職務内容 Job Description | Company overview: Nomura is a global financial services group with an integrated global network spanning over 30 countries. Japan IT (Information Technology) is a diverse environment with employees of over 25 nationalities, who work on technical support, application development and implementation of system changes for Japan Retail Wealth Management Business and Global Wholesale (Global Markets and Investment Banking). Nomura provides competitive employee benefits, training and upskilling opportunities, and is committed to promoting diversity, equity and inclusion, employee health and well-being. Founded in 1925, the firm is built on a tradition of disciplined entrepreneurship, serving clients with creative solutions and considered thought leadership. 野村は、世界30カ国以上に広がる統合されたグローバルネットワークを持つグローバル金融サービスグループです。日本のIT (情報技術) は、25カ国以上の国籍の従業員がおり、日本のリテール・ウェルス・マネジメント事業とグローバル・ホールセール (グローバル・マーケッツ・インベストメント・バンキング) の技術サポート、アプリケーション開発、システム変更の実装に取り組んでいます。野村は、競争力のある従業員福利厚生、トレーニング、スキルアップの機会を提供し、多様性、公平性、インクルージョン、従業員の健康と福祉の促進に取り組んでいます。1925年に設立された野村は、規律ある起業家精神の伝統に基づいて構築されており、創造的なソリューションと思慮深いリーダーシップでクライアントにサービスを提供しています。 | | | Role Overview: This dual-function role combines regional CISO responsibilities for Japan with leadership of Security Architecture & Engineering (SAE). Reporting directly to the Group CISO, you will be a senior member of the Global Information Security Leadership Team and oversee all CISO team members based at Nomura’s Japan Headquarters. Most team members have dual reporting lines. This means that they support the Japan regional organization and report to the Regional CISO, while also contributing to global functions and reporting to the relevant Global Heads. This hands-on role is responsible for developing and implementing the global SAE strategy in Japan while ensuring that Japan-specific requirements are addressed. It also oversees regional security operations, including security Governance, Risks and Controls (GRC), regulatory compliance, data protection, and security project management. A core responsibility is to ensure that all global strategic programs - not only those related to SAE - are aligned with and support the broader global strategies. | | | | Key Responsibilities: | | Japan Security Architecture & Engineering (SAE) Leadership | - Develop and maintain comprehensive information security architecture framework aligned with business objectives and the Information Security Risk and Control Framework
- Create and maintain reference architecture for security, ensuring full alignment with enterprise reference architecture developed by the Global Head of Security Architecture to meet the needs of the CTO organization and the business line CIOs (Wholesale, Wealth Management, Nomura Assets Management, and Nomura Trust Banking)
- Ensure that the implementation of global security policies, standards, best practices, and technical implementation guides are in place and operating effectively
- Lead design and implementation of secure network architecture, AI & cloud security solutions, and endpoint protection, data protection mechanisms including security tooling management
- Support the establishment a Security Engineering Hub in our Mumbai-based delivery center to provide 24x7 engineering support of our Japan and global security platforms
- Collaborate with cross-functional teams to evaluate and select security technologies including AI/ML, SaaS, security automation, and R&D initiatives
- Provide technical guidance and expertise on security infrastructure design, configuration, and deployment across all regions
- Ensure that the implementation of global security controls and measures to protect against cyber threats, malware, and unauthorized access are in place and operating effectively
- Lead security architecture reviews and assessments to identify gaps, vulnerabilities, and areas for resilience improvement; provide recommendations on risk mitigation in collaboration with the Global Heads and other regional CISOs to ensure consistency in control implementation
- Ensure that Security by Design practices are in place in collaboration with the global AppSec team (located in our New York office); support the development of a DevSecOps program for Nomura in Japan
- Establish and manage security lab and sandbox for evaluating security solutions and testing emerging technologies in collaboration with the global Security R&D / Innovation team located in our New York office
- Identify and assess emerging cyber technologies and startups that could support revenue generation for our Investment Banking and Digital Company stakeholders
- Stay current on emerging technologies, trends, and threats in information security architecture and engineering
- Establish a resourcing plan in Japan to build strong security architecture and engineering capabilities
- Ensure SAE resourcing coverage aligns with key regions to support regional business, IT, and business development needs
| | Japan Regional CISO Responsibilities | - Strategic Leadership: Implement comprehensive information security and risk management program for Japan according to group strategy and roadmap, including budget planning for security activities
- Partnership Collaboration: Liaise with Japanese business units (Internal Audit, Law, Finance, Safety & Security, Risk Management, HR) and external agencies to maintain strong security posture
- Regional and Global Management: Collaborate with Global Heads of Information Security to ensure consistency and standardization of global practices across Japan, while accounting for regional differences; in addition, support the Group CISO in ensuring domestic lines of business receive timely regulatory security updates through metrics, committees/forums, project support, and related channel
- Regional and Global Management: Collaborate with the Global Heads of Information Security to ensure consistency and standardization of global practices across Japan while taking into account regional differences.
- Advisory Role: Provide leadership and guidance on information security topics, business continuity, and disaster recovery plans specific to Japan operations
- Risk Management: Identify, assess, and mitigate information security risks across Japan region through regular risk assessments and audits
- Policy Support: Enforce security policies, standards, and procedures ensuring compliance with Japanese regulatory requirements and best practices
- Security Governance: Lead governance, risk and control activities for Nomura Japan implementing business-centric risk management and managing third-party stakeholder risks
- Compliance: Ensure compliance with regional and international regulations, including Japanese data protection laws and industry standards
- Security Awareness: Support culturally appropriate security awareness programs and lead key security awareness events in Japan
- Incident Response: Lead and represent regional management in response to significant information security breaches and events, serving as point of contact for all regional cyber events
- Cyber Threat Management: Monitor external threat environment for emerging threats and advise stakeholders on appropriate courses of action
- Cyber Simulation Tests: Run various security exercises including cyber simulations with appropriate understanding of regulatory risks
- Team Management: Recruit, train, and manage security professionals in Japan region capable of adequately protecting the company
- Japan Support: As the Group CISO is based at the Japan headquarters, the Japan Head of Security Engagement will support you with communications, reporting, and overall engagement with Japan-based entities
| | Leadership & People Management | - Adhere to and promote company values and ethical framework across global and regional teams
- Lead environment where people management and development is top priority, empowering and mentoring direct reports
- Drive achievement of high performance through effective career management, succession planning, and talent management
- Act as role model communicating SMART business-driven objectives and ensuring continuous performance reviews
- Proactively manage people decisions aligning performance with organizational needs
- Provide regional perspective on talent, skills, development, promotion, and compensation
- Contribute to year-end compensation process, hiring, retention, promotion, and disciplinary actions
| |
登録資格 Requirements | | Required Qualifications: | | Education & Certifications | - Bachelor's degree in Computer Science, Information Technology, or related field; Master's degree or equivalent preferred
- CISSP or CISM certification required or equivalent cybersecurity certifications
| | Experience | - Minimum 15+ years of leadership experience in large, complex, global organizations
- Minimum 10 years in information security with focus on security architecture and engineering
- Demonstrated executive experience leading relevant business of similar size and complexity across multiple locations
- Experience with matrix organization leadership and non-staff resource allocation
- Broad experience across business and infrastructure disciplines including regulatory interaction, audit facilitation, and technology service delivery
| | Technical & Strategic Skills | - Strong knowledge of security technologies, protocols, and frameworks (ISO 27001, NIST, OWASP)
- Experience designing and implementing security controls for cloud environments, network infrastructure, and software applications
- Strategic and operational understanding of risk frameworks and regional security best practices
- Information security experience with global and regional trends for managing security in complex organizations
| | Core Competencies | - Excellent analytical, problem-solving, and project management skills
- Strong communication and interpersonal skills for diverse stakeholder collaboration
- Ability to translate complex technical security concepts into business risks and business cases
- Ability to communicate with knowledge and credibility to all management levels including management committees
- Demonstrated ability to develop strong relationships with regional external oversight and regulators
- Japanese and English proficiency critical for global collaboration and regional regulatory interaction
- Ability to reach out to the cybersecurity community in Japan through either formal security associations (e.g., FS-ISAC) or informal roundtables, peer sessions, etc.
| | Right to work in Japan | - Ability to collaborate with internal and external stakeholders ensuring alignment with industry standards and regulatory requirements
- Experience managing complex change agendas and driving strategy formulation and service delivery
| |