CTE QA Architect
Summary
Define and implement cybersecurity testing strategy, QA maturity frameworks, and audit-ready evidence standards for HSBC’s global cyber teams, driving adoption of automated testing and DevSecOps practices.
Role: Testing
Strategy & QA Governance Consultant (Cyber)
Location: Sheffield, UK (Hybrid role, require 2-3 days a week onsite)
Big Bank Funding. FinTech Thinking
Our technology teams work closely with
HSBC’s global businesses to help design and build digital services that allow
our millions of customers around the world, to bank quickly, simply and
securely. We also run and manage our IT infrastructure, data centres and core
banking systems that power the world’s leading international bank.
Our multi-disciplined teams include DevOps
engineers, IT architects, front and back-end developers, infrastructure
specialists, cyber experts, as well as project and programme
managers.
Following extensive investment across our
Technology and Digital domains and with plans for continued expansion
throughout 2025 and beyond, we are currently seeking a QA Architect who will be
able to define the Testing Strategy and standards across Cyber as part of a
central Professional Testing Practise. This is a delivery-focused role
with clear outcomes: you’ll be accountable for defining and embedding
Cyber-wide testing strategy, QA maturity assessment and an actionable
remediation roadmap.
Business area
overview
Cybersecurity Technology & Engineering
is responsible for fielding solutions that help defend HSBC against a wide
range of threats to the business as well as its customers, clients, partners,
and staff. The team works in concert, with partner teams across HSBC, to
implement novel defensive capabilities that are effective and adaptable against
a constantly evolving threat landscape. The function operates under the
vision: “Enabling HSBC to be safely successful everywhere the Firm chooses to
do business”.
What you will be
doing
The
role will report to the Cyber QA Practice lead and will be responsible for supporting
the establishment and development of Cyber's Professional Testing Practise, contributing
to its strategic direction and helping to drive improvements across all facets
of testing across Cyber. The role will involve working closely with a wide
range of stakeholders including Cybersecurity project teams, Control Owners,
and the business. The role is outcome-driven and will be measured on
delivery of agreed artefacts and adoption across Cyber teams.
The
role will:
- Define and deliver, with guidance from the
Cyber QA Practice Lead, the Testing Strategy, QA Maturity Framework and QA
standards to be used across Cyber, including the frameworks, processes, methodologies
and tooling that should be used and adopted by the Cyber teams.
- Lead on the Maturity Framework assessment
and definition of the remediation plan needed to meet the agreed framework
levels. This includes driving the adoption of automated test practices
across Cyber and assisting teams in determining the correct level of
performance and stress testing to be performed. This will cover both in-house
developed applications and third-party applications that are supported and
maintained by the Cyber teams.
· Provide support and
assistance to the Cyber QA Practice Lead and help ensure their vision is
effectively developed and implemented across the Cyber delivery teams.
- Define and deliver appropriate training
for the Testing Practice members and QA professionals within the Cyber
teams and monitor adoption and usage of QA tools within the existing
environments.
- Provide standards and guidance for testing
evidence suitable for audit review in our Regulated business environment
and ensure that teams are following these guidelines and provide metrics
and dashboards to support adoption tracking.
· Work with the Cyber QA Practice Lead to establish
clear KPIs and OKRs for the Cyber QA Team, tracking delivery performance,
quality improvements, and process efficiency.
Key deliverables (examples):
· Cyber
Testing Strategy (incl. governance, tooling, metrics and adoption plan).
· QA
Maturity Assessment report + remediation roadmap (priorities, milestones,
ownership).
· Audit-ready
testing evidence standards (templates, traceability expectations, minimum
evidence set).
· KPIs/OKRs
and dashboards to track quality, efficiency and adoption.
What you will bring
to the role
- Proven experience defining and delivering departmental Testing
Strategies and governance frameworks including best practices across
multiple teams and regions
· Proven experience in aligning testing strategy with business goals. 6+ years of
QA experience, 2+ years in a QA Manager or QA Architect Lead role;
· Proven experience supporting QA/audit readiness in regulated
environments (evidence, traceability, controls)
· Participation in
internal/external QA audits or working with Control Owners / Risk &
Compliance
· Relevant
training/certifications (e.g. ISTQB Advanced/Test Manager, audit/quality
governance courses)
· Strong
stakeholder management experience and the ability to influence and build
partnership across Teams and Departments in order to conduct data analysis and
present raw data in a simplified manner displaying trend analysis and
highlighting outliers/exceptions;
- Familiar with Agile software development
and DevSecOps delivery processes (burndown metrics, backlog tracking,
velocity, task definition, retrospectives and defect management) and
supporting tools, e.g., JIRA, Confluence, GIT, etc.
- Good verbal and written communication
skills in English, including experience of managing workshops and writing
best practice documentation;
- Able to work in a fast-paced, team-focused
environment with a proven track record of delivering and completing
assigned tasks as an individual and as team;
- Demonstrates a strategic leadership,
change management, continuous improvement mindset with a willingness to continuously
learn and share learnings with others.
Come Power a
Business that Defines How to Power the World
As a business operating
in markets all around the world, we believe diversity brings benefits for our
customers, our business and our people. This is why HSBC UK is committed to
being an inclusive employer and encourages applications from all suitably qualified
applicants irrespective of background, circumstances, age, disability, gender
identity, ethnicity, religion or belief and sexual orientation.
We want everyone to be
able to fulfil their potential which is why we provide a range of flexible
working arrangements and family friendly policies.
As an HSBC employee in
the UK, you will have access to tailored professional development opportunities
and a competitive pay and benefits package. This includes private healthcare
for all UK-based employees, enhanced maternity and adoption pay and support
when you return to work, and a contributory pension scheme with a generous
employer contribution.
Personal data held by
the Bank relating to employment applications will be used in accordance with
our Privacy Statement, which is available on our website.