Job Title: Lead Information Security Analyst
Nomura Overview:
Nomura is a financial services group with an integrated global network. By connecting markets East & West, Nomura services the needs of individuals, institutions, corporates and governments through its four business divisions: Wealth Management, Investment Management, Wholesale (Global Markets and Investment Banking), and Banking. Founded in 1925, the firm is built on a tradition of disciplined entrepreneurship, serving clients with creative solutions and considered thought leadership. For further information about Nomura, visit www.nomura.com.
Nomura Services, India supports the group’s global businesses. With world-class capabilities in trading support, research, information technology, financial control, operations, risk management and legal support, the firm plays a key role in facilitating the group’s global operations across four international regions.
At Nomura, creating an inclusive workplace is a priority. Our approach to inclusion encompasses a variety of initiatives, including sensitization campaigns, implementing conducive policies & programs, providing infrastructure support and engaging in community events. Over time, we have made meaningful progress in these areas, and this commitment has been well-recognized across the industry. We are proud recipients of the prestigious Top 10 Employers award by the India Workplace Equality Index (IWEI), IWEI Gold Employer of Choice awards, India CSR Leadership Award 2024 for Holistic Village Development Program and the YUVA Unstoppable Changemaker Awards.
Divisional Overview:
Powai Information security division is an integral part of Nomura where mostly support functions are delivered out of this entity. We mainly support Nomura wholesale business.
Senior management takes a hands-on approach within the department, and is keen to reward hard work, enthusiasm and success. Nomura presents a unique opportunity to learn and gain experience of a broad range of products and business lines within a supportive setting and surrounded by skilled professionals.
Business Overview:
We are seeking a skilled Automation Engineer to join our Information Security team within the Automation & AI function. This role combines Python development expertise with modern AI application development to drive intelligent automation initiatives across our security operations. The ideal candidate will bring hands-on experience building web applications, APIs, and AI-powered solutions, and security orchestration playbooks while maintaining a solid understanding of cybersecurity principles. You will work at the intersection of security, automation, and AI to transform how our organization approaches information security challenges.
What We Offer:
- We support employee wellbeing by ensuring a sense of purpose and belonging.
- We offer a comprehensive range of wellbeing services which allows employees to get access to the assistance they need at any point in their wellbeing journey.
- Our bespoke benefits support employees and their family’s holistic wellbeing and are inclusive of diverse identities and family structures.
Background Information:
Information Security Third Party Cyber Risk Management team conducts security assessment on vendor/third party supporting Nomura business teams for all of Nomura globally. There are various trigger points which ensure Information Security team is involved in the end to end lifecycle of Third Party engagement process and can perform necessary due diligence on the Third Party from Cyber Security perspective on information access and handling in line with Nomura policies and standard requirements.
Duties & Responsibilities:
- Maintain strong governance on the third-party cyber risk assessment (TPCRM) process in terms of complying with regional and global requirements.
- Identify non-compliances in Third Party Cyber Security control landscape and create and discuss the assessment reports with stakeholders.
- Perform Third Party Cyber Security assessments by coordinating with various business departments and Third Parties.
- Oversee third party governance across cyber assessment lifecycles including due diligence, reporting, issue remediation and reporting
- Provide recommendations to the Third Party to remediate identified non-compliances and document remediation plans.
- Periodically track non-compliances reported to the Third Parties for closure and validate the evidence shared by Third Parties.
- Ensure periodic reporting on all the open items and completed assessments.
- Liaise with stakeholders such as business owner, technology owner, legal team etc. to include the Information Security requirements in the contracts with third party vendor
- Maintain and update inventory of assessments and define re-assessment calendars.
- Carry out re-assessments based on defined re-assessment calendars.
- Generate daily/weekly/monthly KRI & KPI reports for internal and senior management consumption.
- Work in a strategic and operational capacity to enhance the Third Party Cyber Security Risk Management process based on various international regulatory requirements and industry best practices.
- Work with various stakeholders to automate the assessment and risk management process.
Knowledge, Skill, Experience Required:
Essential:
- Knowledge of regulatory frameworks and experience with regulatory compliance
- Familiarity with security standards (e.g., CRI, ISO 27001, NIST)
- In-depth understanding of information security principles and practices
- Knowledge of current cyber threats and mitigation strategies
- Strong collaboration skills along with the ability to effectively communicate complex security-related information to a business audience, including risk identification, assessment, and remediation activity.
- Excellent communication skills with the ability to articulate complex cyber threat information to technical and non-technical audiences.
- Demonstrable ability to create and maintain collaborative relationships in a large, multinational organization.
- Strong understanding of cyber security principles and technologies.
Beneficial:
- Specialist training or skills in one or more of the following:
- Security certification (CISA/CISM/CISSP/CRISC/ISO-27001 etc.).
- Cloud Security Certifications.
Personal Characteristics:
- Strong communication skills, ability to work comfortably with different regions
- Good team player, ability to work on a local, regional and global basis and as part of joint cross location initiative.
- Strong analytical and problem-solving abilities
- Ability to work independently and as strong team player in global team
Ability to run with multiple tasks concurrently and manage expectations appropriately
We are committed to providing equal opportunities throughout employment including in the recruitment, training and development of employees. We prohibit discrimination in the workplace whether on grounds of gender, marital or domestic partnership status, pregnancy, carer’s responsibilities, sexual orientation, gender identity, gender expression, race, color, national or ethnic origins, religious belief, disability or age.
*Applying for this role does not amount to a job offer or create an obligation on Nomura to provide a job offer. The expression "Nomura" refers to Nomura Services India Private Limited together with its affiliates.
*The benefits are subject to change and will be in accordance with Company’s policies as may be applicable from time to time).