Principal Information Security Specialist

Nomura Holdings, Inc.

Mumbai

On-site

INR 4,500,000 - 6,500,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nomura Holdings, Inc. in Mumbai, India seeks a Principal Information Security Specialist to lead security architecture and data protection initiatives.

You will drive security-by-design across SDLC, perform risk assessments, and guide engineering teams on implementing robust controls for data protection, encryption, DLP, and classification. You will collaborate with cross-functional teams, manage architecture governance, and contribute to regulatory compliance efforts (GDPR-like or MAS/DPDP

Qualifications

  • 10–15 years of hands-on cybersecurity experience.
  • Security architecture assessments and secure-by-design implementations.
  • Knowledge of data protection technologies including DLP, discovery, and classification.
  • Cloud security experience with data protection and access controls.
  • Familiarity with security frameworks (NIST, ISO 27001, CIS).
  • Threat modeling methodologies (STRIDE, PASTA).
  • Strong documentation and architecture diagram skills.

Responsibilities

  • Define enterprise Data Protection reference architectures and security design patterns.
  • Embed Security-by-Design and Privacy-by-Design into SDLC and project lifecycle.
  • Review solution architectures and recommend data protection controls.
  • Perform architecture governance across project lifecycle.
  • Develop security standards and guidelines; document with diagrams.
  • Collaborate with security engineering teams to integrate requirements in SDLC.
  • Perform security risk assessments and threat modeling exercises.
  • Support audit activities and compliance reporting.
  • Manage security architecture projects using Jira and document in Confluence.
  • Provide security guidance to stakeholders and participate in security committees.

Skills

Security architecture
Data protection
Threat modeling
Cloud security
DLP platforms
Data discovery
Classification
Information protection
CASB
NIST ISO 27001

Tools

Jira
Confluence

Job description

Select how often (in days) to receive an alert:

Job Title: Principal Information Security Specialist

Job Code: 14528

Country: IN

Skill Category: IT\\Technology

Description:

Nomura Overview:

Nomura is a financial services group with an integrated global network. By connecting markets East & West, Nomura services the needs of individuals, institutions, corporates and governments through its four business divisions: Wealth Management, Investment Management, Wholesale (Global Markets and Investment Banking), and Banking. Founded in 1925, the firm is built on a tradition of disciplined entrepreneurship , serving clients with creative solutions and considered thought leadership. For further information about Nomura, visit www.nomura.com .

Nomura Services, India supports the group’s global businesses. With world-class capabilities in trading support, research, information technology, financial control, operations, risk management and legal support, the firm plays a key role in facilitating the group’s global operations across four international regions.

At Nomura, creating an inclusive workplace is a priority. Our approach to inclusion encompasses a variety of initiatives, including sensitization campaigns, implementing conducive policies & programs, providing infrastructure support and engaging in community events. Over time, we have made meaningful progress in these areas, and this commitment has been well-recognized across the industry. We are proud recipients of the prestigious Top 10 Employers award by the India Workplace Equality Index (IWEI), IWEI Gold Employer of Choice awards, India CSR Leadership Award 2024 for Holistic Village Development Program and the YUVA Unstoppable Changemaker Awards.

Roles & Responsibilities:

Security Architecture & Design:

  • Define enterprise Data Protection reference architectures and security design patterns.
  • Embed Security-by-Design and Privacy-by-Design principles into the SDLC and project lifecycle.
  • Review solution architectures and recommend appropriate data protection controls.
  • Perform architecture governance during project initiation, design, implementation, and production readiness reviews.
  • Develop security standards and guidelines.
  • Create detailed architecture diagrams and documentation using visualization tools.
  • Collaborate with security engineering teams to integrate security requirements into the software development lifecycle.
  • Perform security risk assessments and threat modeling exercises.
  • Support audit activities and compliance reporting.
  • Manage security architecture projects and initiatives using Jira for tracking and workflow management.
  • Maintain comprehensive documentation in Confluence including security standards, procedures, and knowledge base articles.
  • Provide security guidance and recommendations to stakeholders.
  • Participate in architecture review boards and security committees.

Data Lifecycle Protection

  • Understand and assess data throughout its lifecycle:
    • Data Creation
    • Data Collection
    • Data Discovery
    • Data Classification
    • Data Storage
    • Data Processing
    • Data Sharing
    • Data Retention
    • Data Archival
    • Secure Disposal
  • Identify risks at every lifecycle stage and recommend appropriate protection mechanisms.

Data Protection Technologies

Design and provide architectural guidance for:

  • Enterprise Data Discovery
  • Information Classification & Labeling
  • Microsoft Purview Information Protection
  • Data Loss Prevention (Endpoint, Email, Cloud, Network)
  • Information Rights Management (IRM)
  • Encryption (Data at Rest, In Transit, In Use)
  • Tokenization
  • Static & Dynamic Data Masking
  • Database Security Controls
  • Key Management Systems (KMS)
  • Certificate Lifecycle Management
  • Secrets Management
  • Hardware Security Modules (HSM)
  • Cloud-native data protection capabilities

Project & Solution Advisory

  • Participate in project design workshops.
  • Perform security architecture reviews.
  • Define mandatory security controls for new applications.
  • Identify security design gaps and provide remediation recommendations.
  • Review High-Level Designs (HLD) and Low-Level Designs (LLD).
  • Provide implementation guidance to engineering teams.
  • Support threat modelling focused on data protection risks.

Governance & Compliance

  • Ensure alignment with enterprise Data Security and Cryptography Standards.
  • Support Secure Architecture Evaluation and project governance forums.
  • Validate adherence to regulatory requirements such as GDPR, DPDP, MAS, DORA, JFSA, etc.
  • Define architecture guardrails and security exceptions where required.
Knowledge, Skill, Experience Required:

Required:

Must have 10-15 years of hands-on experience in cybersecurity domain.
  • Proven experience in security architecture assessments and secure-by-design implementations.
  • Strong knowledge of data protection technologies including DLP platforms, data discovery tools, and classification frameworks.
  • Familiarity with Cloud Access Security Brokers (CASB) and cloud data protection solutions.
  • Experience with data discovery and classification technologies for identifying and protecting sensitive data.
  • Experience with cloud security, especially related to data protection, visibility, and access controls.
  • Experience with enterprise security frameworks and methodologies.
  • Deep understanding of security architecture principles and frameworks.
  • Proficiency in threat modeling methodologies (STRIDE, PASTA)
  • Knowledge of security controls and standards (NIST, ISO 27001, CIS Controls)
  • Experience with security assessment tools and techniques.
  • Understanding of network security, application security, cloud security and data protection domains.
  • Expertise in creating detailed architecture diagrams using visualizations, including network diagrams, system architecture, data flow diagrams, and security control mappings
  • Strong documentation skills with experience in creating technical specifications, security procedures, and architectural decision records.
  • Preferred certifications: CISSP, CCSP, Microsoft SC-100/400, TOGAF, SABSA etc.

Beneficial:

  • Strong analytical and problem-solving abilities
  • Excellent written and verbal communication skills
  • Ability to work independently and manage multiple priorities
  • Strong attention to detail and quality-focused approach
  • Experience working in agile environments with cross-functional teams

Personal Characteristics:

  • Strong analytical and problem-solving abilities.
  • Excellent written and verbal communication skills.
  • Ability to work independently and manage multiple priorities.
  • Strong attention to detail and quality-focused approach.
  • Experience working in agile environments with cross-functional teams.

We are committed to providing equal opportunities throughout employment including in the recruitment, training and development of employees. We prohibit discrimination in the workplace whether on grounds of gender, marital or domestic partnership status, pregnancy, carer’s responsibilities, sexual orientation, gender identity, gender expression, race, color, national or ethnic origins, religious belief, disability or age.

*Applying for this role does not amount to a job offer or create an obligation on Nomura to provide a job offer. The expression "Nomura" refers to Nomura Services India Private Limited together with its affiliates.

*The benefits are subject to change and will be in accordance with Company’s policies as may be applicable from time to time).

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Lead Information Security Analyst
Lead Information Security Analyst

Nomura Holdings, Inc. • Mumbai

On-site
INR 3,000,000 - 4,500,000
Wellbeing benefits
Inclusive culture
Employee assistance
Lead Support Analyst
Lead Support Analyst

Nomura Holdings, Inc. • Mumbai

On-site
INR 2,200,000 - 4,200,000
Wellbeing services
Inclusive workplace
Awards & recognition
Sr. Principal Risk & Control Specialist
Sr. Principal Risk & Control Specialist

Nomura Holdings, Inc. • Mumbai

On-site
INR 1,800,000 - 2,800,000
Principal Infrastructure and Platform Engineer
Principal Infrastructure and Platform Engineer

Nomura Holdings, Inc. • Mumbai

On-site
INR 4,000,000 - 7,000,000
Risk Management – Business Analyst – Counterparty Credit Risk - Associate
Risk Management – Business Analyst – Counterparty Credit Risk - Associate

Nomura • Mumbai

On-site
INR 2,500,000 - 4,200,000
Sr. Infrastructure Operations & Services
Sr. Infrastructure Operations & Services

Nomura Holdings, Inc. • Mumbai

On-site
INR 1,800,000 - 2,400,000
Principal Risk & Control Specialist
Principal Risk & Control Specialist

Nomura Holdings, Inc. • Mumbai

On-site
INR 4,000,000 - 7,000,000
Sr. Infrastructure Operations & Services
Sr. Infrastructure Operations & Services

Nomura Holdings, Inc. • Mumbai

On-site
INR 1,200,000 - 1,800,000
Risk Management – Risk & Control Associate
Risk Management – Risk & Control Associate

Nomura • Mumbai

On-site
INR 1,500,000 - 2,100,000
VP - AI Governance
VP - AI Governance

Nomura Holdings, Inc. • Mumbai

On-site
INR 1,000,000 - 1,500,000
Comprehensive wellbeing services
Inclusive benefits for diverse identities
Support for work-life balance