CISO CTO Infrastructure in Sheffield

CISO CTO Infrastructure in Sheffield

Sheffield Full-Time 120000 - 150000 £ / year (est.) No working from home possible
hackajob

At a Glance

  • Tasks: Lead security strategy for HSBC's global tech infrastructure and protect critical services.
  • Company: HSBC, a leading global banking and financial services organisation.
  • Benefits: Competitive salary, diverse workplace, and opportunities for professional growth.
  • Other info: Join a diverse team dedicated to inclusion and accessibility.
  • Why this job: Make a real impact on global security while collaborating with top professionals.
  • Qualifications: Senior leadership experience in security within a regulated environment.

The predicted salary is between 120000 - 150000 £ per year.

About HSBC

HSBC is one of the world’s largest banking and financial services organisations, serving millions of customers through our global network. We connect people, businesses and institutions to opportunities across international markets, supported by a broad range of banking and wealth services. At HSBC, we’re focused on opening up a world of opportunity – helping people and businesses thrive and supporting economies to prosper. If you’re looking for work with global reach, real‑world impact and the chance to collaborate with colleagues across markets, you’ll find it here.

The Role

As Chief Information Security Officer for CTO Infrastructure you’ll define and drive the security posture of HSBC’s global technology infrastructure estate across cloud, on‑premises data centres, network, identity, endpoint and operational technology. You’ll operate at the intersection of the CTO and CISO organisations to protect a complex, globally distributed environment across more than 40 jurisdictions. The role is directly relevant to the bank’s obligations under DORA, PRA/FCA supervisory expectations, NIS2 and emerging AI Act requirements. You’ll represent the bank before UK, EU and US regulators on infrastructure security matters and serve on the Group Security Leadership Committee. You’ll lead a globally distributed team of c.8–12 specialists and manage an operating budget typically in the range of $25–50M. Success means measurable improvement in infrastructure security resilience, strong regulatory outcomes and security embedded into the bank’s technology transformation.

What You Will Be Doing

  • Own the multi‑year infrastructure security strategy aligned to technology transformation, cloud migration and AI adoption.
  • Define and govern Zero Trust architecture standards across hybrid cloud and on‑premises environments.
  • Lead security architecture review and approval for major infrastructure programmes including cloud platform, SD‑WAN, core network refresh and OT modernisation.
  • Set and enforce multi‑cloud security posture across AWS, Azure, GCP and private cloud including CSPM, CNAPP and cloud workload protection.
  • Establish secure‑by‑default configuration standards and IaC guardrails across compute, storage, networking and container platforms.
  • Own infrastructure‑layer identity controls including PAM, machine identity and secrets management across management and control planes.
  • Strengthen detection, resilience and response for infrastructure‑layer threats including exercises, TLPT scope and P1/P2 incident leadership.
  • Govern security risk across critical infrastructure suppliers including DORA‑aligned third‑party monitoring and concentration risk assessments.

Essential

  • Demonstrated security leadership experience including senior director‑level leadership in a Tier 1 global financial institution or equivalent regulated enterprise.
  • Deep technical grounding across infrastructure security including network, multi‑cloud, identity and PAM, endpoint and OT/ICS security.
  • Show accountability for a significant infrastructure security programme in a multi‑jurisdictional regulated environment.
  • Evidence strong engagement with regulators including PRA, FCA, ECB, NYDFS and MAS on infrastructure security matters.
  • Lead major incident response for infrastructure security events including ransomware, nation‑state intrusions or significant cloud incidents.
  • Design and implement Zero Trust architecture at enterprise scale.
  • Apply strong cloud security architecture expertise across AWS, Azure and GCP including CSPM, CNAPP, cloud IAM and network security.
  • Build and lead globally distributed security engineering teams and manage large budgets and vendor relationships with rigour.

Desirable

  • Secure agentic AI and LLM infrastructure including MCP server security, AI gateway controls and GPU cluster hardening.
  • Manage TIBER‑EU / CBEST red team scoping and remediation programmes.
  • Plan quantum‑safe cryptography transition for infrastructure components.
  • Hold CCSP or AWS/Azure Security Specialty certification or CREST or equivalent TLPT qualification.

Securing HSBC’s infrastructure backbone

This is a senior leadership role with real accountability for the resilience of the technology foundations HSBC depends on every day. You’ll shape how security is designed into cloud platforms, networks, identity and OT environments at global scale – protecting critical services across 40+ jurisdictions. If you’re at your best when translating complex technical risk into clear executive decisions and leading teams through high‑stakes moments, you’ll thrive here. Bring your judgement, technical depth and collaborative influence and help set the standard for infrastructure security across the bank.

Being open to different points of view is important for our business and the communities we serve. At HSBC, we’re dedicated to creating diverse and inclusive workplaces – no matter their gender, ethnicity, disability, religion, sexual orientation, socio‑economic background or age. We are committed to removing barriers and ensuring careers at HSBC are inclusive and accessible for everyone to be at their best. We take pride in being a Disability Confident Leader and will offer an interview to people with disabilities, long term conditions or neurodivergent candidates who meet the minimum criteria for the role. If you have a need that requires accommodations or changes during the recruitment process, please contact the Recruiter.

CISO CTO Infrastructure in Sheffield employer: hackajob

HSBC is an exceptional employer, offering a dynamic work environment where innovation meets global impact. As a leader in the banking and financial services sector, we prioritise employee growth through diverse opportunities and a commitment to inclusivity, ensuring that every voice is heard. With a focus on collaboration across international markets and a robust support system for professional development, HSBC empowers its employees to thrive while making a meaningful difference in the world.

hackajob

Contact Details:

hackajob Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land CISO CTO Infrastructure in Sheffield

Tip Number 1

Network like a pro! Reach out to your connections in the industry, attend relevant events, and engage with professionals on platforms like LinkedIn. We can’t stress enough how important it is to make those personal connections that could lead to job opportunities.

Tip Number 2

Prepare for interviews by researching HSBC’s values and recent projects. Tailor your responses to show how your experience aligns with their mission. We want you to shine, so practice common interview questions and have your own ready to ask!

Tip Number 3

Showcase your expertise! Create a portfolio or a presentation that highlights your achievements in infrastructure security. We believe that demonstrating your skills can set you apart from other candidates, especially for a role as critical as CISO CTO.

Tip Number 4

Don’t forget to apply through our website! It’s the best way to ensure your application gets seen. Plus, we’re always looking for passionate individuals who are ready to make an impact at HSBC, so let’s get your application in!

We think you need these skills to ace CISO CTO Infrastructure in Sheffield

Security Leadership
Infrastructure Security
Zero Trust Architecture
Cloud Security Architecture
Multi-Cloud Security Posture Management
Identity and Access Management (IAM)
Incident Response Management

Some tips for your application 🫡

Tailor Your Application:Make sure to customise your CV and cover letter to highlight your experience in infrastructure security, especially in a regulated environment. We want to see how your skills align with the specific requirements of the CISO CTO Infrastructure role.

Showcase Your Leadership Skills:Since this is a senior leadership position, it’s crucial to demonstrate your past leadership experiences. Share examples of how you've led teams through complex security challenges and your engagement with regulators.

Be Clear and Concise:When writing your application, keep it straightforward and to the point. Use clear language to explain your technical expertise and how it relates to the role. We appreciate clarity as much as complexity!

Apply Through Our Website:Don’t forget to submit your application through our official website. It’s the best way for us to receive your details and ensure you’re considered for this exciting opportunity at HSBC!

How to prepare for a job interview at hackajob

Know Your Stuff

Make sure you have a solid understanding of infrastructure security, especially in a multi-cloud environment. Brush up on Zero Trust architecture and be ready to discuss how you've implemented it in past roles. This will show that you’re not just familiar with the concepts but can apply them effectively.

Engage with Regulators

Since this role involves liaising with regulators like the PRA and FCA, prepare examples of your past interactions with regulatory bodies. Highlight how you’ve navigated compliance challenges and improved security posture in regulated environments. This will demonstrate your capability to handle the responsibilities of the position.

Show Leadership Skills

Be ready to talk about your experience leading teams, especially in high-pressure situations like major incident responses. Share specific examples of how you’ve managed large budgets and vendor relationships, as well as how you’ve built and led globally distributed teams. This will showcase your leadership style and effectiveness.

Prepare for Technical Questions

Expect deep technical questions related to cloud security, identity management, and incident response. Review key concepts and be prepared to discuss your approach to securing cloud platforms like AWS, Azure, and GCP. This will help you convey your technical depth and readiness for the challenges of the role.