Associate, Principal IT Risk & Control (IWM)

NOMURA
NOMURA

IT

Singapore

Posted on Jul 22, 2026

Job Title: Principal IT Risk & Control (IWM)

Corporate Title: Associate

Division: AEJ Technology

Location: Singapore

SFID: 14373

Licensed Role: No

Nomura Overview

Nomura is a financial services group with an integrated global network. By connecting markets East & West, we service the needs of individuals, institutions, corporates and governments through our four business divisions: Wealth Management, Investment Management, Wholesale (Global Markets and Investment Banking) and Banking.

Driven by the insights of some 28,000 people worldwide, we put our clients at the center of everything we do, delivering unparalleled access to, from and within Asia. For further information about Nomura, visit www.nomura.com

Department Overview

Nomura's IT department provides technology solutions to support the company's business activities. The team works closely with senior leadership, business units, and stakeholders to develop and implement effective IT strategies, providing guidance on technology selection and implementation while ensuring system reliability, security, and scalability. Nomura's IT team specializes in software development, infrastructure management, cybersecurity, and data analytics and is known for providing exceptional service to clients. With a strong track record and commitment to innovation and global reach, Nomura's IT department is well-positioned to continue driving growth and success in the financial industry.

Role Description

Reporting to Senior Principal Business Analyst, the Principal IT Risk & Control Officer will be required to support the continued growth of its International Wealth Management (IWM) business in Asia, overseeing IT audit readiness and conducting reviews of all internal IT controls, frameworks, policies, and standards.

The role will serve as the central coordination point between technology teams and internal/external stakeholders on IT risk, controls, and compliance matters. While the primary focus will be on IWM, the scope may expand to other business lines in the future.

Responsibilities

  • Overseeing IT audit readiness and conducting reviews of all internal IT controls, frameworks, policies, and standards.
  • Managing engagement with external reviewers, including Financial Auditors, SOX assessors, and regulatory bodies (MAS, SFC, JFSA).
  • Interpreting regulatory requirements — in particular the MAS Technology Risk Management (TRM) Guidelines, HKMA/SFC requirements, and JFSA standards — and translating them into operational actions, processes, and sustainable controls within the technology environment.

IT Controls & Governance

  • Review and ensure that IT controls and processes adhere to the standards and procedures established by the bank.
  • Facilitate gap analyses for applications and systems that do not comply with internal standards, and drive remediation actions through to closure.
  • Track process improvements and maintain a register of control enhancements, providing regular status updates to senior management.
  • Document solutions, control decisions, and risk acceptances in a clear and auditable manner.

Project Assurance

  • Perform internal due diligence checks across all technology projects based on the SDLC lifecycle, ensuring adherence to required procedures and successful completion of quality gates.
  • Challenge and advise project teams on control requirements at each stage of delivery.

Audit & Regulatory Engagement

  • Act as the single point of contact for all IT-related audit and regulatory engagements, coordinating deliverables between internal application managers, infrastructure teams, and auditors.
  • Liaise with Internal Audit, External Audit, and regulatory inspection teams, ensuring timely and accurate responses to information requests.
  • Support the preparation and execution of SOX, MAS, SFC, and JFSA audits and inspections.

Reporting & Stakeholder Management

  • Produce regular senior management reporting covering the IT risk and control landscape, including open issues, remediation progress, and areas for improvement.
  • Engage proactively with business and technology stakeholders to promote a strong control culture and awareness of regulatory expectations.

Requirements

  • Degree in Computer Science, Computer Engineering, Information Systems, or related discipline.
  • Minimum 6 years’ experience of experience in information technology risk, IT security, IT audit, or IT controls within a financial services environment
  • Minimum 4 years’ experience in conducting or supporting IT audits and reviewing controls, frameworks, policies, and standards.
  • Strong understanding of regulatory frameworks applicable to technology in banking (e.g., MAS TRM, HKMA/SFC, JFSA).
  • Excellent communication, presentation, and advisory skills, with the ability to articulate complex technical matters to non-technical stakeholders.
  • Ability to work independently, manage competing priorities, and deliver under pressure in a fast-paced environment.
  • Proactive, self-motivated, and detail-oriented with strong organisational skills.
  • ITIL Foundation certification or above.
  • Professional certification in one or more of: CISSP, CISM, CISA, or CRISC.
  • Knowledge of the Technology Information Security Officer (TISO) function and responsibilities.
  • Experience with SOX IT General Controls (ITGCs) testing and remediation.
  • Familiarity with Agile and Waterfall SDLC methodologies in a regulated environment.

Nomura Competencies

  • Explore Insights & Vision: Identify the underlying causes of problems faced by you or your team and define a clear vision and direction for the future.
  • Making Strategic Decisions: Evaluate all the options for resolving the problems and effectively prioritize actions or recommendations.
  • Inspire Entrepreneurship in People: Inspire team members through effective communication of ideas and motivate them to actively enhance productivity.
  • Elevate Organizational Capability: Engage proactively in professional development and enhance team productivity through the promotion of knowledge sharing.
  • Inclusion: Respect DEI, foster a culture of psychological safety in the workplace and cultivate a "Risk Culture" (Challenge, Escalate and Respect).

Diversity Statement

Nomura is committed to an employment policy of equal opportunities, and is fundamentally opposed to any less favourable treatment accorded to existing or potential members of staff on the grounds of race, creed, colour, nationality, disability, marital status, pregnancy, gender or sexual orientation.

DISCLAIMER: This Job Description is for reference only, and whilst this is intended to be an accurate reflection of the current job, it is not necessarily an exhaustive list of all responsibilities, duties, skills, efforts, requirements or working conditions associated with the job. The management reserves the right to revise the job and may, at his or her discretion, assign or reassign duties and responsibilities to this job at any time.

Nomura is an Equal Opportunity Employer