Nomura Overview Nomura is a financial services group with an integrated global network. By connecting markets East & West, we service the needs of individuals, institutions, corporates and governments through our four business divisions: Wealth Management, Investment Management, Wholesale (Global Markets and Investment Banking) and Banking. Driven by the insights of some 28,000 people worldwide, we put our clients at the center of everything we do, delivering unparalleled access to, from and within Asia. For further information about Nomura, visit www.nomura.com Department Overview Nomura's IT department provides technology solutions to support the company's business activities. The team works closely with senior leadership, business units, and stakeholders to develop and implement effective IT strategies, providing guidance on technology selection and implementation while ensuring system reliability, security, and scalability. Nomura's IT team specializes in software development, infrastructure management, cybersecurity, and data analytics and is known for providing exceptional service to clients. With a strong track record and commitment to innovation and global reach, Nomura's IT department is well-positioned to continue driving growth and success in the financial industry. Role Description Reporting to Senior Principal Business Analyst, the Principal IT Risk & Control Officer will be required to support the continued growth of its International Wealth Management (IWM) business in Asia, overseeing IT audit readiness and conducting reviews of all internal IT controls, frameworks, policies, and standards. The role will serve as the central coordination point between technology teams and internal/external stakeholders on IT risk, controls, and compliance matters. While the primary focus will be on IWM, the scope may expand to other business lines in the future. Responsibilities Overseeing IT audit readiness and conducting reviews of all internal IT controls, frameworks, policies, and standards. Managing engagement with external reviewers, including Financial Auditors, SOX assessors, and regulatory bodies (MAS, SFC, JFSA). Interpreting regulatory requirements — in particular the MAS Technology Risk Management (TRM) Guidelines, HKMA/SFC requirements, and JFSA standards — and translating them into operational actions, processes, and sustainable controls within the technology environment. IT Controls & Governance Review and ensure that IT controls and processes adhere to the standards and procedures established by the bank. Facilitate gap analyses for applications and systems that do not comply with internal standards, and drive remediation actions through to closure. Track process improvements and maintain a register of control enhancements, providing regular status updates to senior management. Document solutions, control decisions, and risk acceptances in a clear and auditable manner. Project Assurance Perform internal due diligence checks across all technology projects based on the SDLC lifecycle, ensuring adherence to required procedures and successful completion of quality gates. Challenge and advise project teams on control requirements at each stage of delivery. Audit & Regulatory Engagement Act as the single point of contact for all IT-related audit and regulatory engagements, coordinating deliverables between internal application managers, infrastructure teams, and auditors. Liaise with Internal Audit, External Audit, and regulatory inspection teams, ensuring timely and accurate responses to information requests. Support the preparation and execution of SOX, MAS, SFC, and JFSA audits and inspections. Reporting & Stakeholder Management Produce regular senior management reporting covering the IT risk and control landscape, including open issues, remediation progress, and areas for improvement. Engage proactively with business and technology stakeholders to promote a strong control culture and awareness of regulatory expectations. Requirements Degree in Computer Science, Computer Engineering, Information Systems, or related discipline. Minimum 6 years’ experience of experience in information technology risk, IT security, IT audit, or IT controls within a financial services environment Minimum 4 years’ experience in conducting or supporting IT audits and reviewing controls, frameworks, policies, and standards. Strong understanding of regulatory frameworks applicable to technology in banking (e.g., MAS TRM, HKMA/…