Job Title: Sr. Information Security Analyst
Nomura Overview:
Nomura is an Asia-headquartered financial services group with an integrated global network spanning over 30 countries. By connecting markets East & West, Nomura services the needs of individuals, institutions, corporates and governments through its four business divisions: Retail, Asset Management, Wholesale (Global Markets and Investment Banking), and Merchant Banking. Founded in 1925, the firm is built on a tradition of disciplined entrepreneurship, serving clients with creative solutions and considered thought leadership. For further information about Nomura, visit www.nomura.com
Nomura is an equal opportunities employer. We are committed to providing equal opportunities throughout employment including in the recruitment, training and development of employees (including promotion, transfers, assignments and beliefs). We prohibit discrimination in the workplace whether on grounds of gender, marital or domestic partnership status, pregnancy, career’s responsibilities, sexual orientation, gender identity, race, colour, national or ethnic origins, religious belief, disability, or age. Our objective is to attract job applications and applications for development from the best possible candidates and to retain the best people.
Division Overview:
Global Chief Information Security Office:
- Demonstrate oversight and control of all Information Security activities globally spanning all businesses, regions and partners
- Fully align with the governance frameworks of Group CIO and the broader Nomura Group to ensure Information Security transparency is demonstrated to all stakeholder groups
- Align around a common set of strategic Information Security “capabilities” (spanning run and change) to proactively manage the maturity of these capabilities and consistently demonstrate their value to all stakeholder groups
The Global Chief Information Security Office has teams in Japan, America, Asia (including India), and Europe.
Business Unit Overview:
Within the Global Chief Information Security Office, the Security Risk and Control (SRC) function provides a structured framework for managing security across the organisation, aligning security efforts with business objectives, and ensuring compliance with regulatory requirements. Effective Security Risk and Control framework establishes policies, oversight of risk management and ensures adherence to relevant laws and industry standards.
Position Specifications:
|
Corporate Title |
Analyst / Associate |
|
Functional Title |
Senior Information Security Analyst |
|
Experience |
5 to 9 years |
|
Qualification |
Bachelor’s degree in engineering (Computer / Telecommunication), Computer Science / Information Technology or equivalent |
|
Requisition No. |
|
Job Summary:
We are seeking an experienced Information Security professional to join the Security Risk and Control team. The ideal candidate should have a strong background in risk management, regulatory change management, compliance, and audit management. This role requires a combination of technical expertise, excellent communication skills, and a thorough understanding of information security principles.
Role & Responsibilities:
Regulatory Management
- Monitor and interpret regulatory changes affecting information security, including specific requirements for the People's Republic of China (PRC) such as CSL, PIPL, DSL, and MLPS
- Ensure compliance with relevant laws and regulations across all jurisdictions
- Manage regulatory change processes and implementation
- Support gap analysis and remediation efforts to meet regulatory requirements
Audit Management
- Coordinate and manage audit exercises conducted by internal and external auditors, regulators, or external assessors
- Liaise with information security teams to prepare audit documentation and evidence
- Work with information security leads to address audit findings and track corrective actions through to closure
Risk Management
- Conduct risk assessments to identify potential information security risks
- Analyze risk trends and emerging threats to provide insights for risk mitigation
- Collaborate with cross-functional teams to ensure appropriate controls are in place to reduce risk exposure
Stakeholder Engagement and Communication
- Collaborate with information security teams, IT teams, and business units to communicate information security risks and provide guidance on risk mitigation
- Provide regular updates to relevant stakeholders on information security incidents, emerging risks, and matters requiring attention
Requirements – Skills, Experience, and Certifications:
Technical Skills
- Knowledge of regulatory frameworks and requirements (e.g., CSL, PIPL, HK SFC, MAS, etc) and experience with regulatory compliance
- Familiarity with security standards (e.g., CRI, ISO 27001, NIST)
- In-depth understanding of information security principles and practices
- Knowledge of current cyber threats and mitigation strategies
- A sound understanding and experience of incident response process.
- Understanding of security methodologies, best practice and industry standards.
Soft Skills
- Excellent communication and interpersonal skills
- Strong analytical and problem-solving abilities
- Ability to work independently and as part of a team
- Detail-oriented with strong organizational skills
- Ability to manage multiple tasks and projects simultaneously
Experience
- 5-9 years of experience in information security, with a focus on risk management, regulatory change management, compliance, and audit management
- Proven track record of managing and mitigating information security risks
Certifications
- Information Security related professional certifications (e.g., Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), etc.)