At a Glance
- Tasks: Lead cybersecurity risk management and develop frameworks to protect our data.
- Company: Join Moody's, a leader in data management and analytics, fostering innovation and inclusivity.
- Benefits: Enjoy competitive salary, medical insurance, and a supportive work environment with flexible options.
- Why this job: Make a real impact on cybersecurity while collaborating with diverse teams in a dynamic setting.
- Qualifications: 6+ years in information security; strong knowledge of application security and risk management required.
- Other info: Open to applicants who may not meet every requirement—your unique perspective is valued!
The predicted salary is between 56400 - 84800 £ per year.
Location: 55 Princess Street, Floor 3, Manchester, M2 4EW, GB
Line Of Business: Data Estate (DE)
Job Category: Engineering & Technology
Experience Level: Experienced Hire
At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We strive to create an inclusive environment where everyone feels welcome to be who they are, with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways.
Welcome to the Data Estate business unit at Moody's Analytics, where we are pioneering the future of data management and analytics. Our mission is to deliver precise, timely data with a commitment to innovation. At Data Estate, we focus on enhancing Moody's digital presence and improving customer engagement through innovative data solutions. Our team is dedicated to enforcing and evolving our data quality framework, improving transparency into our data assets, and strategically growing new and existing information providers.
We are building a resilient data platform that supports our strategic priorities and drives long-term, sustainable growth for the business. Join us at Data Estate and be part of a dynamic team that is shaping the future of data management. We offer a collaborative environment where your contributions will have a meaningful impact on our clients and the industry. If you are passionate about data quality, governance, and innovation, we invite you to explore opportunities with us and help us deliver exceptional results.
Job Summary:
The Associate Director will be responsible for supporting the identification, assessment, and mitigation of cybersecurity risks and vulnerabilities within the organization. This role involves assisting in the development and implementation of cybersecurity frameworks and procedures to ensure the organization's compliance with regulatory requirements and industry best practices. The Associate Director will work closely with senior management, business units, and other stakeholders to promote a strong risk culture and ensure effective cybersecurity risk management practices.
Responsibilities include:
- Assist in the development and implementation of an enterprise-wide cybersecurity risk management framework, including procedures and tools for identifying, assessing, monitoring, and reporting cybersecurity risks and vulnerabilities.
- Support the execution of risk assessments, vulnerability assessments, and penetration testing to identify potential cybersecurity risks and their impact on the organization.
- Provide dedicated security functions in accordance with the needs, risk level, and plans provided by the corporate security plan.
- Manage the risk posture, regulatory compliance assurance, and the coordination of security plans in conjunction with the Senior Director of Risk Management.
- Monitor, schedule and communicate information security tasks, events and trends.
- Identify monitoring and reporting of risk items to the Senior Director of Risk Management.
- Develop and report key metrics.
- Document the application security program (Secure Coding Policies, Security Guidelines, Best Practices, Checklists, etc.).
- Act as business security champion, mentor and guide other security analysts.
- Collaborate with business units and other stakeholders to ensure that cybersecurity risks are effectively managed and mitigated.
- Perform other related duties as assigned.
Qualifications:
- Bachelor's degree in Information Assurance, Information Security, Information Systems or related field preferred.
- Information Security certifications and Security Product Certifications are desirable.
- 6+ years information security experience in a large and complex business environment.
- 3+ years experience identifying and remediating application security risks as part of vulnerability assessments and remediation programs.
- Strong knowledge of the development of application security assessment and code review methodologies.
- Strong knowledge of application security vulnerabilities, remediation and mitigation techniques, and secure coding practices.
- Working knowledge of automated application security scanning tools such as Qualys, Prisma Cloud or other similar commercial solutions.
- Working knowledge of manual assessment tools, automation scripts and other commercial and open source tools is preferred.
- Strong analytical skills to troubleshoot technical problems and determine resolution.
- Strong knowledge of web technologies (.ASP, .NET, Java).
- Exposure to Application Security Maturity Models.
- Collaborates effectively with cross-functional entities across the enterprise.
- Organizational direction, time management, problem-solving, prioritization, goal setting, leadership and motivation, negotiation, interpersonal relations, verbal/written communications and human resource management.
Annual base salary gross: £68,400.00 to £113,000.00. Actual salaries will vary and will be based on various factors, such as candidate’s qualifications, skills, and competencies. The salary is one component of Moody’s total compensation package for employees. Other rewards and benefits include Medical, Personal Accident, Life Insurance and Time Off. Moody’s is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender expression, gender identity or any other characteristic protected by law.
Associate Director - Risk Management - Cybersecurity employer: Moody's Investors Service
Contact Detail:
Moody's Investors Service Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Associate Director - Risk Management - Cybersecurity
✨Tip Number 1
Familiarise yourself with the latest cybersecurity frameworks and regulations relevant to the role. Being able to discuss how these frameworks can be applied in practice during your interview will demonstrate your proactive approach and understanding of the industry.
✨Tip Number 2
Network with professionals in the cybersecurity field, especially those who work at Moody's or similar companies. Engaging in conversations about current trends and challenges can provide you with valuable insights and potentially lead to referrals.
✨Tip Number 3
Prepare to showcase your experience with risk assessments and vulnerability management. Be ready to discuss specific projects where you've successfully identified and mitigated risks, as this will highlight your practical skills and relevance to the role.
✨Tip Number 4
Demonstrate your leadership qualities by discussing how you've previously mentored others in cybersecurity practices. This aligns with the role's requirement to act as a business security champion and shows your ability to foster a strong risk culture.
We think you need these skills to ace Associate Director - Risk Management - Cybersecurity
Some tips for your application 🫡
Tailor Your CV: Make sure your CV highlights relevant experience in cybersecurity and risk management. Focus on your achievements in previous roles, especially those that align with the responsibilities listed in the job description.
Craft a Compelling Cover Letter: In your cover letter, express your enthusiasm for the role and the company. Mention specific aspects of Moody's values that resonate with you and how your background makes you a great fit for their team.
Highlight Relevant Skills: Emphasise your knowledge of application security vulnerabilities, secure coding practices, and any relevant certifications. Make sure to mention your experience with automated security scanning tools, as this is crucial for the role.
Showcase Your Collaborative Spirit: Since the role involves working closely with various stakeholders, provide examples of how you've successfully collaborated in past projects. This will demonstrate your ability to foster relationships and promote a strong risk culture.
How to prepare for a job interview at Moody's Investors Service
✨Understand Cybersecurity Fundamentals
Make sure you have a solid grasp of cybersecurity principles and frameworks. Be prepared to discuss how you would identify, assess, and mitigate risks within an organisation, as this is crucial for the Associate Director role.
✨Showcase Your Experience
Highlight your relevant experience in information security, particularly in risk management and vulnerability assessments. Use specific examples from your past roles to demonstrate your ability to handle complex security challenges.
✨Emphasise Collaboration Skills
Since the role involves working closely with various stakeholders, be ready to discuss how you've successfully collaborated with cross-functional teams in the past. Share examples that showcase your ability to communicate effectively and build relationships.
✨Prepare for Technical Questions
Expect technical questions related to application security vulnerabilities and remediation techniques. Brush up on your knowledge of automated scanning tools and secure coding practices, as these will likely come up during the interview.