Some careers shine brighter than others.
If you’re looking for a career that will help you stand out, join HSBC and fulfil your potential. Whether you want a career that could take you to the top, or simply take you in an exciting new direction, HSBC offers opportunities, support and rewards that will take you further.
HSBC is one of the largest banking and financial services organizations in the world, with operations in 64 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realize their ambitions.
We are seeking a Senior Associate Director – Risk and Control Lead to lead the Risk & Controls agenda across the Technology/Data portfolio. This is a strategic leadership role to with hands-on accountability for control operations and control execution across technology, cyber, data, security and architecture control domains.
In this role, you will:
- Own the end-to-end Risk and Controls strategy and operating model for the portfolio, aligned to enterprise control expectations. Ensure DT adheres to CIO-defined KCIs/KRIs by driving accurate data sourcing, threshold monitoring, breach governance, timely remediation, and senior escalation where required.
- Provide a central, governed ‘golden source of truth’ for DT controls, obligations, KCIs/KRIs, issues/exceptions, audit evidence and reporting. Represent DT at senior risk & control governance forums and own the end-to-end management of materials (packs, dashboards, actions, follow-ups). Control Operations & Control Execution : Run DT’s control operating cadence ensuring controls are performed, evidenced, quality-checked, and completed on schedule across service lines. Own the control evidence standards (what good evidence looks like, where it lives, how it’s labelled, retention expectations) and drive consistent adoption.
- Manage exceptions and control breaches operationally: triage, accountable owner assignment, due dates, closure validation and re-occurrence prevention. Support ad hoc control testing/validation where required. Represent DT in senior governance forums including CTO RCMM, Architecture RCMM, CTO DT RCMM, and Business RCMM. Own forum governance end-to-end: agenda, pre-reads, KPI/KCI/KRI reporting, issue/exceptions narrative, action log, decision tracking, and closure governance. Maintain DT’s authoritative control inventory and mapping (controls to services/platforms/owners/obligations) and ensure its current.
- Control Execution Oversight & Advisory :Build and lead a virtual community of DT service-line control leads, running regular control forums to drive consistent control execution, evidence discipline, and prioritisation. Act as the senior advisor for technology controls, ensuring consistent interpretation and application across services and platforms. Guide ITSOs and engineering leaders in implementing and sustaining effective controls across the technology estate.
- Drive execution of portfolio control commitments (e.g., control programme activities such as TRCB where applicable) and ensure completion quality. Partner with IT Service Assurance and service owners to ensure controls are built into design and delivery (control-by-design), not bolted on after incidents/audits Audit & Assurance (Internal, External, Regulatory) : Lead audit readiness and audit execution across the portfolio: walkthrough planning, evidence standards, response governance, and stakeholder coordination. Manage relationships with Internal Audit, External Audit, and compliance partners; ensure timely, accurate responses and controlled communications. Validate findings, ensure root cause integrity, and drive resolution paths that stand up to re-test and scrutiny. Govern DT’s evidence repository and reporting datasets to ensure data integrity, traceability, and audit-ready reproducibility.
- Remediation & Issue Management (Sustainable Closure) : Own the lifecycle for audit/control issues: identify, triage, root cause, corrective action, evidence, testing, validation, and closure. Drive reduction of repeat findings, overdue issues, and systemic control weaknesses, focusing on durable fixes not tactical patches. Govern exceptions/risk acceptances where needed—ensuring approvals, time-bound actions, and compensating controls are in place and reported.
- Risk & Control Visibility (Executive Reporting): Provide transparent and decision-ready reporting on risk posture, control effectiveness, remediation health, and emerging themes. Publish dashboards/heatmaps and executive packs highlighting gaps, timelines, ownership, and cross-team dependencies. Escalate material risks early with clear options, impacts, and recommended actions.
- Automation, Analytics & AI Enablement (Controls): Drive automation and AI enablement across DT control execution, evidence management and reporting to improve control effectiveness and reduce manual overhead. Introduce continuous monitoring capabilities for key controls and KCIs/KRIs where practical, with defined alerting and exception workflows. Develop automated, standardised RMM reporting packs and dashboards with clear data lineage and governance.
To be successful in this role, you should meet the following requirements:
- 15–18+ years of experience in technology risk, IT controls, IT audit, compliance, governance, or operational risk within a large/global organisation.
- Proven expertise in technology controls, risk frameworks and standards (e.g., COBIT, NIST, ISO 27001, COSO/Three Lines Model where applicable).
- Strong track record leading audit management and remediation across complex technology environments (platforms, infrastructure, applications, data).
- Demonstrated ability to operate effectively from both perspectives:
Internal Audit / assurance delivery, and Auditee / control owner leadership and remediation accountability. - Excellent stakeholder management and influencing skills at senior leadership level; able to drive outcomes in a matrix organisation.
- Strong analytical and communication skills with ability to produce executive-ready materials (PowerPoint/Excel/Papers).
- Preferred Certifications :CISA, CRISC, CIA, CISSP/CISM, CGEIT, CPA/CA/ACCA, PMP (as relevant).
- People Leadership and Capability Building: Lead and develop a high-performing team across controls, audit response, remediation, and enablement. Set objectives/KPIs, coach leaders, manage performance, build succession plans, and invest in skills/certifications. Ensure adequate capacity planning aligned to audit/regulatory demand and portfolio risk profile. Build and lead a virtual community of DT service-line control leads, running regular control forums to drive consistent control execution, evidence discipline, and prioritisation.
You’ll achieve more when you join HSBC.
www.hsbc.com/careers
HSBC is committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and opportunities to grow within an inclusive and diverse environment. Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
Issued by – HSBC Software Development India