gestor de incidentes de seguridad de la informaciónwe are currently seeking an experienced professional to join our team in the role of gestor de incidentes de seguridad de la información.role purposeglobal cybersecurity operations (gco) provides a coordinated suite of "information & network defence" services responsible for detecting and responding to information and cybersecurity threats to hsbc assets across the globe and is under the management of the head of global cybersecurity operations.
this includes dedicated functions for the monitoring and detection of threats within the global estate as well as cybersecurity incident management and response activities.
these two principal functions are supported by additional internal gco capabilities in; cyber intelligence and threat analysis, security sciences and client engagement and support services.
critical to the success of gco is its close partnership with sister cybersecurity teams, it infrastructure delivery, and global business and function clients.
the overall gco mission is placed under the purview of the group chief information security officer (ciso).
main activitiesthe information protection incident manager is accountable for:managing the response to data breach events and incidents across the globe, taking responsibility for the timely mitigation of data related risks and cyber-threats.coordinating the actions of multiple business units during the response to data breach events and incidents.providing timely and relevant updates to appropriate stakeholders and decision makers during data loss incidents.cultivating close working relationships with regional data protection officers, cybersecurity leads, business information risk officers (biros) and risk managers whose support and knowledge are vital in delivering the remediation of security data incidents.maintaining a strong awareness of regulatory trends, legislation, and industry best practice.triaging potential data breach events.adhering to any defined sla's.following detailed processes and procedures to analyse, respond to and/or elevate data breaches.supporting information security incidents through to eradication and feedback lessons learned, in to improved cyber resilience.identifying and developing new ideas to enhance our detection capability (use cases) and mitigations (playbooks).
reviewing and validating new use cases and playbooks.supporting handovers to other teams and countries at the start and end of the working shift.collaborating with the wider cybersecurity (and it) teams.identifying processes that can be automated and orchestrated to ensure maximum efficiency.supporting engagement in support of hsbc global businesses and functions to drive a general uplift in cyber‐security and information protection awareness.requirementssecurity and privacy acts, ffiec guidelines, cis and nist standards.ability to speak, read and write in english, in addition to your local language.technical skillsgood level knowledge of gdpr requirements and regulations.understanding of common operating systems and platforms.understanding of 3rd party cloud computing platforms such as aws, azure and google.understanding of common mobile platforms, such as blackberry, ios, android and windows.knowledge and understanding of the thought processes, methodologies (tactics, techniques & procedures) used by advanced adversaries, including criminal and nation state adversaries, spanning multiple aspects of the security domain.knowledge of common log management suites, security information and event management (siem) tools, use of "big data" and cloud‐based solution for the collection and real‐time analysis of security information.ability to produce key performance indicator (kpi) metrics for accurate and contextual evaluation of operational effectiveness as well as providing re#j-*-ljbffr