Moody’s Information Risk and Security is looking for an Assistant Vice President, security architecture, to join its growing organization. This is a challenging position requiring a strong background in Information Security practice, solid communication and organization skills, and a deep knowledge of Information Security and how it can be applied to infrastructure and cloud components. The candidate is very motivated and willing to take on challenges, able to multi-task to succeed, and has the ability to work independently with minimal oversight.
The Moody’s Information Risk and Security team is responsible for helping the organization balance risk by aligning policies and procedures with Moody’s business and regulatory requirements. The team's mission is to identify risks to Moody's data and systems, and implement strategies to aid in defending against and mitigating those risks. They are responsible for key programs including Security Architecture, Cyber Security, Identity Management and Vendor Security Management. The Information Risk and Security team sets the strategic direction for IT risk and security globally and aligns with stakeholders throughout the organization.
- Provide security architecture designs and security consulting services for enterprise IT projects that cross multiple platforms and ensure alignment with Moody’s security architecture.
- Support the creation of and adherence to Cyber-Security and Information Security Reference Architectures by working with the CyberSecurity Engineering team and developing reusable patterns for security.
- Be able to perform application and infrastructure Risk Assessments.
- Assist in the training of security champions within the various business units to ensure alignment with security
- Support the evaluation of security concerns with new and emerging technologies with particular focus on SaaS, PaaS and IaaS specifically MS Azure / AWS.
- Support successful delivery of Information Security projects and services for our customers by working directly with key business stakeholders and technology SMEs
Risk Assessment and Architecture Minimum education and work experience required for this position include:
- Minimum 7-10 years of experience in IT industry, preferably in a financial services or consulting organization
- BS or BA degree, preferably in technology/business or equivalent
- Relevant certifications such as CISSP, SANS, CCNA/P/E or other known technical certifications are a plus
- Development experience with python, ruby, lambda are a plus.
- Ability to think with a security mindset. The successful candidate has a strong IT background with in depth knowledge of several key security practice area: network/host security; cloud security; security architecture.
- Adaptability and flexibility to work on a variety of assignments as defined by constantly evolving priorities.
- Knowledge of AWS or Azure Cloud technologies, Active Directory, Authentication/Authorization protocols, and Single Sign On technologies.
- Knowledge of NIST, CIS, and CCM security controls.
- Strong written and oral communication skills including the ability to interact directly with customers that do not have an IT background.
- Strong presentation skills involving large and of varying IT background audiences.