Associate Director, Tech SME
Indexed description
We are currently seeking an experienced professional to join our team in the role of Associate Director, Tech SME.
Business: MSS Operations Technology
Job ID: 54081
Principal Responsibilities
- Regional risk & control leadership
Establish consistent control execution across applications and teams, ensuring “secure-by-design” is embedded in delivery ways of working.
Provide oversight of key technology and cyber risks, ensuring appropriate governance and escalation where required.
- Control assessment, monitoring and remediation
Identify control gaps and drive remediation plans with clear ownership, milestones, and measurable outcomes.
Challenge and support teams to ensure remediation is proportionate, sustainable, and reduces residual risk.
- Issue and action plan lifecycle ownership
Ensure issues are accurately articulated (root cause, impact, risk statement) and supported by robust evidence for closure.
Maintain a clear view of thematic issues and systemic control weaknesses; drive cross-team fixes where needed.
- Audit and regulatory readiness (including ICMP)
Coordinate audit/regulatory evidence collection, ensuring completeness, quality, and timeliness.
Lead and coordinate ICMP responses and follow-ups, ensuring actions are owned, tracked, and delivered to commitment.
- Governance, MI and residual risk reporting
Provide forward-looking insights (emerging risks, hotspots, delivery impacts) to support decision-making.
Ensure reporting is consistent, accurate, and aligned to stakeholder expectations across Technology and Risk.
- Secure delivery enablement (Agile/DevOps engagement)
Support adoption of security tooling and interpret outputs from testing/scanning (e.g., vulnerability results, code quality/security findings) to drive remediation.
Promote pragmatic, automation-friendly controls that improve speed and safety.
- Capability building and culture
Foster a strong risk culture where teams understand “why” controls matter and how to implement them efficiently.
Create communities of practice across MSS Ops Tech to scale consistent control execution.
Knowledge & Experience/Qualifications
- Strong experience in technology risk and controls, cybersecurity risk, or technology assurance within a large financial services environment.
- Proven track record managing issues/action plans end-to-end, including evidence-based closure and effective challenge.
- Experience supporting audits and/or regulatory exams, including evidence coordination and response management.
- Working knowledge of secure SDLC and Agile/DevOps delivery practices, with the ability to translate control requirements into delivery actions.
- Strong stakeholder management skills—able to influence across engineering, operations, and risk functions.
- Excellent written and verbal communication, including governance reporting and senior-level presentations.
- Familiarity with common control and security frameworks (e.g., NIST, ISO 27001, COBIT) and technology control domains (access, change, vulnerability, resilience, third-party, logging/monitoring).
- Experience with security/testing tooling outputs (e.g., SAST/DAST, vulnerability scanning, dependency scanning) and interpreting results for remediation prioritisation.
- Experience operating in a regional/global matrix organisation with multiple application portfolios.
Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
***Issued By HSBC Software Development (GuangDong) Limited***
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search