HSBC Service Delivery (Polska) Sp. z o.o. is a part of HSBC Holdings plc, the parent company of the HSBC Group, headquartered in London. The Group serves customers worldwide from over 6,300 offices in over 75 countries and territories in Europe, Asia, North and Latin America, and the Middle East and North Africa. HSBC is one of the world’s largest banking and financial services organisations. Currently, we are looking for a candidate for the position of:
Cybersecurity Operations Crew Lead
Ref No: HTK/Cybersecurity/COCL/06/2018
Global Cybersecurity Operations (GCO) provides a coordinated suite of “Network Defence” services responsible for detecting and responding to information and cybersecurity threats to HSBC assets across the globe and is under the management of the Head of Global Cybersecurity Operations. This includes dedicated functions for the monitoring and detection of threats within the global estate as well as Cybersecurity Incident Management and Response activities. These two principal functions are supported by additional internal GCO capabilities in; Cyber Intelligence and Threat Analysis, Security Sciences and Client Engagement and Support Services. Critical to the success of GCO is it close partnership with sister Cybersecurity teams, IT Infrastructure Delivery and Global Business and Function clients. The overall GCO mission is placed under the purview of the Group Chief Information Security Officer (CISO).
The Cybersecurity Monitoring and Threat Detection Team are charged with efficiently and effectively monitoring the HSBC global technology and information estate 24x7. The team’s mission is to detect the presence of any adversary within the estate, quickly analyze the severity and scope of the issue and work with the Cybersecurity Incident Management and Response Team to contain, mitigate and remediate the incursion. In addition, the team is responsible for constantly improving its detection capability through attack analysis and ensuring that the appropriate security event information is being fed into the team and that the alerting rules are tuned for maximum effectiveness. This mission is critical to the protection of HSBC customers, the HSBC brand, shareholder value, as well as HSBC information and financial assets.
- Managing and maintaining a highly skilled, efficient and effective local team of Cybersecurity Analysts in achievement of their responsibilities, which include:
- Monitoring the entire global HSBC technology and information estate for new attacks and log them to appropriate systems.
- Triaging potentially malicious events to determine severity and criticality of the event.
- Responding to alerts from the various monitoring/detection systems and platforms within defined SLAs.
- Following detailed processes and procedures to analyze, respond to and/or escalate cyber security incidents.
- Supporting cyber security incidents through to eradication and feedback lessons learned, in to improved cyber resilience.
- Analyzing network traffic using a variety of analysis tools.
- Monitoring security appliance health and perform basic troubleshooting of security devices; notify security engineering as necessary for malfunctioning equipment.
- Analyzing malicious artefacts obtained from network monitoring with a focus on generation of threat intelligence and service improvement.
- Identifying and developing new ideas to enhance our detection capability (Use cases) and mitigations (Playbooks) across the security platforms.
- Supporting handovers to other teams and countries at the start and end of the working shift.
- Performance management and development of the Cybersecurity Analysts.
- Collaboration with other local and global Crew Leads and Watch Commanders to ensure co-ordination of workload and continuous 24x7 cybersecurity operations service provision.
- Reviewing and validating new Use Cases and Playbooks created by Cybersecurity Analysts.
- Ensuring a comprehensive and smooth hand-over between the global teams as shifts end and begin.
- Identification of processes that can be automated and orchestrated to ensure maximum efficiency of GCO resources.
- Promoting a “self-critical” and continuous assessment and improvement culture whereby identification of weaknesses in the bank’s control plane (people, process and technology) are brought to light and addressed in an effective and timely manner.
- Embedding a culture of individual self-improvement, development and self-directed learning whereby staff are expected to maintain subject matter expertise within their area of focus and within the realm of cyber security more broadly.
- Production of Management Information related to the Monitoring and Threat Detection mission that is appropriate to the target audience, supported by data and experienced analysis enabling informed decisions.
Engagement within the Lines of Defense Risk Management framework adopted by HSBC to ensure complete transparency and effective working relationship across all lines of defense.
- 5+ years of experience in Cyber-security leadership position.
- Solid experience in a technical leadership position within an enterprise scale organization; including hands-on experience of complex data center environments, preferably in the finance or similarly regulated sector
- Industry recognized cyber security related certifications including; CEH, EnCE, SANS GSEC, GCIH, GCIA and/or CISSP
- Formal education and advanced degree in Information Security, Cyber-security, Computer Science or similar and/or commensurate demonstrated work experience in the same.
- Excellent knowledge and demonstrated experience of common cybersecurity technologies such as; IDS / IPS / HIPS, Advanced Anti-malware prevention and analysis, Firewalls, Proxies, MSS, etc.
- Excellent knowledge of common network protocols such as TCP, UDP, DNS, DHCP, IPSEC, HTTP, etc. and network protocol analysis suits.
- Excellent knowledge of common enterprise technology infrastructure, platforms and tooling, including; Windows, Linux, infrastructure management and networking hardware.
- Good knowledge and technical experience of 3rd party cloud computing platforms such as AWS, Azure and Google.
- Good knowledge and demonstrated experience in incident response tools, techniques and process for effective threat containment, mitigation and remediation.
- Excellent knowledge and demonstrated experience of common log management suites, Security Information and Event Management (SIEM) tools, use of “Big Data” and Cloud-based solution for the collection and real-time analysis of security information.
- Ability to identify, develop and track key performance indicator (KPI) metrics for accurate and contextual evaluation of operational effectiveness as well as providing recommendations for control improvement and mitigating control adjustments.
- Good knowledge of intelligence analysis principles either though formal education / training or equivalent professional experience.
- Sound knowledge and demonstrated experience of common intelligence sharing platforms / protocols and experience operating within a collective defense environment with internal stakeholders and external partners.
- An understanding of business needs and commitment to delivering high-quality, prompt and efficient service to the business.
- An understanding of organizational mission, values and goals and consistent application of this knowledge.
- Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one.
- An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily-understood, authoritative and actionable manner.
- A team-focused mentality with the proven ability to work effectively with diverse stakeholders.
- Self-motivated and possessing of a high sense of urgency and personal integrity.
- Highest ethical standards and values.
- Good understanding of HSBC cyber security principles, global financial services business models, regional compliance regulations and applicable laws.
- Good understanding and knowledge of common industry cyber security frameworks, standards and methodologies, including; OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines, CIS and NIST standards.
- Excellent communication and interpersonal skills with the ability to produce clear and concise reports for targeted audiences across internal and external stakeholders.
- Solid understanding of business finance as well as effective management of budgets and expenditures.
- Experience in a leadership position within a cyber-security operations team to include team and capability development, staff development, career management, and recruitment.
- Ability to orchestrate, manage and successfully implement major procedural and technological change within a complex, global organization.
- Ability to speak, read and write in English, in addition to your local language.
- Stable job in professional team,
- Interesting path of career in an international organization,
- Consistent scope of responsibilities,
- Private health care, employees’ benefits.