Information Security Engineer recruitment
Job Description
Moody's Information Security is looking for an Information Security Engineer to join its growing organization. This is a challenging position requiring a wide array of skills in core IT infrastructure and security. The candidate must be very motivated and willing to take on challenges, learn new concepts and be willing to multi-task to succeed.
The Moody's Information Security team is responsible for helping the organization balance risk by aligning policies and procedures with Moody's business requirements. The team is responsible for the administration of security controls required to enforce and monitor policies including the administration of user access rights, access control infrastructure and monitoring and reporting systems. The Information Security Engineer is responsible for providing front line support to these areas by acting as an escalation point for customer request tickets and service outages. The job requires excellent organization skills and attention to detail so that requests are handled in a uniform manner and so that issues are properly documented for our auditors. The job requires a very good understanding of the underlying platform infrastructure and associated security issues. The Information Security Engineer ensures that standard operating procedures are followed through the lifecycle of security requests as they are escalated to other technical teams. The associate will monitor the effectiveness of procedures, document issues and then work with senior team members on improvement plans.
Functional Responsibilities
- Processing information security request tickets including monitoring information security request queues to ensure that client requests are handled effectively and in a timely manner.
- Review client requests for information security changes to ensure that the appropriate policies are followed and that the requests are properly documented before they are transferred to the operations teams.
- Review of monitoring and audit reports to ensure that operations teams are performing within established guidelines and that security controls are executed properly.
- Collecting information for internal clients including our Legal, Human Resources, and Audit organizations.
- Documenting information security exceptions and working with senior Information Security team members to update procedures where appropriate.
- Ensuring that procedures and policies are followed during the security request lifecycle.
- Assisting other technical teams in resolution of security incidents and outages related to information security controls, including coordinating information security resources and performing first response troubleshooting.
- Keeping abreast of new technologies and developments in related area of responsibility.
- Evaluate third-party applications to determine appropriate security controls, risk to the environment, and recommend competing products based on security criteria.
- Interpret audit findings and work with system administrators and developers to resolve open security issues.
- Engineer and manage security operations solutions including firewalls, remote access, IPS, two-factor authentication, server and desktop client security and anti-virus.
- Monitor and respond to security alerts; develop root cause analysis for security incidents.
Qualifications
Minimum education and work experience required for this position include:
- Minimum 5 years experience in IT industry in relevant area or relevant industry certification combined with some college level coursework in IT.
- Strong written and communication skills.
- Ability to interact directly with customers that do not have an IT background.
- Experience with Information Security policies and procedures associated with a large enterprise especially as they relate to regulatory issues surrounding Sarbanes-Oxley, and the Payment Card Industry Data Security Standard.
- Experience using Visio to create process diagrams based on existing procedures.
- Strong experience using Excel to produce effective reports.
- Experience working with Microsoft Windows in an Active Directory environment, including group-based security and group policy.
- Strong knowledge of TCP/IP networking including firewall and packet filtering concepts.
- Familiarity with the ISO 27002 standard.
- Solid understanding of multi-tier applications and their associated security issues.
- Able to translate business requirements into sensible security solutions and work within a budget.
Key Tech and Non-Tech Skills
- Ability to think with a security mindset. The successful candidate has a strong IT background with expert level knowledge of a key security practice area: access control; application security; network security; monitoring; endpoint; etc.
- Working knowledge of regulatory standards that govern Information Security practices such as SOX, PCI, and state and federal privacy laws.
- Strong written and oral communication skills including the ability to interact directly with customers that do not have an IT background.
- Demonstrates technical insight through problem solving, applying technical knowledge of products and service management for areas in which he/she operates.
- Use relevant technical information to diagnose problems to allow for appropriate decisions to solve both complex and routine issues.
- Self-direction and or self-motivated to do more than what is expected or required in the job.
- Produce work at high standards to minimize errors.
- Conduct themselves according to the highest standards of integrity and ethics in all business activities.
- Can be counted on to see assigned tasks through to completion without constant follow up.
- Collaborate with others to work together to achieve common goals.
Equal Employment Opportunity
Moody's Corporation is committed to equal opportunities and diversity in its recruitment practices. We welcome applications from all sections of the community and are dedicated to the fair and equal treatment of potential and existing employees, candidates and clients regardless of sex, marital status, ethnic origin, religion, disability, sexual orientation, age or any other characteristic protected by law.