Job Title: Risk & Control Analyst
Company overview
Nomura is a global financial services group with an integrated network spanning approximately 30 countries and regions. By connecting markets East & West, Nomura services the needs of individuals, institutions, corporates, and governments through its three business divisions: Wealth Management, Investment Management, and Wholesale (Global Markets and Investment Banking). The business divisions are supported by Corporate Functions, including Group Chief Information Office (GCIO). Founded in 1925, the firm is built on a tradition of disciplined entrepreneurship, serving clients with creative solutions, and considered thought leadership. We operate in approximately 30 countries and regions with a diverse workforce of about 26000 people. For further information about Nomura, visit www.nomura.com.
Role description
Nomura in Powai is looking for a Risk and Controls Analyst. This role will be responsible for implementing the GCIO risk management framework and tool(s). The incumbent will work with Nomura vendors and support the delivery of Service Now – Integrated Risk Management (SNOW – IRM) within GCIO.
This is an excellent opportunity for an experienced Risk and Controls Analyst looking for career development.
The ideal candidate will have a breadth of experience in Non-Financial Risk Management Frameworks.
- Adherence to Risk Framework - Assist in the implementation, and continued adherence to the GCIO Risk Management Framework
- Risk Appetite - Engaging appropriate stakeholders (Technology, ORM, Compliance, Legal, Audit, BCM etc.) to establish Nomura’s “risk appetite” ensuring any key metrics are produced and presented in the context of stated appetite.
- Audit Support - Liaise with Internal/External auditors and regulators etc. through all phases of an audit including providing independent input/advise to technology teams being audited (auditee), liaising with Auditors to ensure identified risks are appropriately represented and dimensioned. Other key elements of audit support include educating technology teams in their responsibilities during an audit (audit engagement), ensuring requested information is sourced, reviewed, and provided in a timely and secure manner.
- Risk related activities/initiatives - Support the full range of IT risk activities including -
- IT incidents
- Change
- Internal / External audits
- Risk assessments
- Risk workshops
- Disaster recovery planning / walkthroughs / exercises
- Attestations / affirmation
- Remediation tracking
- Maintenance of artefacts
- Facilitate cross-technology and cross-division forums / meetings etc.
- Formal Reporting - Assist in the production of both ad-hoc and periodic risk reporting - appropriately tailoring reports for target audience.
- Informal Reporting - Provide ongoing status updates of pertinent risk, incidents, and other risk related activities/initiatives to management.
- Automate Reporting - Automate ongoing and new status reports of pertinent risk, incidents, and other risk and/or audit related activities/initiatives to management.
- Risk Assessment - Undertake risk assessments (RCSA) with Technology functions ensuring identified risks that are out of appetite are appropriately analysed against defined criteria for potential impact/likelihood and pragmatic remediation plans are appropriately defined and tracked.
- Controls Assessment - Organizing and conducting independent controls assessments evaluating the design and operating effectiveness of the controls, providing independent opinion to management, and tracking any necessary remedial efforts.
- Application risk assessment - Organizing and conducting independent application risk assessments evaluating providing independent opinion to management and tracking any necessary remedial efforts.
- Training & Awareness - Act as the risk subject matter expert to Technology units providing day-to-day support, education, and training to staff to raise risk awareness and skill levels that help us embed risk management within our day-to-day activities.
- Risk Management Tool – Support the implementation of GCIO risk management tool
- 5-7 years’ experience in Risk management, preferably within financial services
- Expertise in MS Office (O365) suite for Reporting (very good at Excel), MIS (very good at Power point)
- Prior experience in using a Risk Management tool, preferably ServiceNow.
- Understanding of industry standards like ITIL, COBIT and NIST
- Excellent analytical and problem-solving skills
- Good interpersonal skills necessary to work effectively with a variety of individuals and departments
- Good organizational skills that support multiple units of Technology in a time sensitive global environment
- Ability to work with both remote teams and across division
- Strong attention to detail in supporting management reporting with clear and concise data points and presentation
- Result-oriented, proactive and adaptive
- Self-starter and Team player
- Ability to manage multiple tasks, as well as prioritize; time management
- Demonstrate an excellent track record in execution of the tasks at hand
- Strong understanding of regulatory requirements and industry best practices related to controls assurance, relevant to GCIO risks – such as Information Technology (IT), Information Security (IS), and/ or Data Management
- Exceptional communication skills, both verbal and written, with the ability to influence and engage stakeholders at all levels.
- Experience operating in a regulated environment and managing stakeholders across the Three Lines of Defense.
- Strong organization skills and attention to detail.
Qualifications
- Bachelor’s degree in Finance, Information Technology (IT), Business Administration etc
- Risk management certification (e.g., CRISC) preferred.
Nomura Competencies – Associate/Analyst
Trusted Partner
- Understand clients’ needs and issues and respond with high- quality proposals.
- Acquire capabilities to perform one’s responsibilities and contribute to being a Trusted Partner
Entrepreneurial leadership
- Produce new ideas that might challenge the status-quo or oneself.
Teamwork - Collaboration
- Seek advice from senior colleagues and utilize it for improved results.
- Collaborate with members from relevant departments.
Teamwork - Influence
- Contribute to the success of the organization both quantitatively and qualitatively, and act with awareness of the impact on others.
- Serve as role model and provide guidance to junior employees.
Integrity
- Have a good understanding of corporate philosophy, professional ethics, compliance, risk management, and code of conduct, and make decisions and take actions accordingly.
Diversity Statement
Nomura is committed to an employment policy of equal opportunities and is fundamentally opposed to any less favourable treatment accorded to existing or potential members of staff on the grounds of race, creed, colour, nationality, disability, marital status, pregnancy, gender, or sexual orientation. If you require any assistance or reasonable adjustments due to a disability or long-term health condition, please do not hesitate to contact us.
Right to Work
Nomura is an Equal Opportunity Employer