strong technical problem-solving and trouble-shooting skills.
Strong technical awareness of Cloud, Cyber Security tools and concepts (ideally with a Cloud certification(s)) and one or more industry-recognised cybersecurity-related certifications including CISSP, CRISC, CISM or Cloud Security Certifications would be nice to have.

offered :
Competitive salary
Annual performance-based bonus
Additional bonuses for recognition awards
Multisport card
Private medical care
Life insurance
One-time reimbursement of home office set-up (up to 800 PLN)
Corporate parties & events
CSR initiatives
Nursery discounts
Financial support with trainings and education
Social fund
Flexible working hours
Free parking (Cracow office)

benefits :
sharing the costs of sports activities
private medical care
sharing the costs of professional training & courses
life insurance
remote work opportunities
flexible working time
integration events
corporate sports team
doctor’s duty hours in the office
retirement pension plan
corporate library
no dress code
coffee / tea
parking space for employees
leisure zone
extra social benefits
employee referral program
opportunity to obtain permits and licenses
charity initiatives
family picnics
extra leave
In-office gym



  • Krakow, Polska HSBC Service Delivery Pełny etat

    Some careers shine brighter than others. If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further. Your career opportunity Whilst the...

  • Lead Cloud Security Analyst

    1 tydzień temu


    Krakow, Polska HSBC Service Delivery Pełny etat

    Some careers shine brighter than others. If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further. Your career opportunity Operating...


  • Krakow, Polska HSBC Service Delivery (Polska) Sp. z o.o. Pełny etat

    about-project :Operating within the Cybersecurity Global Defence function and under the management of the Global Head of Cybersecurity Operations, the Global Cybersecurity Operations (GCO) team provides a coordinated suite of "Network Defence" related services and are responsible for the detection and response to information and cybersecurity threats across...


  • Krakow, Polska HSBC Service Delivery (Polska) Sp. z o.o. Pełny etat

    Operating system, WindowsAbout the project, Operating within the Cybersecurity Global Defence function and under the management of the Global Head of Cybersecurity Operations, the Global Cybersecurity Operations (GCO) team provides a coordinated suite of "Network Defence" related services and are responsible for the detection and response to information and...


  • Krakow, Polska HSBC Service Delivery (Polska) Sp. z o.o. Pełny etat

    about-project : Operating within the Cybersecurity Global Defence function and under the management of the Global Head of Cybersecurity Operations, the Global Cybersecurity Operations (GCO) team provides a coordinated suite of “Network Defence” related services and are responsible for the detection and response to information and cybersecurity threats...

  • Cloud DevSecOps Engineer

    2 tygodni temu


    Krakow, Polska Motorola Solutions Systems Polska Pełny etat

    The position is part of our Cloud Platform Engineering (CPE) organization which operates and manages MSI’s Public Safety Application SaaS platform. As a Team Lead, you will be responsible for the security of these mission-critical systems that are used every day by public safety and government agencies across multiple countries. You will be working in a...

  • Cloud DevSecOps Engineer

    3 tygodni temu


    Krakow, Polska Motorola Solutions Systems Polska Pełny etat

    The position is part of our Cloud Platform Engineering (CPE) organization which operates and manages MSI's Public Safety Application SaaS platform. As a Team Lead, you will be responsible for the security of these mission-critical systems that are used every day by public safety and government agencies across multiple countries. You will be working in a...


  • Krakow, Polska HSBC Service Delivery (Polska) Sp. z o.o. Pełny etat

    technologies-expected : Python Bash PowerShell SQL about-project : The role of Cloud Security Senior Consultant reports into the Global Head of Cloud Security, supporting the execution of capabilities aligned to their cloud security vision to support strategic business objectives at an enterprise level, enabling HSBC to make robust strategic and operational...


  • Krakow, Polska HSBC Service Delivery Pełny etat

    Some careers shine brighter than others. If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further. Your career opportunity The role...

  • Cloud Security Engineer

    3 tygodni temu


    Krakow, Polska Euroclear Pełny etat

    Expected, Cloudflare, SSL, TLS/mTLS, PythonOptional, Agile, Scrum, DevOpsOperating system, Windows, LinuxAbout the project, As a global critical financial infrastructure, the protection of Euroclear information and assets is fundamental to the companys' business. Security is at the core of our services, firmly embedded in the management systems and processes...

  • Senior Security Specialist

    1 tydzień temu


    Krakow, Polska NTIATIVE sp. z o.o. Pełny etat

    Senior Security Specialist Miejsce pracy: Kraków Technologies we use Expected Microsoft Azure Defender Operating system Windows About the project We are looking for a Senior Security Specialist who would be responsible for overseeing security for digital infrastructure and support services at Metso. Responsibilities include ensuring compliance with...


  • Krakow, Polska NTIATIVE sp. z o.o. Pełny etat

    Expected, Microsoft Azure, DefenderOperating system, WindowsAbout the project, We are looking for a Senior Security Specialist who would be responsible for overseeing security for digital infrastructure and support services at Metso. Responsibilities include ensuring compliance with security directives, providing technical expertise, leading vulnerability...


  • Krakow, Polska GFT Poland Pełny etat

    technologies-expected :AzureCryptographyCloud SecurityCNAPPGCPEnglishabout-project :As a Cloud Security Delivery Specialist, you will be the face of GFT for our prospects and customers. You will be a part of Global Security Practice, which shapes and delivers cybersecurity solutions for GFTs' customers.As a specialist, you will be focused on both: building...


  • Krakow, Polska HSBC Service Delivery Pełny etat

    Some careers shine brighter than others. If you’re looking for a career that will help you stand out, join HSBC, and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further. Your career opportunity The most...


  • Krakow, Polska HSBC Service Delivery (Polska) Sp. z o.o. Pełny etat

    technologies-expected : AWS Jira Confluence about-project : The most exciting digital revolution in HSBC’s history is happening right now. The global digital solutions we are creating will influence the banking behaviour of over 37 million customers worldwide. Such an exciting journey comes with a truly unique career opportunity: working alongside a...

  • Cloud Security Engineer

    1 tydzień temu


    Krakow, Polska Euroclear Pełny etat

    technologies-expected : Cloudflare HTTP HTTPS SSL TLS/mTLS Python technologies-optional : Agile Scrum DevOps about-project : As a global critical financial infrastructure, the protection of Euroclear information and assets is fundamental to the company’s business. Security is at the core of our services, firmly embedded in the management systems and...

  • Lead DevOps Engineer

    1 miesiąc temu


    Krakow, Polska Syberry Pełny etat

    Take the next step in your career  from Senior Engineer to Technical Lead! If you have no leading experience, but aspire to grow professionally, we give the opportunity to grow into the technical lead. ‍ Collaborate with a DevSecOps Engineer on cloud security best practices, ‍ Champion high-velocity engineering, ‍ Learn directly from our clients...


  • Krakow, Polska Michael Page Pełny etat

    Cybersecurity Controls Design Manager Miejsce pracy: Kraków Recruitment for Our client is an international company based in the UK, which provides consulting, advisory and technology enablement services for external clients. This role is related to one of their clients from the banking industry.Technologies we use Operating system WindowsYour...


  • Krakow, Polska Michael Page Pełny etat

    Recruitment for, Our client is an international company based in the UK, which provides consulting, advisory and technology enablement services for external clients. This role is related to one of their clients from the banking industry.Operating system, WindowsYour responsibilities, The Controls Design Manager will be deployed onsite to one of our...


  • Krakow, Polska Mindbox S.A. Pełny etat

    about-project :Cybersecurity Control Design Analyst will support continuous maintenance and development of the Cybersecurity control environment. The role holder will be tasked with support of defining and maintaining operational controls instances and their attributes, control measurements as well as control requirements for Group...