Department and Function Background
Operating within the Global Cybersecurity function and under the management of the Global Head of Cybersecurity Operations & Intelligence, the Global Cybersecurity Operations & Intelligence (GCO&I) team provides a coordinated suite of cyber-threat defence services and are responsible for the monitoring, detection and response to cybersecurity threats across the global HSBC technology estate.
The GCO&I team is split into five distinct sub-functions:
- Monitoring & Threat Detection (M&TD) – Monitoring, detection, alerting and triage of initial cyber-threat events.
- Incident Management & Response (IM&R) – Management and deep-dive investigation and response to cyber-incidents.
- Information Protection & Response (IPR) – Management and response to cyber-related data protection incidents.
- Cyber Intelligence & Threat Analysis (CITA) – Collection, curation and production of actionable cyber-threat intelligence.
- Sustainable Cybersecurity Operations (SCO) – Consisting of three sub-function teams focussed on the continuous improvement of the Cybersecurity Operations and Security Operations Centre (SOC), technology integrations and capability enhancements.
Critical to the success of GCO&I are close partnerships with the wider Cybersecurity teams, technical infrastructure support teams and the internal HSBC stakeholders across the global businesses and functions.
Role Description – Lead Cybersecurity Operations Integration Analyst
Reporting directly into the ‘Head of Cybersecurity Operations Integration, the Lead Cybersecurity Operations Integration Analyst is a technical subject matter expert (SME) within a small team tasked with the onboarding of new technologies, business services logging feeds and cybersecurity tooling into the Global Cybersecurity Operations Security Operation Centre (SOC).
The role holder will be a key technical and engagement lead, tasked with achieving the desired outcomes via proactive and collaborative stakeholder engagements across the technology landscape. Working closely with the technology owners and the SOC Monitoring & Threat Detection and Incident Response teams, the role holder will continuously review and manage onboarding requests to ensure a cyber-threat intelligence led approach to the prioritisation of engagements.
This is a key role that underpins the foundational capabilities that support the Global Cybersecurity Operations & Intelligence mission to respond to
cyber-threats against HSBC rapidly, effectively and consistently.
The Lead Cybersecurity Operations Integration Analyst is accountable for:
- Supporting the technical development, implementation and maintenance of a technology and log ingestion framework that aligns to control requirements and supports a cyber-threat intelligence led approach to the detection, response and containment of cyber-threats.
- Supporting and maintaining the technical aspects of a flexible stakeholder engagement model that caters for both proactive and reactive collaboration and can rapidly adjust and reprioritise workloads in response to the changing threat-landscape.
- Contributing to the building and maintaining strong processes and collaborative working practices with supporting teams in Sustainable Cybersecurity Operations and the wider Global Cybersecurity Operations & Intelligence teams.
Building relationships and engagements with the many technology and platform owner stakeholders
- Successfully maintaining these relationships and delivering prioritised outcomes in an environment where relationships can be complex and priorities are often divergent.
- Maintaining governance across all Cyber Ops Integration activities and ensuring the creation, collection and processing of key data points to feed into relevant service reporting e.g. service delivery metrics, KPIs, KCIs, and performance dashboards.
- Supporting the development and maintenance of a functional strategy that supports continuous improvement and is aligned to the wider Sustainable Cybersecurity Operations and Global Cybersecurity Operations & Intelligence strategy and goals.
Impact on the Business/Function
- Supports the development of the GCO&I functions, engaging with colleagues across Cybersecurity and other IT functions to drive and deliver sustainable operational solutions in line with department strategy.
- Drives business performance, clear thinking and utilises experience whilst under pressure.
- Delivers sustainable business outcomes.
- Supports the building of effective technology and process control capabilities that continuously evolve to meet security and compliance needs
- Works closely with peers and business leads to build and implement controls in adlignment with risk-posture, architectural constraints, company strategic direction and industry trends and best practices.
- Drives delivery of the highest standards and outcomes, inspiring others to do the same. Focuses on medium and long-term goals even when under pressure or facing uncertainty. Manages expectations, results and impact of agreed outcomes, thinking ahead to identify and overcome potential issues.
- Strategically drives innovation to gain competitive advantage, taking calculated, entrepreneurial risks to achieve business outcomes. Generates an environment in which innovation is seamlessly embedded into working practices.
Customers / Stakeholders
- Leads a customer-focused and collaborative culture by championing customer and stake-holder engagement throughout the team.
- Demonstrates an understanding of customer and stakeholder requirements by providing specialist input and knowledge and having a detailed understanding of the different short and long term shifts in business/function patterns of activity and demand.
- Understands and interprets developments and changes in future business requirement and ensures the appropriate reaction and response through discourse and the implementation of relevant, security focused, technical and procedural solutions.
Strengthens stakeholder relationships and enhances key relationships using rapport-building expertise and appropriate influencing skills to add and increase stakeholder advocacy. Key relationships to include Functional heads across the other CTO functions and external account managers for third party suppliers and vendors, along with other regional counterparts across the globe, Cultivate strong relationships with organisationally important global and/or high value stakeholders with a tailored approach.
Leadership & Teamwork
- Supports the technical direction of the Cyber Ops Integration team, making sustainable decisions that protects and enhances HSBC’s values, reputation and stakeholder value.
- Actively engages in a learning culture, encouraging collaboration and cross-functional working to develop and nurture teams and identify talent.
- Authentically engages a diverse group of stakeholders internally and externally to influence the achievement of best outcomes for all stakeholders.
- Builds rapport and mutual understanding to communicate and create opportunities for cross-business and/or international working, encouraging debate and open discussion. Encourages people to build sustainable relationships beyond transactional levels and use empathy and insight to build better understanding of mutual benefits.
Supports close team collaboration and mentoring practices.
Operational Effectiveness & Control
- Governs risk responsibly. Promote ethical management of risk across regions and business areas within their teams.
- Communicates changes in policy and governance effectively, reinforcing risk processes within their team.
- Builds and sustains a risk aware culture. Shows integrity whilst promoting and managing relevant monitoring and reporting requirements within their team.
- Embeds efficient risk and compliance processes and procedures into business as usual practices.
- Builds collaborative relationships, defines and articulates to stakeholders the targeted benefits for a change intervention.
- Demonstrates effective financial skills to develop a detailed business case, including investments, detailed benefits (financial, non-financial and strategic) and link to overall finances of the business.
- Supports the management of department finances. Accurately interprets strategic financial information: makes insightful decisions in financial planning and programme performance monitoring.
- Identifies and highlights financial implications of risks/issues, involves stakeholders and supports management of budget variation as appropriate
- The role holder will ensure the fair treatment (service excellence) of our customers is at the heart of everything we do, both personally and as an organisation.
- The role holder will also continually reassess the Cyber Security and operational risks associated with the role and inherent in the business, taking account of changing economic or market conditions, legal and regulatory requirements, operating procedures and practices, management restructurings, and the impact of new technology.
This will be achieved by ensuring all actions take account of the likelihood of operational risk occurring and by addressing any areas of concern in conjunction with entity management and/or the appropriate department.