Thursday, 5 December 2013

Job: AVP - Information Security Monitoring

Job Description

Moody"s Investors Service is among the world"s most respected, widely utilized sources for credit ratings, research and risk analysis. In addition to our core ratings business, Moody"s publishes market-leading credit opinions, deal research and commentary that reach more than 3,000 institutions and 22,000 subscribers around the globe. Moody’s Information Security is looking for an AVP of Information Security Monitoring to join its growing organization. This is a challenging position requiring a strong background in Information Security practice, deep knowledge of security monitoring tools, and solid communication and organization skills. The successful candidate is very motivated and willing to take on challenges, able to multi-task to succeed and has the ability work independently and with minimal oversight.

The Moody’s Information Security team is responsible for helping the organization balance risk by aligning policies and procedures with Moody’s business requirements. The team is responsible for the development, enforcement and monitoring of security controls, policies and procedures, and for the delivery of security services. The Information Security team sets strategic direction for security within the organization and aligns with stakeholders throughout the company.

The AVP of Information Security Monitoring will be responsible for owning the overall security tools architecture, mapping all threats in the current landscape, and ensuring the correct technological strategy to counter each threat. The employee will maintain the security tools map, identifying gaps, and proposing solutions to address gaps and make improvements. The employee works closely with platform engineering teams to integrate security monitoring tools in the network and server environment and owns relationships with third-party security monitoring vendors.

Functional Responsibilities:



  • Act as the Information Security point person for architecting, implementing and maintaining the security tool environment. 
  • Establishes as the resident expert on the chosen and considered security tools, able to articulate use cases and functionality, as well as provide training to other employees. 
  • Owns third-party security monitoring relationships and synthesizes internal and third-party dashboards and threat intelligence reports into executive presentations. 
  • Manage the successful delivery of Information Security tool projects, by working directly with key business stakeholders, Moody’s IT (MIT) executives and project teams. Work with Project Managers, as well as Platform and Security Engineers to ensure that security tool implementations are designed and deployed in a manner which satisfies the Information Security team’s short and long term goals. 
  • Provide Level-3 support for security tools in the Moody’s environment; assisting L1 and L2 teams with troubleshooting errors, performance tuning, and functionality improvement. 
  • Keep the relevant Moody’s Information Security policies and procedures aligned with industry standards, technology best practices, as well as infrastructure and organizational changes. Develop and showcase security tool coverage gap analyses and dashboards. 
  • Contribute to the overall security strategy and future roadmap for our security posture. 
  • Assist other technical teams in resolution of security incidents and outages related to information security tools, including coordinating of information security resources and root cause analysis. 
  • Develop and oversee the execution of implementation and improvement plans.
Resumes submitted in Microsoft Word format are preferred.



Thank you for taking the time to express your interest in employment opportunities with Moody"s Investors Service.

Job Requirements
Minimum education and work experience required for this position include:



  • 7 to 10 years experience in IT industry, preferably in a financial services organization. 
  • Minimum of 3 recent years direct experience working with security monitoring and control tools such as application whitelisting, password vaulting, privileged access control, email vaulting, log archiving. 
  • Expert knowledge of regular expressions and at least one common scripting language (PERL, Python, VB Script). 
  • Direct experience with managed security service provider (MSSP) relationships either, as a consumer or employee. 
  • BS or BA degree, preferably in technology/business or equivalent. 
  • Relevant certifications such as CISSP are a plus. 
  • Proficiency in a second language is a plus, especially Mandarin, Korean, Japanese or Russian.

Key Competencies



  • Ability to think with a security mindset. The successful candidate has a strong IT background with expert level knowledge of multiple relevant security practice areas (access control; application security; network security; monitoring; endpoint, etc.). 
  • Extensive knowledge of security monitoring tools which perform functions such as application whitelisting, password vaulting, privileged access control, email vaulting, log archiving. A wide range of experience in these tools, from hands-on configuration and operation, to high level design and architecture is preferred. 
  • Strong written and oral communication skills including the ability to interact directly with customers that do not have an IT background. 
  • Proven ability to work within a large enterprise that spans multiple continents, is governed by change management and has a tiered support model. 
  • Security tool gap analysis documentation; must be able to write and proof documents intended for technical and executive audiences. 
  • Experience in selecting different types of tools to combat the myriad of threats present in the current landscape, taking into account budget, and minimizing functionality overlap. 
  • Ability to work in a time-sensitive environment; must be detail oriented and able to multitask to meet deadlines and company objectives.

Company Overview

Moody's is an essential component of the global capital markets, providing credit ratings, research, tools and analysis that contribute to transparent and integrated financial markets. Moody's Corporation (NYSE: MCO) is the parent company of Moody's Investors Service, which provides credit ratings and research covering debt instruments and securities, and Moody's Analytics, which offers leading-edge software, advisory services and research for credit and economic analysis and financial risk management. The Corporation, which reported revenue of $2.3 billion in 2011, employs approximately 6,100 people worldwide and maintains a presence in 28 countries. Further information is available at www.moodys.com.



Not Ready to Apply?

0 comments:

Post a Comment