■ Company Overview
Nomura is a global financial services group with an integrated global network spanning over 30 countries. Japan IT (Information Technology) is a diverse environment with employees of over 25 nationalities, who work on technical support, application development and implementation of system changes for Japan Retail Wealth Management Business and Global Wholesale (Global Markets and Investment Banking). Nomura provides competitive employee benefits, training and upskilling opportunities, and is committed to promoting diversity, equity and inclusion, employee health and well-being. Founded in 1925, the firm is built on a tradition of disciplined entrepreneurship, serving clients with creative solutions and considered thought leadership.
野村は、世界30カ国以上に広がる統合されたグローバルネットワークを持つグローバル金融サービスグループです。日本のIT (情報技術) は、25カ国以上の国籍の従業員がおり、日本のリテール・ウェルス・マネジメント事業とグローバル・ホールセール (グローバル・マーケッツ・インベストメント・バンキング) の技術サポート、アプリケーション開発、システム変更の実装に取り組んでいます。野村は、競争力のある従業員福利厚生、トレーニング、スキルアップの機会を提供し、多様性、公平性、インクルージョン、従業員の健康と福祉の促進に取り組んでいます。1925年に設立された野村は、規律ある起業家精神の伝統に基づいて構築されており、創造的なソリューションと思慮深いリーダーシップでクライアントにサービスを提供しています。
-
Reporting directly to the Group CISO, you will work closely with the Japan CISO, Regional CISOs, global security capability leaders, Japan CIO organization, Japan business leadership, and relevant risk, compliance, legal, audit, and regulatory teams.
- The Japan Head of Security Engagement serves as the principal bridge between the Group CISO organization and Nomura’s Japan businesses, legal entities, technology organizations, and senior management.
- The role is responsible for ensuring that the priorities, requirements, concerns, and operating realities of Japan stakeholders are understood by the global CISO organization. Equally, the role ensures that the Group CISO’s strategy, risk position, security requirements, services, investments, and decisions are communicated clearly and appropriately within Japan.
- The position requires a genuinely bilingual and bicultural leader who can operate effectively across Japanese and international management environments. The individual must be able to translate more than language. They must translate business context, management expectations, cyber risk, regulatory requirements, technical issues, and organizational sensitivities into clear decisions and practical actions.
- The role will initially place particular emphasis on strengthening engagement with Wealth Management, Nomura Asset Management, Nomura Trust and Banking, and other Japan entities that are not yet fully integrated with the global CISO operating model.
- In addition, the individual will serve as the Group CISO’s Japan-based Chief of Staff and communications lead, supporting the preparation of executive discussions, coordinating priorities, maintaining decision discipline, and ensuring consistent messaging across Japan in collaboration with global heads.
Key Responsibilities:
Japan business relationship management
・Establish structured and trusted relationships with Wealth Management, Nomura Asset Management, Nomura Trust and Banking, and other Japan businesses and entities.
・Develop a clear understanding of each business’s strategy, technology environment, cyber risk profile, regulatory obligations, transformation agenda, and current relationship with the global CISO organization.
・Serve as the primary coordination point when Japan stakeholders need to engage multiple global CISO capabilities.
・Help businesses understand which CISO services they receive, the value of those services, the responsibilities retained by the business or technology organization, and the associated funding and delivery expectations.
・Identify misunderstandings, duplication, ownership gaps, and conflicting expectations before they become delivery or management issues.
・Ensure that Japan concerns are brought into global planning and decision-making early enough to influence the outcome.
Translation between Japan and the global CISO organization
・Translate complex cyber, risk, regulatory, and technical matters into clear business language for Japan executives.
・Translate Japan business requirements and operating realities into actionable direction for global CISO teams.
・Ensure that communications are culturally appropriate without changing the underlying risk position, security requirement, or management accountability.
・Identify where apparent disagreement results from language, context, decision-making processes, or differing interpretations of responsibilities.
・Help global capability leaders prepare effectively for engagement with Japan stakeholders.
・Maintain consistency between Japanese and English materials, decisions, commitments, and management messages.
Strategic communications
・Lead the development and coordination of Group CISO communications for Japan stakeholders.
・Prepare executive briefing materials, management updates, speaking points, decision papers, meeting summaries, and stakeholder communications in Japanese and English.
・Adapt global CISO strategy, risk, controls, and transformation materials for Japan audiences without weakening or changing the core message.
・Create a consistent narrative explaining the role of the CISO organization, the services it provides, the risks it manages, and the value it delivers to Japan businesses.
・Coordinate the communication and socialization of significant CISO initiatives before formal management decisions are required.
・Help ensure that executive communications focus on business exposure, resilience, regulatory obligations, decisions, and outcomes rather than unnecessary technical detail.
Chief of staff to the Group CISO
・Represent the Group CISO in designated Japan management, business, governance, and transformation forums.
・Act as the Group CISO’s principal Japan-based delegate for stakeholder engagement, issue coordination, and executive follow-through.
・Provide the Group CISO with an accurate and unfiltered view of Japan business concerns, organizational dynamics, emerging risks, and decisions requiring escalation.
・Ensure that positions communicated on behalf of the Group CISO accurately reflect agreed strategy, risk priorities, and decision authority.
・Support the Group CISO in building trusted relationships with Japan executives and other senior stakeholders.
・Coordinate closely with the Japan CISO while maintaining the distinct mandate of each role.
・Coordinate the Group CISO’s Japan priorities, stakeholder engagements, executive meetings, and follow-up actions.
・Prepare the Group CISO for meetings with Japan executives by providing stakeholder context, likely areas of concern, relevant history, and recommended positions.
・Maintain an integrated view of key Japan issues, decisions, commitments, dependencies, and escalations.
・Ensure that actions agreed with the Group CISO are assigned, tracked, and completed.
・Connect related issues across businesses, entities, CISO capabilities, technology teams, and transformation programs.
・Challenge unclear ownership, unresolved dependencies, and commitments that are not supported by an executable plan.
・Support the Group CISO Leadership Team by ensuring that Japan priorities are visible and incorporated into global discussions.
Cyber program coordination and delivery
・Coordinate cross-functional cyber initiatives affecting Japan businesses and entities.
・Translate executive decisions into structured plans with accountable owners, milestones, dependencies, and target dates.
・Track progress across global CISO capabilities and Japan stakeholder organizations.
・Identify delivery risks, resource constraints, competing priorities, and decisions that require senior management intervention.
・Facilitate resolution where responsibilities span CISO, the Japan CIO organization, business technology teams, external service providers, and global capability owners.
・Support the integration of Japan entities into global security capabilities, standards, reporting, and governance where agreed.
・Ensure that local implementation requirements remain aligned with the global CISO Controls & Risks Framework and enterprise cyber strategy.
Cyber governance, risk, and regulatory alignment
・Support Japan businesses in understanding global security policies, Essential Cyber Controls, risk assessment requirements, and evidence expectations.
・Help connect Japan regulatory requirements with the global CISO strategy and Controls & Risks Framework.
・Coordinate with cyber GRC, legal, compliance, risk, internal audit, and regulatory engagement teams on issues affecting Japan.
・Ensure that business decisions involving control gaps, exceptions, delayed remediation, or localized operating models are clearly documented and assigned to the appropriate accountable owner.
・Help distinguish between regulatory obligations, global security requirements, business decisions, and technical implementation responsibilities.
・Support clear reporting of Japan cyber risk, remediation progress, control implementation, and material dependencies.