Upload Button Icon Add office photos

HSBC Group

Compare button icon Compare button icon Compare
4.0

based on 4.5k Reviews

Proud winner of ABECA 2024 - AmbitionBox Employee Choice Awards

zig zag pattern zig zag pattern
filter salaries All Filters

144 HSBC Group Jobs

Head of Web Application and API Protection

7-11 years

Hyderabad / Secunderabad

1 vacancy

Head of Web Application and API Protection

HSBC Group

posted 2d ago

Job Description

Job description

Some careers have more impact than others.

If you re looking for further opportunities to develop your career, take the next step in fulfilling your potential right here at HSBC.

HSBC is one of the largest banking and financial services organisations in the world, with operations in 62 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realise their ambitions.

We are currently seeking an experienced professional to join our team in the role of Head of Web Application Security & Protection.

Location: Pune / Hyderabad

Department Background:

Our Cybersecurity team helps maintain a strong, secure technology and data infrastructure using industry leading techniques, real-time data analytics and controls to enhance protection against cyber-attacks.

The Opportunity:

  • Our Technology teams work closely with HSBC s Global Businesses and Markets to design, build and run digital services that allow millions of our customers around the world to bank quickly, simply and securely. We run and manage Technology infrastructure, data centers and core banking systems that power the world s leading international bank, with one of the largest technology estates in the industry.
  • We are looking for a Cybersecurity leader to join us to shape our long-term strategy, and turbo-charge delivery, as the accountable owner for Web Application Security & Protection (WASP) across the bank. This senior role reports directly to the Global Head of Network Security.

What you ll do:

  • Strategy: Define and maintain our global strategy for WASP, supported by engineers, platform owners, architects and Control Owners, enabling business success, meeting regulatory expectation and best practice, whilst responding to current and likely threat actor evolution.
  • Delivery: Own the investment roadmap for WASP and its successful delivery across multiple partners. Ensure the transparent prioritisation of a common backlog to drive risk reduction, simplification and wider strategic needs. Ensure risk-risk trade-offs are managed, particularly risk mitigation and operational needs.
  • Innovation: Empower HSBC to successfully navigate cyber risk with innovative, responsive and frictionless technologies and services, both those delivered in-house and from external partners. Foster and empower a culture of innovation, experimentation, and continuous improvement.
  • Partnership: Develop with colleagues throughout technology and the business innovative technical solutions that meet both current and future business needs, ensuring the bank s infrastructure remains scalable and resilient. Drive the shift-left of WASP in partnership with DevOps. Partner with external technology providers and security specialists to integrate best practice and leverage or build cutting-edge tooling.
  • Services: define, operate and mature a business service supporting adoption and tuning of protections, as well as being a trusted advisor and point of escalation for technical and business teams managing online services, ensuring security requirements are understood and effectively implemented.
  • Oversight: Ensure WASP is overseen end-to-end, robustly and throughout the organisation: from platform acquisition, service deployment through to federated operation. Drive a data-centric approach to observability and assessment, wherever possible supported by automation, measures and analytics.
  • Accountability: Ensure regulatory and risk management outcomes are being maintained or robustly managed. Ownership of High-Risk Audit, Regulator and self-identified issues. Ownership of the capability budget, balancing run and change investment. As a senior leader, contribute to and champion change across both Cybersecurity and Technology, occasionally outside of your primary remit.
  • Talent: Lead, manage, invest in, recruit and inspire a team of highly skilled and performant SMEs across the globe. A culture driven by empowerment, experimentation, learning, partnership and delivery. A place where colleagues thrive, solving meaningful problems that keep the bank and its customers safe.
Requirements

What you will need to succeed in the role:

  • Hands-on experience in designing and implementing web application protection strategies, leveraging tools and frameworks to secure and optimise resilient network infrastructures.
  • Robust understanding of common industry cyber security frameworks, standards, and methodologies, including PCI DSS, FFIEC guidelines, CIS and NIST standards.
  • Expertise in web application security including implementing application-layer firewalls in a large-scale, complex, and global organisation. Familiarity with leading WAF solutions (e.g. AWS WAF, Akamai Kona, Cloudflare etc).
  • Designing and implementing web application protection strategies, leveraging tools and frameworks to secure and optimise resilient network infrastructures.
  • Expertise in API security including hardening, authentication (OAuth, token-based, etc) and gateway security. Understanding of vulnerability scanning tooling and integration with WAFs for automated protection.
  • Ability to escalate, drive relationships and delivery across multiple regions & teams.
  • Deep understanding of web application vulnerabilities and attack patterns, include OWASP, CRS and their mitigations, and of cloud environments (e.g., AWS) and associated network security challenges and solutions.
  • Awareness of advanced techniques for defending against modern threats, such as bot mitigation, automated attack prevention, and anomaly detection.
  • Strong analytical skills to identify and resolve complex problems, often with risk-risk trade-offs.
  • Proven experience in technology leadership roles, running high performing technology teams ans experience working in a large scale, multi-national and technologically diverse environments.
  • Knowledge and exposure of the application of Risk and Control Management and associated frameworks, preferably from a multi-market institution.
  • Ability to articulate technical threats, scenarios, controls and risks to both technical and business stakeholders.
  • Managing, developing and retaining high-performing individuals in different geographies, often remotely. Proven ability to collaborate across industry, academia and government to solve complex problems.
  • Ability to prepare concise presentations, reports and updates for senior management. Possess strong leadership skills to bring out the best in a team. This includes both direct leadership and cross-functional capabilities.
  • Experience within fast-moving, complex and demanding corporate environments and able to provide appropriate direction to the team whilst dealing with ambiguity and change.
  • Act as a role-model for more junior members of Cybersecurity and Technology. An inquisitive approach, always asking how to achieve goals in a smarter and more effective way.
  • An ability and interest to learn and experiment with new approaches to achieve business and cybersecurity outcomes, in different and often challenge contexts.
  • Influential, credible and persuasive, active listener, embraces HSBC Values, shows good judgement and demonstrates high level of communication skills to achieve effective stakeholder management.

You ll achieve more when you join HSBC.

www.hsbc.com/careers

HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.

Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.

***


Employment Type: Full Time, Permanent

Read full job description

HSBC Group Interview Questions & Tips

Prepare for HSBC Group roles with real interview advice

People are getting interviews at HSBC Group through

(based on 318 HSBC Group interviews)
Job Portal
Referral
Campus Placement
Company Website
Walkin
Recruitment Consultant
28%
19%
15%
8%
4%
4%
22% candidates got the interview through other sources.
High Confidence
?
High Confidence means the data is based on a large number of responses received from the candidates.

What people at HSBC Group are saying

What HSBC Group employees are saying about work life

based on 4.5k employees
65%
84%
74%
83%
Flexible timing
Monday to Friday
No travel
Day Shift
View more insights

HSBC Group Benefits

Free Transport
Health Insurance
Cafeteria
Work From Home
Soft Skill Training
Job Training +6 more
View more benefits

Compare HSBC Group with

Standard Chartered

3.8
Compare

Citibank

3.9
Compare

ICICI Bank

4.0
Compare

Axis Bank

3.8
Compare

HDFC Bank

3.9
Compare

State Bank of India

3.8
Compare

Kotak Mahindra Bank

3.8
Compare

IndusInd Bank

3.6
Compare

Yes Bank

3.8
Compare

RBL Bank

3.7
Compare

JPMorgan Chase & Co.

4.1
Compare

Wells Fargo

3.9
Compare

UBS

4.0
Compare

BNY

4.0
Compare

State Street Corporation

3.8
Compare

American Express

4.2
Compare

Citicorp

3.7
Compare

Morgan Stanley

3.7
Compare

BNP Paribas

3.8
Compare

Cholamandalam Investment & Finance

4.0
Compare

Similar Jobs for you

Protection at sendhelper

Bangalore / Bengaluru

6-9 Yrs

₹ 8-11 LPA

Protection at Egon Zehnder Pvt Ltd

Gurgaon / Gurugram

2-6 Yrs

₹ 6-10 LPA

Protection at Flipkart Internet Private Limited

Kurnool

7-10 Yrs

₹ 10-15 LPA

Protection at Ernst Young

Bangalore / Bengaluru

4-8 Yrs

₹ 6-10 LPA

Service Manager at HSBC electronic data processing india pvt ltd

Bangalore / Bengaluru

6-8 Yrs

₹ 8-10 LPA

Procurement Head at Prakhar Software Solutions

New Delhi

3-8 Yrs

₹ 5-10 LPA

Head at PSS Global.net

Mumbai

12-14 Yrs

₹ 14-16 LPA

Compliance at Link Group

Mumbai

9-15 Yrs

₹ 11-17 LPA

Head Global at Ashirvad Pipes

Bangalore / Bengaluru

11-14 Yrs

₹ 13-16 LPA

Compliance Head at MUFG Pension Market Services

Mumbai

9-15 Yrs

₹ 11-17 LPA

HSBC Group Hyderabad / Secunderabad Office Location

View all
Hyderabad Office
The Hongkong and Shanghai Banking Corporation Limited, Private Banking Department, 1st Floor 6-3-1107 & 1108, Rajbhavan Road, Somajiguda, Hyderabad Hyderabad
500 082

Head of Web Application and API Protection

7-11 Yrs

Hyderabad / Secunderabad

5d ago·via naukri.com

Assistant Vice President, THIRD PARTY RISK MANAGEMENT

3-5 Yrs

Bangalore / Bengaluru

2d ago·via naukri.com

Vice President and Area Head Hyderabad

15-20 Yrs

Hyderabad / Secunderabad

2d ago·via naukri.com

Relationship Manager - BB - Vice President

2-5 Yrs

Mumbai

2d ago·via naukri.com

Associate Vice President/Manager LG Mortgage Asset Specialist, MSF

5-8 Yrs

Hyderabad / Secunderabad

2d ago·via naukri.com

DB2 Systems Programmer

4-8 Yrs

Hyderabad / Secunderabad, Pune, Bangalore / Bengaluru

2d ago·via naukri.com

Assistant Manager

0-5 Yrs

Mumbai

2d ago·via naukri.com

F4 Senior Test Analyst

5-7 Yrs

Chennai

2d ago·via naukri.com

Senior Portfolio Services Manager

6-8 Yrs

Bangalore / Bengaluru

2d ago·via naukri.com

IBM Mainframe, Seeburger/ Manager Business Analyst

1-3 Yrs

Hyderabad / Secunderabad

2d ago·via naukri.com
write
Share an Interview