Head of AppSec
HSBC · Hyderabad
- Experience7–20 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelexecutive
- Posted21 Sept 2026
About HSBC
HSBC is hiring in Hyderabad in financial services. This role looks for around 7+ years of experience.
Skills
- DevSecOps
- SAST
- DAST
- SCA
- IAST
- Secrets Management
- threat modeling
- STRIDE
- PASTA
- AWS
- Azure
- Google Cloud Platform
- Kubernetes
- microservices
- API security
- CNAPP
- application security
- software engineering
- secure architecture
- cybersecurity
- risk management
- supply chain security
- open-source software security
The role
A Head of Application Security at a global banking and financial services organization transforms application security through threat modeling, DevSecOps, and cloud security. The role builds developer-focused security practices, governs vulnerability risk, and aligns engineering, cyber, technology, and risk stakeholders.
Full job description
Some careers have more impact than others.
If you’re looking for further opportunities to develop your career, take the next step in fulfilling your potential right here at HSBC.
HSBC is one of the largest banking and financial services organizations in the world, with operations in 58 countries and territories. We aim to be where the growth is, enabling businesses to thrive and economies to prosper, and, ultimately, helping people to fulfil their hopes and realize their ambitions.
We are currently seeking an experienced professional to join our team in the role of Head of AppSec.
The Opportunity
We are seeking a modern, visionary, pragmatic, and collaborative Head of Application Security to transform our global AppSec function. Operating across multiple geographies, your mandate is to secure a vast, hybrid technology estate—ranging from core on-premises systems to modern cloud-native platforms—while actively tackling enterprise tech debt.
In this highly influential matrixed leadership role, you will bridge the gap between engineering velocity and rigorous financial-grade security. Success requires seamless cross-functional orchestration across Cyber, CTO (Chief Technology Officer), CIO (Chief Information Officers in Global Businesses), and the CRO (Chief Risk Officer) organizations to embed security into the DNA of our software delivery lifecycle (SDLC).
What You’ll Do
Strategic & Modern AppSec Transformation Shift-Left at Scale: Evolve traditional gatekeeping security practices into a developer-empowered, automated or autonomous "DevSecOps" model that integrates seamlessly into continuous delivery pipelines. Tech Debt & Risk Navigation: Formulate pragmatic, risk-based strategies to remediate vulnerabilities across legacy on-premise architectures and modern cloud environments without stifling business innovation. Unified Tooling & Automation: Drive the strategy and implementation of modern Application Security Testing (AST) capabilities—including SAST, DAST, SCA, IAST, and Secrets Management—with high signal-to-noise ratios. Engineering Leadership: Truly bring an engineering mindset to problem solving and is not afraid to build in house, built with speed and purpose to learn, and think enterprise grade and demonstrates ambition in problem solving. Matrixed Collaboration & Stakeholder Management Cross-Functional Orchestration: Act as the central nexus between Cyber (threat intelligence and architecture), CTO/CIO (engineering, platform, and infrastructure delivery), and CRO (regulatory compliance and operational risk). Influence Without Authority: Navigate a complex matrixed organizational structure to align competing priorities, secure executive buy-in, and drive accountability across global engineering teams. Developer Advocacy: Build a culture of "security champions" by fostering trust, providing continuous feedback loops, and delivering actionable, developer-friendly remediation guidance. Think Enterprise: Thinks and builds for the enterprise. Anticipates interlocks and connects across functions within Cyber and in larger Tech organization and works to bridge and collaborate for impact. Governance, Risk, and Compliance (GRC) in a Global Bank Regulatory Alignment: Ensure the AppSec framework satisfies multi-jurisdictional compliance mandates (e.g., global central bank regulations, PCI-DSS, GDPR, regional data sovereignty laws). Quantitative Risk Reporting: Translate technical vulnerability data into executive-level risk metrics, communicating business impact clearly to the CRO and operational risk committees. Third-Party & Open-Source Risk: Establish robust controls for managing supply chain security, open-source software dependencies, and third-party vendor components.
What You Will Need To Succeed In The Role
Technical Leadership
Deep Architectural Fluency: Hands-on background in software engineering or secure architecture, with comprehensive knowledge of both legacy on-premise infrastructure (mainframe, monolithic apps) and modern cloud environments (AWS, Azure, GCP, Kubernetes, Microservices). Modern AppSec Stack Mastery: Proven track record of scaling modern AppSec tooling, API security gateways, cloud-native application protection platforms (CNAPP), and automated vulnerability orchestration pipelines. Threat Modeling Expertise: Strong command of threat modeling methodologies (e.g., STRIDE, PASTA) tailored for complex, interconnected banking applications.
Functional & Cultural Leadership
Matrix Leadership in Scale: Experience in cybersecurity, with senior leadership role within a highly regulated, matrixed enterprise (ideally global financial services). Exceptional Communicator: Ability to fluently translate complex security metrics into business language for executive stakeholders (CIO, CTO, CRO) while maintaining technical credibility with elite engineering teams. Pragmatic Risk Mindset: An understanding that perfection is the enemy of progress in a legacy-heavy banking environment; ability to balance risk mitigation with business agility and speed-to-market. People Developer: Demonstrated success in building, mentoring, and inspiring globally distributed, high-performing engineering and security teams.
Education & Certifications
Bachelor’s or Master’s degree in Computer Science, Cybersecurity, Information Technology, or a related field. Relevant industry certifications (e.g., CISSP, CISM, CSSLP, AWS/Azure Security Certifications) are preferred.
You’ll achieve more when you join HSBC.
HSBC is an equal opportunity employer committed to building a culture where all employees are valued, respected and opinions count. We take pride in providing a workplace that fosters continuous professional development, flexible working and, opportunities to grow within an inclusive and diverse environment. We encourage applications from all suitably qualified persons irrespective of, but not limited to, their gender or genetic information, sexual orientation, ethnicity, religion, social status, medical care leave requirements, political affiliation, people with disabilities, color, national origin, veteran status, etc., We consider all applications based on merit and suitability to the role.
Personal data held by the Bank relating to employment applications will be used in accordance with our Privacy Statement, which is available on our website.
Issued By HSBC Software Development (India) Limited***