SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Moody's Internal Controls Department is seeking a Senior Controls Analyst to lead risk-based cybersecurity audits, controls assessments, and readiness reviews across applications, infrastructure, cloud, and hybrid environments. This role is part of the Internal Controls Department, which provides independent assurance and advisory services to strengthen Moody's control environment and support operational excellence.
Key Responsibilities:
- Lead and execute risk-based cybersecurity audits, controls assessments, and readiness reviews across applications, infrastructure, cloud, and hybrid environments
- Conduct ISO 27001-focused assessments and validate the design and operating effectiveness of cybersecurity controls across business and technology functions
- Perform audit planning, scoping, control mapping, evidence collection, testing, documentation, reporting, and remediation validation activities
- Evaluate cybersecurity risks and identify control gaps using established frameworks, threat scenarios, and risk assessment methodologies
- Assess secure configurations, vulnerability management programs, identity and access management controls, network security controls, DLP solutions, and SIEM capabilities
- Facilitate walkthroughs, stakeholder interviews, and audit closeout meetings to communicate findings and remediation expectations
- Develop and maintain Risk and Control Matrices (RCMs), testing methodologies, continuous assurance programs, and audit standards
- Monitor process, technology, and organizational changes that may impact the company's cybersecurity posture
- Perform root cause analysis and impact assessments for identified issues
- Provide risk-based recommendations to strengthen controls and support regulatory requests, management reporting, and board-level materials
- Maintain organized repositories of policies, test evidence, audit documentation, and assessment results
- Drive continuous improvement initiatives by applying data analytics, automation, business intelligence, and innovative assurance techniques
- Build strong partnerships with stakeholders across business and technology functions
- Mentor and coach team members, fostering professional development and knowledge sharing
The role offers the opportunity to contribute to high-impact internal control evaluations, risk management assessments, and advisory initiatives while working with global stakeholders to support Moody's commitment to integrity, compliance, and continuous improvement.
Requirements:
- 5+ years of experience in Cybersecurity, IT Audits, Cyber Controls Testing, Risk Management, or Information Security Assurance
- Strong expertise in cybersecurity control frameworks including NIST CSF, ISO 27001, CIS Controls, OWASP, cloud security, and data governance practices
- Proven ability to assess the design and operating effectiveness of preventive, detective, and corrective controls across applications, infrastructure, cloud, and hybrid environments
- Hands-on knowledge of vulnerability management, secure configuration reviews, SIEM, DLP, IAM, network security, and remediation practices
- Experience leveraging AI, automation, and data analytics to enhance testing efficiency, monitoring capabilities, and assurance coverage
- Excellent stakeholder management, communication, project management, analytical thinking, and team leadership skills
- Ability to manage multiple priorities in a global environment
- Bachelor's Degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field
- ISO 27001 Lead Auditor certification (required)
- Professional certifications such as CISA, CISSP, AWS Security, Microsoft Security, OSCP, or equivalent (strongly preferred)