Risk Manager IT, Information Security, Business Resilience and Third Party Risk Management

Nomura Holdings, inc.New York, NY
$220,000 - $270,000Onsite

About The Position

The Operational Risk Management (ORM) 2LoD function is part of the Risk Management organization and is responsible for developing operational risk frameworks and policies, providing independent oversight over operational risks and challenging First Line of Defense, monitoring risk appetite compliance, and reporting to senior management and committees. In this role, you will be the second line of defense risk manager overseeing Nomura Information Technology and Information Security (IT & IS), Business Resilience as well as Third Party risks (TPRM). You will focus on checking and challenging the ICT risk profile of the Americas operations as well as participating in risk management programs for Nomura globally. You will provide independent risk opinions on compliance with relevant regulatory and industry expectations (NIST, FFIEC…), review the risk profile across IT change management, identity and privileged access (IAM/PAM), resilience, vulnerability and patch management, data leakage prevention, etc., review and challenge the 1LoD controls rollout and results, and produce and/or contribute to management dashboard, focusing on remediation action when needed. You will also review and challenge the Business Continuity Management (BCM) program (BCP, testing…). Additionally, you will provide third-party risk oversight, assess independently the adherence to industry and regulatory standards e.g. interagency guidance, review the proper tiering of TPs, due diligence standards, monitoring of risk acceptances… and independently challenge criticality and materiality designations, with particular focus on material outsourcing and intragroup service arrangements.

Requirements

  • 15+ years in a technical role along with exposure to / experience in technology risk management, information security, or IT audit.
  • Bachelor's degree in computer science, engineering, or information systems; CISSP, CISA, CISM, CRISC, or CCSP preferred.
  • Hands-on technical experience in engaging 1LoD experts on technical issues.
  • Experience in proactively sustaining independent check and challenges with first line.
  • Understanding of Industry standards and regulatory expectations, with experience implementing or auditing IT and IS risk compliant framework.

Nice To Haves

  • CISSP, CISA, CISM, CRISC, or CCSP preferred.

Responsibilities

  • Check and Challenge the ICT risk profile of the Americas operations as well as participate in risk management programs for Nomura globally
  • Provide independent risk opinions on compliance with relevant regulatory and industry expectations (NIST, FFIEC…)
  • Review the risk profile across IT change management, identity and privileged access (IAM/PAM), resilience, vulnerability and patch management, data leakage prevention, etc.
  • Review and challenge the 1LoD controls rollout and results.
  • Produce and/or contribute to management dashboard, focusing on remediation action when needed.
  • Review and Challenge the Business Continuity Management (BCM) program (BCP, testing…).
  • Assess independently the adherence to industry and regulatory standards e.g. interagency guidance
  • Review the proper tiering of TPs, due diligence standards, monitoring of risk acceptances…
  • Independently challenge criticality and materiality designations, with particular focus on material outsourcing and intragroup service arrangements

Benefits

  • sign-on bonus
  • restricted stock units
  • discretionary awards
  • full range of medical, financial, and/or other benefits
  • 401(k) eligibility
  • various paid time off benefits, such as vacation, sick time, and parental leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service