Risk Manager IT, Information Security, Business Resilience and Third Party Risk Management
Nomura
- Location
- New York, NY, US, 10019
- Work model
- On-Site
- Level
- Mid
- Salary
- $220k – $270k/yr
About this role
Job Title: Risk Manager IT, Information Security, Business Resilience and Third Party Risk Management Department: Risk Management Location: New York Corporate Title: Executive Director The pay range for this position at commencement of employment is expected to be between $220,000 to $270,000 per year (see below footnote for additional compensation and benefits information). Company overview Nomura is a financial services group with an integrated global network. By connecting markets East & West, we service the needs of individuals, institutions, corporates and governments through our four business divisions: Wealth Management, Investment Management, Wholesale (Global Markets and Investment Banking) and Banking. Driven by the insights of some 28,000 people worldwide, we put our clients at the center of everything we do, delivering unparalleled access to, from and within Asia. For further information about Nomura, visit www.nomura.com Aon’s Benefit Index®, Nomura’s benefits rank #1 amongst our competitors Department Overview: Risk Management supports Nomura to achieve its business goals by partnering with business units across the firm, providing independent advice to the Board and protecting the firm from exposure to losses as a result of credit, market, operational and other risks. The Operational Risk Management (ORM) 2LoD function is part of the Risk Management organization and is responsible for:
Developing operational risk frameworks and policies Providing independent oversight over operational risks and challenging First Line of Defense Monitoring risk appetite compliance Reporting to senior management and committees
Key Responsibilities: In this role, you will be the second line of defense risk manager overseeing Nomura Information Technology and Information Security (IT & IS), Business Resilience as well as Third Party risks (TPRM). You will focus on:
Check and Challenge the ICT risk profile of the Americas operations as well as participate in risk management programs for Nomura globally
Provide independent risk opinions on compliance with relevant regulatory and industry expectations (NIST, FFIEC…) Review the risk profile across IT change management, identity and privileged access (IAM/PAM), resilience, vulnerability and patch management, data leakage prevention, etc. Review and challenge the 1LoD controls rollout and results. Produce and/or contribute to management dashboard, focusing on remediation action when needed. Review and Challenge the Business Continuity Management (BCM) program (BCP, testing…).
Third-Party risk oversight
Assess independently the adherence to industry and regulatory standards e.g. interagency guidance Review the proper tiering of TPs, due diligence standards, monitoring of risk acceptances… Independently challenge criticality and materiality designations, with particular focus on material outsourcing and intragroup service arrangements
Required Qualifications
15+ years in a technical role along with exposure to / experience in technology risk management, information security, or IT audit. Bachelor's degree in computer science, engineering, or information systems; CISSP, CISA, CISM, CRISC, or CCSP preferred. Hands-on technical experience in engaging 1LoD experts on technical issues. Experience in proactively sustaining independent check and challenges with first line. Understanding of Industry standards and regulatory expectations, with experience implementing or auditing IT and IS risk compliant framework.
Nomura Leadership Behaviors
Explore Insights & Vision: Identify the underlying causes of problems faced by you or your team and define a clear vision and direction for the future. Making Strategic Decisions : Evaluate all the options for resolving the problems and effectively prioritize actions or recommendations. Inspire Entrepreneurship in People : Inspire team members through