Logo for Moody's Analytics

(Application Security Testing) DevOps Engineer

Role overview

Qualifications

  • 1-3 years of experience conducting application security reviews including static and dynamic application security testing, and penetration testing.
  • Strong knowledge of secure software development practices, threat modeling, and secure architecture design.
  • Ability to assess security risks within applications and provide practical remediation guidance.
  • Bachelor’s degree in computer science, Information Security, Engineering, or a related field, or equivalent practical experience.

Responsibilities

  • Partner with product and engineering teams to embed security into the software development lifecycle and drive proactive risk management.
  • Conduct application security reviews including static application security testing, dynamic application security testing, and penetration testing activities.
  • Perform threat modeling exercises and provide recommendations to address identified risks.
  • Design and review secure architectures for applications, services, and cloud-based solutions.

Key facts

Hard skills

Other skills

  • Communication

About the company

Moody's Analytics logo

Moody's Analytics

Data Analytics & Business Intelligence

In an era where risks are multiplying and increasingly interconnected, Moody’s helps organizations make sense of the complexities. By combining data, intelligence, and risk expertise with groundbreaking technologies and a seamless customer experience, we deliver relevant insights on interconnected risk to thousands of organizations worldwide – enabling business and financial leaders to act decisively and thrive amid uncertainty.

Company details

IndustryData Analytics & Business Intelligence
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

 

At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are—with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody’s is transforming how the world sees risk. As a global leader in ratings and integrated risk assessment, we’re advancing AI to move from insight to action—enabling intelligence that not only understands complexity but responds to it. We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed, and confidence.

If you are excited about this opportunity but do not meet every single requirement, please apply! You still may be a great fit for this role or other open roles. We are seeking candidates who model our values: invest in every relationship, lead with curiosity, champion diverse perspectives, turn inputs into actions, and uphold trust through integrity. 

Skills and Competencies

  • 1-3 years of experience conducting application security reviews including static application security testing, dynamic application security testing, and penetration testing.
  • Strong knowledge of secure software development practices, threat modeling, and secure architecture design
  • Ability to assess security risks within applications and provide practical remediation guidance
  • Understanding of network and web protocols including Transmission Control Protocol/Internet Protocol, User Datagram Protocol, Internet Protocol Security, Hypertext Transfer Protocol, and Hypertext Transfer Protocol Secure
  • Experience securing cloud environments including Amazon Web Services, Microsoft Azure, and other public cloud platforms
  • Proficiency in one or more programming languages such as Java, C++, Python, Ruby, or Perl
  • Strong communication and stakeholder management skills with the ability to influence technical decisions and build partnerships with development teams
  • Demonstrated proficiency in artificial intelligence concepts, with hands-on experience using AI tools to streamline workflows and enhance operational efficiency. Proven ability to implement AI-powered solutions to solve business challenges. Demonstrates a growing awareness of AI risk management and a commitment to responsible and ethical AI use.

Education

  • Bachelor’s degree in computer science, Information Security, Engineering, or a related field, or equivalent practical experience

Responsibilities

Partner with product and engineering teams to embed security into the software development lifecycle and drive proactive risk management.

  • Conduct application security reviews including static application security testing, dynamic application security testing, and penetration testing activities
  • Perform threat modeling exercises and provide recommendations to address identified risks
  • Design and review secure architectures for applications, services, and cloud-based solutions
  • Develop security guidance, standards, and documentation for internal development teams
  • Deliver security metrics, analyze trends, and identify opportunities for continuous improvement
  • Build strong relationships with product and engineering teams to promote security best practices and awareness
  • Drive security risk assessments and support risk-based decision making across projects and initiatives
  • Influence technical architecture decisions to ensure security requirements are effectively incorporated into solutions

About the Team

Team is responsible for protecting applications, platforms, and data across the organization by embedding security throughout the development lifecycle. The team partners closely with engineering and product stakeholders to identify risks, strengthen security controls, and drive adoption of secure-by-design principles. By joining this team, you will contribute to securing innovative technology solutions, enhancing organizational resilience, and supporting the responsible adoption of emerging technologies, including artificial intelligence, across the business.

Moody’s is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender expression, gender identity or any other characteristic protected by law.

Candidates for Moody's Corporation may be asked to disclose securities holdings pursuant to Moody’s Policy for Securities Trading and the requirements of the position. Employment is contingent upon compliance with the Policy, including remediation of positions in those holdings as necessary.

 

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

DevOps Engineer Related jobs

Other jobs at Moody's Analytics

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.