Nomura · 12 hours ago
Information Security - Security Risk & Control Lead
Nomura is a global financial services group with an integrated network spanning approximately 30 countries and regions. They are seeking an experienced Information Security Associate to join their Cyber Risk Governance team, focusing on regulatory compliance and vendor risk management.
Responsibilities
Maintain comprehensive knowledge of existing and emerging US cyber regulations
Conduct thorough risk assessments on current and proposed cyber regulatory requirements
Demonstrate proficiency with established cybersecurity frameworks (NIST, ISO 27001, SOC 2, etc.)
Stay current with evolving regulatory landscape and assess impact on organizational compliance
Lead and support regulatory compliance initiatives including SEC cybersecurity regulations, NYDFS Cybersecurity Regulation (23 NYCRR 500), and other applicable regulatory requirements
Develop, implement, and maintain cybersecurity frameworks and map them to internal control structures
Respond to Due Diligence Questionnaires (DDQs) from clients, vendors, and business partners
Manage responses to regulatory inquiries and examinations from various oversight bodies
Conduct risk assessments and gap analyses to ensure ongoing compliance
Collaborate with cross-functional teams to implement control enhancements and remediation activities
Monitor regulatory developments and assess impact on organizational compliance posture
Prepare compliance reports and presentations for senior management and board committees
Support audit activities and coordinate with internal and external auditors
Serve as primary point of contact for vendor risk assessment activities across the US region
Apply expertise in various vendor risk assessment frameworks and methodologies
Collaborate effectively with regional and global business stakeholders to facilitate vendor onboarding processes
Identify, analyze, and communicate risks associated with third-party vendor relationships
Ensure vendor compliance with firm's security standards and regulatory
Qualification
Required
Deep understanding of cybersecurity frameworks and best practices
Proven experience with vendor risk assessment methodologies
Strong knowledge of US cyber regulatory environment
Comprehensive understanding of risk management principles and practices
Minimum 4+ years of relevant information security experience
Excellent written and verbal communication abilities
Strong stakeholder management and relationship-building skills
Ability to translate complex technical risks into business-friendly language
Collaborative approach to working with cross-functional teams
Detail-oriented with strong analytical and problem-solving capabilities
Preferred
Relevant cybersecurity certifications (CISSP, CISA, CRISC, etc.)
Experience in financial services or highly regulated industries
Background in regulatory compliance and audit processes
Project management experience
Benefits
Sign-on bonus
Restricted stock units
Discretionary awards
Eligibility for commissions for applicable sales roles
A full range of medical, financial, and/or other benefits
401(k) eligibility
Various paid time off benefits, such as vacation, sick time, and parental leave
Company
Nomura
Nomura is an investment banking and securities firm that serve the needs of individuals, institutions, corporate and governments. It is a sub-organization of Nomura Capital Management.
H1B Sponsorship
Nomura has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2025 (1)
2023 (1)
2022 (1)
2020 (2)
Funding
Current Stage
Public CompanyTotal Funding
unknown2001-12-17IPO
Leadership Team
Recent News
Renewable Energy Magazine
2026-02-12
2026-02-07
2026-02-04
Company data provided by crunchbase