Logo Pracuj.pl

(Cybersecurity) Lead DevSecOps Analyst

HSBC Service Delivery (Polska) Sp. z o.o.

  • Kraków, Lesser Poland
  • offer expired 2 months ago
  • contract of employment
  • full-time
  • specialist (Mid / Regular)
  • hybrid work
  • remote recruitment
  • запрошуємо працівників з України
Запрошуємо працівників з України
Роботодавець відкритий для працевлаштування громадян України
  • Specializations:DevOps

HSBC Service Delivery (Polska) Sp. z o.o.

Kapelanka 42a



Technologies we use


  • DevOps

About the project

Global Cybersecurity Operations (GCO) provides a coordinated suite of “Network Defense” services responsible for detecting and responding to information and cybersecurity threats to HSBC assets across the globe and is under the management of the Head of Global Cybersecurity Operations. This includes dedicated functions for the Monitoring and Detection of threats within the global estate as well as Cybersecurity Incident Management and Response activities. These two principal functions are supported by additional internal GCO capabilities in; Cyber Intelligence and Threat Analysis and Strategic Innovation and Operations. Critical to the success of GCO is its close partnership with Cybersecurity Engineering, IT Infrastructure Delivery, and Global Business and Function clients. The overall GCO mission is placed under the purview of the Group Chief Information Security Officer (CISO).

Cybersecurity Strategic Innovation and Operations (SI&O) are charged with managing change and innovation for the Cybersecurity Operations teams. The SI&O mission is to champion change and innovation, whilst ensuring a smooth operational transition. This involves working hand-in-hand with the operational teams and Cybersecurity Engineering, to understand the challenges and requirements, and engaging with internal HSBC functions, or external Vendors to address and resolve these. In addition, the team is responsible for the innovation process, including Proof-of-Concepts, Pilots and Vendor engagement, to gain a viability and impact assessment for GCO prior to deploying any technological change. Once the impact is understood, the SI&O team will be responsible for automation, content, technology, and process integration into GCO and support projects on their route-to-live, ensuring that the GCO teams are prepared. The SI&O team will continue to support all content and automation delivered into production GCO environments under the BAU support process. This mission is critical to ensure minimal operational impact for the Operational Teams.

Your responsibilities

  • Lead the design and development of automation workflows, integration of new technology and new features into the operational teams.

  • Design and develop innovative automated solutions to complex problems, primarily using Splunk SIEM Solution and Phantom SOAR Solution.

  • Provide input into new technology deployments and new features.

  • Liaise between the operational teams and its partners to drive change and improvement initiatives that benefit all parties and align to the CISO vision.

  • Support Operational Impact Assessments and deployment planning.

  • Identify conflicts between changes and ensuring these are appropriately managed.

  • Implement changes, providing post go-live support, and ensuring that DevSecOps have the appropriate documentation and training needed to ensure a successful, uneventful go-live.

  • Review and quality assuring new automation pipelines, processes and procedures created by Cybersecurity colleagues.

  • Prioritise improvement initiatives and projects, following agile methodology.

  • Support the SI&O Team and DevSecOps Analysts.

  • Work with third parties and Cybersecurity Engineering to identify and productionise new features.

  • Research emerging threats and vulnerabilities to aid in the identification and automated response of cyber incidents.

  • Contribute to the continued evolution of hunting, monitoring, detection, analysis and response capabilities and processes.

  • Train, develop and mentor colleagues in area(s) of specialism.

  • Collaborate with the wider Cybersecurity (and IT) teams to ensure that the core, underlying technological capabilities that underpin an effective and efficient operational response to current and anticipated threats and trends remain fit for purpose.

  • Promote a “self-critical” and continuous assessment and improvement culture whereby identification of weaknesses in the bank’s control plane (people, process, and technology) are brought to light and addressed in an effective and timely manner.

  • Support engagement in support of HSBC Global Businesses and Functions to drive a global up-lift in cyber-security awareness and help to evangelise HSBC Cybersecurity efforts and success.

Our requirements

  • Excellent level knowledge and demonstrated experience of building complex dashboards, content and automation pipelines within Splunk and / or Phantom.

  • Excellent knowledge and demonstrated experience working with complex cross domain or cross product designs.

  • Excellent knowledge of agile project methodology.

  • Excellent knowledge and demonstrated experience in Python Programming or similar.

  • Excellent knowledge and demonstrated experience in SQL Query Language or similar.

  • Excellent knowledge and demonstrated experience in managing change and deployments that impact a global team in an enterprise scale organisation.

  • Expert level knowledge and demonstrated experience of Splunk and Phantom, use of “Big Data” and Cloud-based solution for the collection and real-time analysis of security information.

  • Good knowledge of common cybersecurity technologies such as IDS / IPS / HIPS, Advanced Anti-malware prevention and analysis, Firewalls, Proxies, MSS, etc.

  • Good knowledge of incident response tools, techniques and process for effective threat containment, mitigation, and remediation.

  • Good knowledge of key information risk management and security related standards including OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines and NIST standards

  • Good knowledge and technical experience of 3rd party cloud computing platforms such as AWS, Azure and Google.

  • A good understanding of business and operational needs and commitment to delivering high-quality, prompt and to the business.

  • An ability to accurately scope technical work, time to deliver and to apply the 80/20 rule.

  • A team-focused mentality with the proven ability to work effectively with diverse stakeholders.

  • 3+ years of experience in similar cyber security principal analyst or senior software development role

  • Experience within an enterprise scale organisation; including hands-on experience of complex data centre environments, preferably in the finance or similarly regulated sector.

  • Formal education and advanced degree in Information Security, Cyber-security, Computer Science or similar and/or commensurate demonstrated work experience in the same.

  • Splunk and Phantom Course Completion Certificates are preferable.

What we offer

  • Contact with top IT technologies available in the market

  • Employees’ benefits: Multisport Card, private medical and dental health care, life insurance

  • Free parking space for our employees - few minutes from the office

  • Internal training events and workshops

  • Realistic career progression opportunities in an international organization


  • sharing the costs of sports activities

  • private medical care

  • sharing the costs of foreign language classes

  • sharing the costs of professional training & courses

  • life insurance

  • remote work opportunities

  • flexible working time

  • integration events

  • corporate sports team

  • doctor’s duty hours in the office

  • retirement pension plan

  • corporate library

  • no dress code

  • video games at work

  • coffee / tea

  • parking space for employees

  • leisure zone

  • extra social benefits

  • employee referral program

  • opportunity to obtain permits and licenses

  • charity initiatives

  • family picnics

  • extra leave

Recruitment stages

Online assessment


Phone interview


Zoom interview


Welcome to HSBC!

HSBC Service Delivery (Polska) Sp. z o.o.

HSBC is one of the world’s largest banking and financial services organisations. Our global businesses serve more than 40 million customers worldwide through a network that covers 63 countries and territories.

HSBC Service Delivery (Polska) Sp. z o.o. is HSBC's global finance, operations, risk and technology centre. We use our unique expertise and capabilities to provide specialised services – our people range from technologists transforming the banking experience to operations professionals managing 1.7 trillion payments a year.

Our Purpose – Opening up a world of opportunity – explains why we exist. We are bringing together the people, ideas and capital that nurture progress and growth, helping to create a better world – for our customers, our people, our investors, our communities and the planet we all share.

Scroll to the company’s profile