Head of Security, Financial Intelligence Unit (FIU)
Graduate job London (Greater London)
Job description
Role Title: Head of Security, Financial Intelligence Unit (FIU)
Business: Group Management Office
New or Existing Role? Existing
Role Purpose
The role holder will be responsible for the delivery of a multi-faceted security project, primarily focussed on information security risk, which forms part of the programme to deliver the Financial Intelligence Platform (FIPL). FIPL is a ‘big data’ project that seeks to aggregate (physically and virtually) all profile and transaction data (approximately 65 million clients and 7bn transactions per annum). The data will be stored and processed on Hadoop clusters, structured using Ab Initio and ingested into a range of analytical tools from SAS and BAES Applied Intelligence. The security of the platform and the controls associated with the user base are absolutely paramount in ensuring that FIPL is successfully delivered and managed.
Key Accountabilities
Impact on the Business
Identification and implementation of class-leading security controls that go beyond the current offerings within HSBC and the industry. Some controls will be implemented by the role-holder, others will be implemented by parts of the programme with oversight and direction provided by the role-holder.
Ongoing oversight and management of the controls (primarily via monitoring) as the principal individual responsible for securing the platform and the user-base. This includes horizon-scanning for new risks and ensuring the controls remain relevant and effective
Customers / Stakeholders
Engage with a diverse set of senior stakeholders in order to achieve the overarching objectives, including:
The SWD team (including third party consultants and contractors)
Information Security Risk (ISR) subject matter experts
The Financial Intelligence Unit (FIU) management team
Financial Crime Compliance and Security and Fraud Risk (SFR)
Leadership & Teamwork
Strong teamwork with the FIU, SWD and ITO teams to establish and maintain productive personal relationships
Outstanding leadership skills that include setting the right tone to ensure people are aware of the security risks and are correctly prioritising and managing them
Due to the nature of the role there is limited direct financial responsibility, although management of budgets for security controls and the identification of opportunities to reduce associated costs are components of the role. However, the effective management of financial crime is a key strategic priority for HSBC and the subject of considerable expenditure and oversight of which this is a key component.
Operational Effectiveness & Control
Adherence to operational controls, as outlined in procedures and policies to ensure risks are identified and managed
Ensuring that the FIU team and others accessing the system adhere to security controls
Establishment of all necessary security controls
Major Challenges
Identifying the specific risks and vulnerabilities associated with new to bank technologies interacting as part of a broader platform and with aggressive delivery targets.
Establishing security processes and protocols that go beyond, and may conflict with, current HSBC standards in order to provide the requisite level of security assurance to senior stakeholders including Line of Business and Global Function COOs.
Developing and maintaining strong and productive relationships with a diverse set of senior stakeholders from SWD, ITO, ISR and the lines of business, in order to align agendas and priorities
Using technical and business knowledge to formulate actionable security solutions and identify new opportunities to enhance the overall security of the platform and the user base
Working in a new and developing department (the FIU) and securing technology without precedence in HSBC
Rapidly developing an accurate understanding of the FIPL programme and the FIU
Accurately prioritising between the competing demands of a security project and live security processes
Role Context
This is a new role in a recently established and rapidly growing function that is jointly owned by Group Security & Fraud Risk and Financial Crime Compliance. The role holder must therefore be able to work comfortably within a fluid and developing framework and be able to autonomously and independently pre-empt risks and issues that may arise from maturing processes and aggressive growth.
Given the nature of cross-border financial crime, the FIU has been designed to operate as a single global department and the role holder will need to be able to navigate through cultural and regional complexity and show flexibility in engaging with people in different jurisdictions and time zones.
The role holder will need to demonstrate strong organisational, interpersonal, and analytical skills in order to be successful, given that the establishment and ongoing management of security controls will require coordination across a wide range of stakeholders.
The role holder will report jointly to the Global Head of Technology (FIU) and the Global Head of Governance (FIU) and will need to be comfortable operating within a matrix management environment.
Finally, the role holder will need to demonstrate the highest levels of professionalism and integrity given their criticality in establishing and maintaining the security of a valuable asset.
Management of Risk
The role itself involves risk management and the role holder must show strong leadership in this area by continually reassessing the operational risks associated with the role, taking account of changing economic, legal, technological and regulatory environments and adhering to all procedures and practices.
Observation of Internal Controls
The jobholder must adhere to all relevant internal controls and should be able to demonstrate a flawless track record in this area.
Desired profile
Knowledge & Experience / Qualifications
Qualifications
Education to degree level or above (desirable)
Relevant security qualifications (desirable)
Experience / Skills
Subject matter expertise in a range of security areas
The ability and enthusiasm to develop subject matter expertise in new areas
Excellent organisational skills with a strong track record of successful delivering security projects
Strong relationship management and persuading and influencing skills
Highly motivated, entrepreneurial and autonomous
Strong analytical, problem-solving and process design skills
Resourceful, creative and inquisitive approach to highly complex tasks
Good written communication skills and attention to detail
Strong team player with leadership experience or potential
Robust, accountable and reliable
(Desirable) Understanding of HSBC’s policy framework for security
(Desirable) Understanding of Hadoop, Ab Initio, SAS, BAES Applied Intelligence technologies
(Desirable) Experience/knowledge of intelligence analytics
Within HSBC certain roles are designated as Enhanced Vetting Roles. For these roles, all internal and external applicants are required (subject to local laws), to pass satisfactorily a series of additional checks both as part of the application process and, if successfully recruited into the Enhanced Vetting role, on an on going basis. The Group reserves its position with regard to any steps which it may take in relation to any material adverse findings which arise either when the checks are first carried out as part of this recruitment exercise, and/or if relevant, on an ongoing basis.
This role has been designated as a Enhanced Vetting Role.
For more information about the relevant additional checks for this role please contact the hiring manager
We are an equal opportunity employer and are committed to creating a diverse environment.