01 Oct
|
Moody's Analytics
|
Gurugram
01 Oct
Moody's Analytics
Gurugram
Job Summary
At Moodys, we unite the brightest minds to turn today s risks into tomorrow s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are-with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody s is transforming how the world sees risk.
As a global leader in ratings and integrated risk assessment, we re advancing AI to move from insight to action-enabling intelligence that not only understands complexity but responds to it. We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed, and confidence.
If you are excited about this opportunity but do not meet every single requirement, please apply! You still may be a great fit for this role or other open roles.
We are seeking candidates who model our values: invest in every relationship, lead with curiosity, champion diverse perspectives, turn inputs into actions, and uphold trust through integrity.
Skills and Competencies
- 5+ years of experience in Cybersecurity, IT Audits, Cyber Controls Testing, Risk Management, or Information Security Assurance
- Strong expertise in cybersecurity control frameworks including NIST CSF, ISO 27001, CIS Controls, OWASP, cloud security, and data governance practices
- Proven ability to assess the design and operating effectiveness of preventive, detective, and corrective controls across applications, infrastructure, cloud, and hybrid environments
- Hands-on knowledge of vulnerability management, secure configuration reviews, SIEM, DLP, IAM, network security, and remediation practices.
- Experience leveraging AI, automation,
and data analytics to enhance testing efficiency, monitoring capabilities, and assurance coverage.
- Excellent stakeholder management, communication, project management, analytical thinking, and team leadership skills, with the ability to manage multiple priorities in a global setting
Education
- Bachelors Degree in Information Security, Cybersecurity, Computer Science, Information Technology, or a related field
- ISO 27001 Lead Auditor certification required
- Professional certifications such as CISA, CISSP, AWS Security, Microsoft Security, OSCP, or equivalent are strongly preferred
Responsibilities
- Lead and execute risk-based cybersecurity audits, controls assessments, and readiness reviews across applications, infrastructure, cloud, and hybrid environments
- Conduct ISO 27001-focused assessments and validate the design and operating effectiveness of cybersecurity controls across business and technology functions and perform audit planning, scoping, control mapping, evidence collection, testing, documentation, reporting, and remediation validation activities
- Evaluate cybersecurity risks and identify control gaps using established frameworks, threat scenarios, and risk assessment methodologies and assess secure configurations, vulnerability management programs,
identity and access management controls, network security controls, DLP solutions, and SIEM capabilities
- Facilitate walkthroughs, stakeholder interviews, and audit closeout meetings to communicate findings, control weaknesses, and remediation expectations.
- Develop and maintain Risk and Control Matrices (RCMs), testing methodologies, continuous assurance programs, and audit standards and monitor process, technology, and organizational changes that may impact the companys cybersecurity posture and control environment
- Perform root cause analysis and impact assessments for identified issues and provide risk-based recommendations to strengthen controls and support regulatory requests, management reporting, board-level materials, and cybersecurity governance activities
- Maintain organized repositories of policies, test evidence, audit documentation, and assessment results while providing status updates to stakeholders and drive continuous improvement initiatives by applying data analytics, automation, business intelligence, and innovative assurance techniques.
- Build strong partnerships with stakeholders across business and technology functions and provide guidance on cybersecurity risk and control matters and mentor and coach team members, fostering professional development, accountability, and knowledge sharing within the team.
Disclaimer: This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.
📌 Sr Controls Analyst (Gurugram)
🏢 Moody's Analytics
📍 Gurugram