Job Title: Principal Information Security Specialist
Nomura Overview:
Nomura is a financial services group with an integrated global network. By connecting markets East & West, Nomura services the needs of individuals, institutions, corporates and governments through its four business divisions: Wealth Management, Investment Management, Wholesale (Global Markets and Investment Banking), and Banking. Founded in 1925, the firm is built on a tradition of disciplined entrepreneurship, serving clients with creative solutions and considered thought leadership. For further information about Nomura, visit www.nomura.com.
Nomura Services, India supports the group’s global businesses. With world-class capabilities in trading support, research, information technology, financial control, operations, risk management and legal support, the firm plays a key role in facilitating the group’s global operations across four international regions.
At Nomura, creating an inclusive workplace is a priority. Our approach to inclusion encompasses a variety of initiatives, including sensitization campaigns, implementing conducive policies & programs, providing infrastructure support and engaging in community events. Over time, we have made meaningful progress in these areas, and this commitment has been well-recognized across the industry. We are proud recipients of the prestigious Top 10 Employers award by the India Workplace Equality Index (IWEI), IWEI Gold Employer of Choice awards, India CSR Leadership Award 2024 for Holistic Village Development Program and the YUVA Unstoppable Changemaker Awards.
Roles & Responsibilities:
Security Architecture & Design:
- Define enterprise Data Protection reference architectures and security design patterns.
- Embed Security-by-Design and Privacy-by-Design principles into the SDLC and project lifecycle.
- Review solution architectures and recommend appropriate data protection controls.
- Perform architecture governance during project initiation, design, implementation, and production readiness reviews.
- Develop security standards and guidelines.
- Create detailed architecture diagrams and documentation using visualization tools.
- Collaborate with security engineering teams to integrate security requirements into the software development lifecycle.
- Perform security risk assessments and threat modeling exercises.
- Support audit activities and compliance reporting.
- Manage security architecture projects and initiatives using Jira for tracking and workflow management.
- Maintain comprehensive documentation in Confluence including security standards, procedures, and knowledge base articles.
- Provide security guidance and recommendations to stakeholders.
- Participate in architecture review boards and security committees.
Data Lifecycle Protection
- Understand and assess data throughout its lifecycle:
- Data Creation
- Data Collection
- Data Discovery
- Data Classification
- Data Storage
- Data Processing
- Data Sharing
- Data Retention
- Data Archival
- Secure Disposal
- Identify risks at every lifecycle stage and recommend appropriate protection mechanisms.
Data Protection Technologies
Design and provide architectural guidance for:
- Enterprise Data Discovery
- Information Classification & Labeling
- Microsoft Purview Information Protection
- Data Loss Prevention (Endpoint, Email, Cloud, Network)
- Information Rights Management (IRM)
- Encryption (Data at Rest, In Transit, In Use)
- Tokenization
- Static & Dynamic Data Masking
- Database Security Controls
- Key Management Systems (KMS)
- Certificate Lifecycle Management
- Secrets Management
- Hardware Security Modules (HSM)
- Cloud-native data protection capabilities
Project & Solution Advisory
- Participate in project design workshops.
- Perform security architecture reviews.
- Define mandatory security controls for new applications.
- Identify security design gaps and provide remediation recommendations.
- Review High-Level Designs (HLD) and Low-Level Designs (LLD).
- Provide implementation guidance to engineering teams.
- Support threat modelling focused on data protection risks.
Governance & Compliance
- Ensure alignment with enterprise Data Security and Cryptography Standards.
- Support Secure Architecture Evaluation and project governance forums.
- Validate adherence to regulatory requirements such as GDPR, DPDP, MAS, DORA, JFSA, etc.
- Define architecture guardrails and security exceptions where required.
Knowledge, Skill, Experience Required:
Required:
· Must have 10-15 years of hands-on experience in cybersecurity domain.
- Proven experience in security architecture assessments and secure-by-design implementations.
- Strong knowledge of data protection technologies including DLP platforms, data discovery tools, and classification frameworks.
- Familiarity with Cloud Access Security Brokers (CASB) and cloud data protection solutions.
- Experience with data discovery and classification technologies for identifying and protecting sensitive data.
- Experience with cloud security, especially related to data protection, visibility, and access controls.
- Experience with enterprise security frameworks and methodologies.
- Deep understanding of security architecture principles and frameworks.
- Proficiency in threat modeling methodologies (STRIDE, PASTA)
- Knowledge of security controls and standards (NIST, ISO 27001, CIS Controls)
- Experience with security assessment tools and techniques.
- Understanding of network security, application security, cloud security and data protection domains.
- Expertise in creating detailed architecture diagrams using visualizations, including network diagrams, system architecture, data flow diagrams, and security control mappings
- Strong documentation skills with experience in creating technical specifications, security procedures, and architectural decision records.
- Preferred certifications: CISSP, CCSP, Microsoft SC-100/400, TOGAF, SABSA etc.
Beneficial:
- Strong analytical and problem-solving abilities
- Excellent written and verbal communication skills
- Ability to work independently and manage multiple priorities
- Strong attention to detail and quality-focused approach
- Experience working in agile environments with cross-functional teams
Personal Characteristics:
- Strong analytical and problem-solving abilities.
- Excellent written and verbal communication skills.
- Ability to work independently and manage multiple priorities.
- Strong attention to detail and quality-focused approach.
- Experience working in agile environments with cross-functional teams.
We are committed to providing equal opportunities throughout employment including in the recruitment, training and development of employees. We prohibit discrimination in the workplace whether on grounds of gender, marital or domestic partnership status, pregnancy, carer’s responsibilities, sexual orientation, gender identity, gender expression, race, color, national or ethnic origins, religious belief, disability or age.
*Applying for this role does not amount to a job offer or create an obligation on Nomura to provide a job offer. The expression "Nomura" refers to Nomura Services India Private Limited together with its affiliates.
*The benefits are subject to change and will be in accordance with Company’s policies as may be applicable from time to time).