ジョブNo.894090 Japan CISO and Japan Head of Security Architecture & Engineering (SAE)

  • 正社員

野村證券株式会社

Company overview:
Nomura is a global financial services group with an integrated global network spanning over 30 countries. Japan IT (Information Technology) is a diverse environment with employees of over 25 nationalities, who work on technical support, application development and implementation of system changes for Japan Retail Wealth Management Business and Global Wholesale (Global Markets and Investment Banking). Nomura provides competitive employee benefits, training and upskilling opportunities, and is committed to promoting diversity, equity and inclusion, employee health and well-being. Founded in 1925, the firm is built on a tradition of disciplined entrepreneurship, serving clients with creative solutions and considered thought leadership.
野村は、世界30カ国以上に広がる統合されたグローバルネットワークを持つグローバル金融サービスグループです。日本のIT (情報技術) は、25カ国以上の国籍の従業員がおり、日本のリテール・ウェルス・マネジメント事業とグローバル・ホールセール (グローバル・マーケッツ・インベストメント・バンキング) の技術サポート、アプリケーション開発、システム変更の実装に取り組んでいます。野村は、競争力のある従業員福利厚生、トレーニング、スキルアップの機会を提供し、多様性、公平性、インクルージョン、従業員の健康と福祉の促進に取り組んでいます。1925年に設立された野村は、規律ある起業家精神の伝統に基づいて構築されており、創造的なソリューションと思慮深いリーダーシップでクライアントにサービスを提供しています。

Role Overview:
This dual-function role combines regional CISO responsibilities for Japan with leadership of Security Architecture & Engineering (SAE). Reporting directly to the Group CISO, you will be a senior member of the Global Information Security Leadership Team and oversee all CISO team members based at Nomura’s Japan Headquarters. Most team members have dual reporting lines. This means that they support the Japan regional organization and report to the Regional CISO, while also contributing to global functions and reporting to the relevant Global Heads.

This hands-on role is responsible for developing and implementing the global SAE strategy in Japan while ensuring that Japan-specific requirements are addressed. It also oversees regional security operations, including security Governance, Risks and Controls (GRC), regulatory compliance, data protection, and security project management. A core responsibility is to ensure that all global strategic programs - not only those related to SAE - are aligned with and support the broader global strategies.

Key Responsibilities:
Japan Security Architecture & Engineering (SAE) Leadership
Develop and maintain comprehensive information security architecture framework aligned with business objectives and the Information Security Risk and Control Framework
Create and maintain reference architecture for security, ensuring full alignment with enterprise reference architecture developed by the Global Head of Security Architecture to meet the needs of the CTO organization and the business line CIOs (Wholesale, Wealth Management, Nomura Assets Management, and Nomura Trust Banking)
Ensure that the implementation of global security policies, standards, best practices, and technical implementation guides are in place and operating effectively
Lead design and implementation of secure network architecture, AI & cloud security solutions, and endpoint protection, data protection mechanisms including security tooling management
Support the establishment a Security Engineering Hub in our Mumbai-based delivery center to provide 24x7 engineering support of our Japan and global security platforms
Collaborate with cross-functional teams to evaluate and select security technologies including AI/ML, SaaS, security automation, and R&D initiatives
Provide technical guidance and expertise on security infrastructure design, configuration, and deployment across all regions
Ensure that the implementation of global security controls and measures to protect against cyber threats, malware, and unauthorized access are in place and operating effectively
Lead security architecture reviews and assessments to identify gaps, vulnerabilities, and areas for resilience improvement; provide recommendations on risk mitigation in collaboration with the Global Heads and other regional CISOs to ensure consistency in control implementation
Ensure that Security by Design practices are in place in collaboration with the global AppSec team (located in our New York office); support the development of a DevSecOps program for Nomura in Japan
Establish and manage security lab and sandbox for evaluating security solutions and testing emerging technologies in collaboration with the global Security R&D / Innovation team located in our New York office
Identify and assess emerging cyber technologies and startups that could support revenue generation for our Investment Banking and Digital Company stakeholders
Stay current on emerging technologies, trends, and threats in information security architecture and engineering
Establish a resourcing plan in Japan to build strong security architecture and engineering capabilities
Ensure SAE resourcing coverage aligns with key regions to support regional business, IT, and business development needs
Japan Regional CISO Responsibilities
Strategic Leadership: Implement comprehensive information security and risk management program for Japan according to group strategy and roadmap, including budget planning for security activities
Partnership Collaboration: Liaise with Japanese business units (Internal Audit, Law, Finance, Safety & Security, Risk Management, HR) and external agencies to maintain strong security posture
Regional and Global Management: Collaborate with Global Heads of Information Security to ensure consistency and standardization of global practices across Japan, while accounting for regional differences; in addition, support the Group CISO in ensuring domestic lines of business receive timely regulatory security updates through metrics, committees/forums, project support, and related channel
Regional and Global Management: Collaborate with the Global Heads of Information Security to ensure consistency and standardization of global practices across Japan while taking into account regional differences.
Advisory Role: Provide leadership and guidance on information security topics, business continuity, and disaster recovery plans specific to Japan operations
Risk Management: Identify, assess, and mitigate information security risks across Japan region through regular risk assessments and audits
Policy Support: Enforce security policies, standards, and procedures ensuring compliance with Japanese regulatory requirements and best practices
Security Governance: Lead governance, risk and control activities for Nomura Japan implementing business-centric risk management and managing third-party stakeholder risks
Compliance: Ensure compliance with regional and international regulations, including Japanese data protection laws and industry standards
Security Awareness: Support culturally appropriate security awareness programs and lead key security awareness events in Japan
Incident Response: Lead and represent regional management in response to significant information security breaches and events, serving as point of contact for all regional cyber events
Cyber Threat Management: Monitor external threat environment for emerging threats and advise stakeholders on appropriate courses of action
Cyber Simulation Tests: Run various security exercises including cyber simulations with appropriate understanding of regulatory risks
Team Management: Recruit, train, and manage security professionals in Japan region capable of adequately protecting the company
Japan Support: As the Group CISO is based at the Japan headquarters, the Japan Head of Security Engagement will support you with communications, reporting, and overall engagement with Japan-based entities
Leadership & People Management
Adhere to and promote company values and ethical framework across global and regional teams
Lead environment where people management and development is top priority, empowering and mentoring direct reports
Drive achievement of high performance through effective career management, succession planning, and talent management
Act as role model communicating SMART business-driven objectives and ensuring continuous performance reviews
Proactively manage people decisions aligning performance with organizational needs
Provide regional perspective on talent, skills, development, promotion, and compensation
Contribute to year-end compensation process, hiring, retention, promotion, and disciplinary actions

野村証券の7つの強み
①お客様からの信頼、国内トップクラスの顧客基盤
②深い分析力と先見性を強みとしたリサーチ力
③本格的なグローバル事業基盤
④事業パートナーとのシナジー
⑤強固な財務基盤
⑥多様性を備えた優秀で厚みのある人材
⑦サステナビリティ関連におけるプレゼンス

コンサルタント 鈴木 陣

募集要項

職種 IT系/PM/PL(Web系・オープン系・パッケージ開発)
年収 2000万円~3000万円
勤務地 東京都
応募資格 学歴・資格
コンピュータサイエンス、情報技術、または関連分野の学士号。修士号または同等の資格を有することが望ましい。
CISSPまたはCISMの資格、あるいは同等のサイバーセキュリティ関連資格が必須。
経験
大規模かつ複雑なグローバル組織における15年以上のリーダーシップ経験
セキュリティアーキテクチャおよびエンジニアリングに重点を置いた、情報セキュリティ分野での10年以上の実務経験
同程度の規模および複雑さを有する関連事業を、複数の拠点にまたがって統率した実績のある経営幹部としての経験
マトリックス組織におけるリーダーシップおよび非専任リソースの配分に関する経験
規制当局との連携、監査の支援、技術サービスの提供など、ビジネスおよびインフラ分野にわたる幅広い経験
技術的・戦略的スキル
セキュリティ技術、プロトコル、およびフレームワーク(ISO 27001、NIST、OWASP)に関する深い知識
クラウド環境、ネットワークインフラ、ソフトウェアアプリケーション向けのセキュリティ対策の設計および実装経験
リスクフレームワークおよび地域ごとのセキュリティベストプラクティスに関する戦略的・運用的な理解
複雑な組織におけるセキュリティ管理に関する、グローバルおよび地域の動向を踏まえた情報セキュリティの実務経験
中核となる能力
優れた分析力、問題解決能力、およびプロジェクト管理能力
多様なステークホルダーとの協業に必要な、優れたコミュニケーション能力および対人スキル
複雑な技術的なセキュリティ概念を、ビジネスリスクやビジネスケースに置き換える能力
経営委員会を含むあらゆる管理レベルに対し、知識と信頼性をもってコミュニケーションを図る能力
地域の外部監督機関や規制当局と強固な関係を構築した実績
グローバルな連携および地域規制当局とのやり取りに不可欠な日本語・英語の堪能さ
公式のセキュリティ協会(例:FS-ISAC)や非公式な円卓会議、ピアセッションなどを通じて、日本のサイバーセキュリティコミュニティと連携できる能力
日本での就労資格
業界標準および規制要件との整合性を確保しつつ、社内外のステークホルダーと連携できる能力
複雑な変革課題の管理、および戦略策定とサービス提供の推進に関する経験
学歴 学歴不問
雇用形態 正社員(期間の定めなし)
勤務時間 08:40-17:10
実働:7.5時間
休日・休暇土、日、祝日
年間休日 125日
年末年始休暇
待遇・福利厚生確定拠出年金(401K)、社宅、従業員持株制度、財形貯蓄
健康保険、厚生年金、労災、雇用保険
通勤交通費(全額)
受動喫煙防止措置屋内原則禁煙(喫煙施設有)

企業情報

企業名野村證券株式会社
業種・資本 金融・保険系(証券・投資銀行)
ヘッドオフィス:国内
事業内容資本市場を通じて、個人投資家及び様々な企業への資産運用・資金調達などのサービスの提供。個人投資家へのライフ・スタイル、リスク許容度、投資資金性格をくみ取り、ニーズにあった商品、ポートフォリオを提案し、長期にわたって資産形成の為のサービス提供。また、オンラインサービスや野村コールセンターなどのサービスを通じ、当社の様々なサービスをより簡便に利用出来る様、IT技術の積極活用を行っている。一方、当社の有する高度なリサーチ能力や問題解決能力を活用し、機関投資家へ対する資産運用の為の様々なサービス、また企業に対しての、引受業務を通じた資金調達やM&A業務を通じた企業価値向上の為のサポートを行っています。

Japan CISO and Japan Head of Security Architecture & Engineering (SAE)

  • IT系/PM/PL(Web系・オープン系・パッケージ開発)
  • 2000万円~3000万円
  • 東京都
​