The Operational Risk Management (ORM) 2LoD function is part of the Risk Management organization and is responsible for developing operational risk frameworks and policies, providing independent oversight over operational risks and challenging First Line of Defense, monitoring risk appetite compliance, and reporting to senior management and committees. In this role, you will be the second line of defense risk manager overseeing Nomura Information Technology and Information Security (IT & IS), Business Resilience as well as Third Party risks (TPRM). You will focus on checking and challenging the ICT risk profile of the Americas operations as well as participating in risk management programs for Nomura globally. You will provide independent risk opinions on compliance with relevant regulatory and industry expectations (NIST, FFIEC…), review the risk profile across IT change management, identity and privileged access (IAM/PAM), resilience, vulnerability and patch management, data leakage prevention, etc., review and challenge the 1LoD controls rollout and results, and produce and/or contribute to management dashboard, focusing on remediation action when needed. You will also review and challenge the Business Continuity Management (BCM) program (BCP, testing…). Additionally, you will provide third-party risk oversight, assess independently the adherence to industry and regulatory standards e.g. interagency guidance, review the proper tiering of TPs, due diligence standards, monitoring of risk acceptances… and independently challenge criticality and materiality designations, with particular focus on material outsourcing and intragroup service arrangements.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Executive