About the Role
HSBC Saudi Arabia is seeking a Data Security Manager to join its team in Riyadh. This role is integral to developing, implementing, and monitoring information security policies and procedures across HSBC Saudi Arabia's business operations. The Data Security Manager will be responsible for fostering awareness of security risks and potential fraud, and will play a key role in Business Continuity Risk Management (BCM) and SMART IT Segregation, with a specific focus on Data Security.
This position involves overseeing all aspects of Information Security Risk for HSBC Saudi Arabia, encompassing Data Security, Threat & Incident Management, Business Controls, Third Party Security, and Technical Security. The role holder will contribute to the design and execution of the Cyber Security strategy, providing essential support to the CISO and CRO, and advising on the management and operations of security controls for critical HSBC Saudi Arabia services. The ideal candidate will possess a deep technical understanding of security controls, a hands-on technical background, strong stakeholder management skills, and a commitment to continuous learning and development.
Key Responsibilities
- Own and lead the implementation, operation, and continuous improvement of data security controls, ensuring the confidentiality, integrity, and availability of organizational data across all environments.
- Operate and manage data security technologies and platforms, including Data Loss Prevention (DLP), data classification, encryption, discovery, and monitoring tools, ensuring their configuration, tuning, enhancement, and ongoing optimization.
- Monitor, detect, and trigger responses to data security incidents, ensuring timely escalation, investigation, coordination with Security Operations Center (SOC)/Incident Response (IR) teams, and post-incident analysis in alignment with incident management processes.
- Develop, generate, and enhance data security reporting and dashboards, providing actionable insights, risk analysis, trends, and control effectiveness metrics for technical teams and senior management.
- Ensure alignment of data security controls with applicable standards, regulatory requirements, and internal policies, driving compliance and audit readiness across business units.
- Lead data security governance activities, including control ownership, risk assessments, exception handling, control uplift initiatives, and continuous maturity improvement.
- Review, update, and maintain data security policies, standards, and procedures, ensuring alignment with business operations, emerging risks, and global best practices.
- Act as a primary liaison with global and cross-functional teams, including IT, Security Operations, Legal, Compliance, and business stakeholders, to embed data security requirements into business processes.
- Translate technical data security risks and findings into business-focused insights, clearly presenting analysis, recommendations, and remediation plans to senior management and executive stakeholders.
- Drive continuous improvement initiatives, including control uplift, reporting enhancements, tool capability expansion, and operational process optimization.
- Support strategic data security initiatives by bridging hands-on technical execution with governance, policy, and management-level oversight.
- Develop information security policies and procedures in accordance with HSBC group standards and industry standards such as ISO and COBIT to ensure up-to-date information security and integration solutions at HSBC Saudi Arabia.
- Supervise the implementation and oversee adherence to agreed policies and compliance practices to create a secure environment for HSBC Saudi Arabia’s business operations.
- Review, collate, and analyze monthly Business Risk Information Officer (BIRO) Reports to identify policy-related risks within respective business units.
- Maintain a close awareness of best practices and industry standards in Information Security, assess potential security threats and risks to HSBC Saudi Arabia IT infrastructure, systems, network, and data, and recommend improvements in policies.
- Enforce appropriate security standards for access control functions and IT Security, and monitor all exceptions closely.
- Implement and manage the BIRO program for HSBC Saudi Arabia, ensuring all risk assessment activities are undertaken within assigned BIRO areas, and work directly with staff to explain the risk assessment process, risk identification, measurement, and mitigation/elimination actions.
- Support general information security/risk oversight and awareness programs implemented across the business, including town hall meetings, marketing initiatives, and informal meetings addressing information security topics.
- Involve in Cyber Security projects and create Engineering solutions in the Data Security Area.
- Configure and run DLP solutions and data scanning tooling.
- Provide production support to Data Security tooling (such as Symantec, McAfee, MIP).
- Utilize Confluence and Jira for Project and Production support tasks.
- Manage stakeholder relationships, including business communication and audit management.
Qualifications and Requirements
- Typically educated to degree level.
- 4 to 5 years of experience in Data Security Engineering.
- Experience with DLP products such as Symantec DLP and SkyHigh DLP, with hands-on experience deploying data discovery tools.
- Demonstrable experience in Data in Motion and/or Data at Rest Security.
- Experience in Agile Methodology and project planning & management.
- Experience in Data Incident Management.
Required Skills
- Data Security
- Threat & Incident Management
- Business Controls
- Third Party Security
- Technical Security
- Infrastructure Security
- Application Security
- Access Management
- Cyber Security Strategy
- Security Controls
- DLP (Data Loss Prevention)
- Data Classification
- Encryption
- Data Discovery
- Data Incident Management
- Risk Management
- Agile Methodology
- Project Planning & Management
- Stakeholder Management
- Business Communication
- Audit Management
- Symantec DLP
- SkyHigh DLP
- Data in Motion Security
- Data at Rest Security
- Jira
- Confluence
- ISO Standards
- COBIT Standards
- Information Security
- IT Security
- Risk Assessment
- Communication
- Leadership
Work Environment and Additional Information
This is a full-time position based in Riyadh, Saudi Arabia. Industry qualifications such as CISSP, CISA, or CISM are preferred but not essential.