The Cybersecurity Assessment and Testing (CSAT) function, part of Global Cybersecurity, is accountable for Vulnerability Management, Secure Development (inc. DevSecOps), Threat and Controls Assessment (inc. threat modelling) and Third-Party Security Assessment. The function drives the identification, capture, assessment, testing/verification and ultimately the remediation of security defects, gaps and vulnerabilities across HSBC’s estate in conjunction with business and technology teams – on-premises, within the Cloud and for those resulting from third party engagements.
responsibilities :
Testing and deploying changes in line with HSBC procedures.
Designing, developing, implementing and maintaining workflow automation tools.
Providing production support including incident management, first and second line support for user queries, management of shared mailbox and handling related communications with stakeholders
Providing continuous support for existing content and automation running in the live environment, ensuring fast and quality driven bug fixes.
Maintaining and monitoring the logging and monitoring services needed to ensure the smooth operation of the CSAT services.
Maintaining proper security posture of the infrastructure in use, including patching and updating of servers, analysis and remediation of new and open vulnerabilities, enforcement of security standards.
Implementing changes, providing post go-live support, and ensuring that DevOps have the appropriate documentation and training needed to ensure a successful, uneventful go-live.
Proposing new technologies and techniques to quickly and comprehensively identify vulnerable infrastructure and platform.
requirements-expected :
5+ years of experience in a DevOps role within an agile delivery environment, Incident and Change Management as well as System Administration (e.g. configuring /managing servers, Linux/Windows).
3+ years of experience of CI/CD solution build up (GitHub/JIRA/Jenkins/Ansible).
1+ years of experience of SQL (e.g. MSSQL, PostgreSQL).
Good working knowledge of GCP and GKE, RHEL / Linux is required.
Good working knowledge of third-party cloud computing platforms such as Ali Cloud, AWS, Azure Python, MSSQL, PostgreSQL, IP networking, and Windows Server will be an advantage.
Experience implementing and maintaining highly scalable and resilient platforms and applications is required.
Experience working with technologies, such as Docker, Kubernetes, Hashicorp Vault, Jenkins, Terraform, Ansible Tower, Puppet, GIT, Application Dynamics, Splunk and xMatters is expected.
Ability to work and lead in a fast paced, team focused environment with a proven track record of delivering and completing assigned tasks as an individual and as team is required.
offered :
Competitive salary
Annual performance-based bonus
Additional bonuses for recognition awards
Multisport card
Private medical care
Life insurance
One-time reimbursement of home office set-up (up to 800 PLN)
Corporate parties & events
CSR initiatives
Nursery discounts
Financial support with trainings and education
Social fund
Flexible working hours
Free parking
benefits :
sharing the costs of sports activities
private medical care
sharing the costs of professional training & courses