Cybersecurity Incident Handler

hace 2 semanas


distrito federal, México HSBC A tiempo completo

If you're looking for a career where you can make a real impression, join Global Service Center (GSC) HSBC and discover how valued you'll be. HSBC is one of the largest banking and financial services organisations in the world, with operations in 64 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realise their ambitions. We are currently seeking an experienced professional to join our team in the role ofCybersecurity Incident Handler Role Purpose Global Cybersecurity Operations (GCO) provides a coordinated suite of "Network Defence" services responsible for detecting and responding to information and cybersecurity threats to HSBC assets across the globe and is under the management of the Head of Global Cybersecurity Operations. This includes dedicated functions for the Monitoring and Detection of threats within the global estate as well as Cybersecurity Incident Management and Response activities. These two principal functions are supported by additional internal GCO capabilities in; Cyber Intelligence and Threat Analysis, Security Sciences and Client Engagement and Support Services. Critical to the success of GCO is it close partnership with sister Cybersecurity teams, IT Infrastructure Delivery, and Global Business and Function clients. The overall GCO mission is placed under the purview of the Group Chief Information Security Officer (CISO). The Cybersecurity Incident Management and Response Team is charged with efficiently and effectively handling all information and cybersecurity incidents across the Group on a 24x7 basis. This mission is critical to the protection of HSBC customers, the HSBC brand, shareholder value as well as HSBC information and financial assets. Main Activities further risk to HSBC's information assets and services. Coordinating the actions of multiple business units during the response to cyber security incidents. Providing timely and relevant updates to appropriate stakeholders and decision makers during cyber security incidents. Managing the completion of post-incident reviews, assessing the effectiveness of controls, detection and response capability, and supporting the required improvements with the responsible owners. Cultivating close working relationships with regional Cybersecurity leads, Business Information Risk Officers (BIROs) and Risk Managers whose support and knowledge are vital in delivering the remediation of security incidents. Maintaining a strong awareness of technology trends and industry best practice, to enable the provision of informed advice and guidance to HSBC Business functions and HSBC IT. Support the development and maintenance of detailed processes and procedures to allow the consistent management of the response to cyber security incidents. Supporting the continued technical enhancement of the security platforms. Supporting the continued evolution of incident management and response capabilities and processes, including automation and orchestration. Supporting a "self-critical" culture whereby identification of weaknesses in the bank's control plane (people, process, and technology) are brought to light in an effective manner and addressed. Supporting a culture of individual self-improvement whereby staff are expected to maintain subject matter expertise within their area of focus and within the realm of cybersecurity more broadly. Supporting engagement of Global Businesses and Functions everywhere HSBC does business that drives a global up-lift in cybersecurity awareness helping to "tell the story "Of HSBC Cybersecurity efforts. Production of Management Information related to the CSIRT mission that is appropriate to the target audience, supported by data and experienced analysis enabling informed decisions. Continued development of own incident management skills to enable the management of larger and more complex cyber security incidents. Qualifications Industry recognised cyber security related certifications including SANS GSEC, GCIH and/or CISSP Formal education and advanced degree in Information Security, Cyber-security, Computer Science or similar and/or commensurate demonstrated work experience in the same. Skills An understanding of business needs and commitment to delivering high-quality, prompt, and efficient service to the business. An understanding of organisational mission, values and goals and consistent application of this knowledge. Strong decision-making capabilities, with a proven ability to weigh the relative costs and benefits of potential actions and identify the most appropriate one. An ability to perform independent analysis of complex problems and distil relevant findings and root causes. An ability to communicate complex and technical issues to diverse audiences, orally and in writing, in an easily understood, authoritative and actionable manner. A team-focused mentality with the proven ability to work effectively with diverse stakeholders. Self-motivated and possession of a high sense of urgency and personal integrity. Highest ethical standards and values. Good understanding of HSBC cyber security principles, global financial services business models, regional compliance regulations and applicable laws. Good understanding and knowledge of common industry cyber security frameworks, standards and methodologies, including OWASP, ISO2700x series, PCI DSS, GLBA, EU data security and privacy acts, FFIEC guidelines, CIS and NIST standards. Proven ability and experience of working in a high-pressure, fast paced environment where bold, time critical decision making is essential. Proven experience in crisis management, crisis response frameworks and communications. Some experience of 3rd party/peer/regulatory/governmental information sharing and disclosure platforms and/or processes. Ability to speak, read and write in English, in addition to your local language. Technical Skills Excellent knowledge and demonstrated experience in incident response tools, techniques and process for effective threat containment, mitigation, and remediation. Good knowledge and demonstrated experience of common cybersecurity technologies such as IDS / IPS / HIPS, Advanced Anti-malware prevention and analysis, Firewalls, Proxies, MSS, etc. Good knowledge of common network protocols such as TCP, UDP, DNS, DHCP, IPSEC, HTTP, etc. and network protocol analysis suits. Good knowledge of common enterprise technology infrastructure, platforms, middleware, databases, applications, and tooling, including Windows, Linux, infrastructure management and networking hardware. Good knowledge and demonstrated experience in analysis and dissection of advanced attacker tactics, techniques, and procedures to inform adjustments to the control plane. Good knowledge and technical experience of 3rd party cloud computing platforms such as AWS, Azure, and Google. Competencies Observer Meticulous Due to the urgent hiring need, candidates with immediate right to work locally and no relocation need will be prioritised. At HSBC we offer our colleagues a greater number of leave days so that they can fully enjoy their wedding, take care of the new member of the family, or grieve the loss of a family member. Our paid leave package is at the forefront in Mexico, now you have one more reason to be HSBC and proudly live a culture of well-being, balance, and care. HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role. Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website. #J-18808-Ljbffr



  • distrito federal, México HSBC A tiempo completo

    A leading global financial organization in Mexico City seeks a skilled Cybersecurity Incident Handler to coordinate responses to cybersecurity incidents. The ideal candidate will manage incident reviews, work closely with various business units, and support the development of security processes. Candidates should possess industry-recognized certifications, a...


  • distrito federal, México BlackLine A tiempo completo

    A leading SaaS company in Ciudad de México is seeking a Senior Incident Management Analyst to ensure product reliability and improve incident response. Candidates should have over 5 years of experience in IT Operations or Cybersecurity and a Bachelor's degree in a related field. The role involves leading incident response efforts and collaborating with...


  • distrito federal, México Novartis México A tiempo completo

    A global healthcare leader is seeking an Associate Director of Threat Hunting and Response in Mexico City. This role is vital for active defense against cyber threats and involves managing incident response, performing forensic analyses, coordinating investigations, and mentoring junior CSOC members. The ideal candidate will leverage extensive cybersecurity...


  • distrito federal, México Mastercard A tiempo completo

    Our Purpose Mastercard powers economies and empowers people in 200+ countries and territories worldwide. Together with our customers, we’re helping build a sustainable economy where everyone can prosper. We support a wide range of digital payments choices, making transactions secure, simple, smart and accessible. Our technology and innovation, partnerships...


  • distrito federal, México BlackLine A tiempo completo

    Get to Know Us: It's fun to work in a company where people truly believe in what they're doing! At BlackLine, we're committed to bringing passion and customer focus to the business of enterprise applications. Since being founded in 2001, BlackLine has become a leading provider of cloud software that automates and controls the entire financial close process....


  • distrito federal, México CONSULTORIA EN INTERNET ERGO SUM A tiempo completo

    Overview Apply your knowledge of IT security, security operations, and incident response with a focus on Google Cloud Platform (GCP) to manage and oversee a 24x7 cybersecurity operations shift and incident response team. Document processes and procedures comprehensively in the form of playbooks and reference guides. Responsibilities Handle and coordinate...

  • SOC Threat Analyst

    hace 1 semana


    distrito federal, México HSBC Global Services Limited A tiempo completo

    Overview If you’re looking for a career where you can make a real impression, join Global Service Center (GSC) HSBC and discover how valued you’ll be. HSBC is one of the largest banking and financial services organisations in the world, with operations in 64 countries and territories. We aim to be where the growth is, enabling businesses to thrive and...


  • distrito federal, México Citi A tiempo completo

    Job Overview The Chief Information Security Officer (CISO) is a senior executive responsible for establishing and maintaining the bank's information security strategy and ensuring that all information assets and technologies are adequately protected. The CISO plays a critical role in safeguarding the bank's data, ensuring compliance with local regulations,...

  • IT Risk Specialist

    hace 2 semanas


    distrito federal, México Nubank A tiempo completo

    About the Role We are a leading fintech company in Mexico, at the forefront of revolutionizing financial services through technology and innovation in Latin America. We are seeking a dynamic and experienced IT Risk Specialist to support the execution of the IT Risk programs and activities within the Non Financial Risk squad in Nu Mexico. This role combines...

  • Sr Security Specialist

    hace 2 semanas


    distrito federal, México Logicalis A tiempo completo

    Descripción de la posición Experiencia en posiciones relacionadas con Ciberseguridad (consultoría, operación, implementación, soporte). Responsabilidades Experiencia en posiciones de preventa de soluciones de Ciberseguridad, cualquier rubro. Experiencia en armado de propuestas técnicas referentes a arquitecturas de Ciberseguridad. Experiencia en el...