- New York, NY, USA
- Permanent, Full time
- 20 Mar 18
Senior Cybersecurity Analyst (Splunk)
Location: New York, NY, USAMoody's Information Risk team is looking for a Senior Cybersecurity Analyst to join its growing organization.
The Senior Cybersecurity Analyst will be responsible for working with Moody's Cybersecurity's SIEM platform based on Splunk and owning the health, accuracy, and maintenance of the application on a go forward basis. The individual will be responsible for architecting upgrades and proactively seek out improvements to the application while working with operations and support teams to implement these upgrades and enhancements. This role will also involve designing Splunk queries that assist the cybersecurity department in identifying potentially malicious activity and assisting other teams at Moody's to make better data-driven decisions using Splunk. This role will also involve the development of dashboards and reports in Splunk to assist with compliance to regulation and identify security control failures. The individual will also be expected to work closely with the operations team to onboard new security-related data sources.
This position requires a technical background in Information Security practice, and solid communication and organization skills. The successful candidate is very motivated and willing to take on challenges, able to multi-task to succeed and has the ability work independently and with minimal oversight.
The Moody's Information Security team is responsible for helping the organization balance risk by aligning policies and procedures with Moody's business requirements. The team is responsible for the development, enforcement, and monitoring of security controls, policies, and procedures, and for the delivery of security services. The Information Security team sets the strategic direction for security within the organization and aligns with stakeholders throughout the company.
- Work as part of the Cybersecurity Analytics program, assisting various departments and individuals at Moody's to onboard new data sources into the SEIM.
- Own the health and maintenance of the Splunk platform, providing clear guidance and direction to operations teams when managing and improving the application.
- Work with other Cybersecurity teams such as Incident Response.
- Keep current on external and internal threat behaviors. Translate these behaviors into Splunk search language queries in the SIEM platform.
- Work with the Moody's SOX team to help Moody's remain in compliance with SOX using custom reports, alerts and dashboards in Splunk.
- Construct advanced reports, dashboards, and alerts using Splunk and operationalize these capabilities with documentation in the form of standard operating procedures.
- Ability to exercise sound technical, interpersonal and organizational judgment while evaluating and solving complex problems.
- Partner with system owners to identify the upcoming end of life components, and plan track their decommissioning
Minimum education and work experience required for this position include:
- At least 5 years of experience in IT industry, preferably in a financial services organization.
- Minimum of 3 recent years direct security analytics or big data analysis.
- Expert knowledge of regular expressions and at least one common scripting language (PERL, Python, VB Script).
- Demonstrated advanced knowledge of the Splunk architecture planning, administration, search language, search techniques, alerts, dashboard and report building.
- BS or BA degree, preferably in Computer Science, other sciences.
- Relevant certifications such as CISSP are a plus.
- Proficiency in a second language is a plus, especially Mandarin, Korean, Japanese or Russian.
- Strong knowledge of regulatory standards that govern Information Security Incident Response and Investigation practices such as state and federal privacy laws, Electronic Communications Privacy Act.
- Hands-on experience using SIEM platforms including Splunk. Expert level of familiarity with SIEM search languages, including mathematical and statistical functions.
- Hands-on experience managing SEIM platforms including Splunk. Strong familiarity with Splunk architecture, implementation, management and maintenance.
- Reasonable understanding of Indicators of Compromise and other methodologies to detect incident-related anomalies.
- Must understand and be familiar with modeling security related data concepts, such as net flow, Web browsing, authentication, email flow, etc.
- Good written and oral communication skills including the ability to interact directly with customers that do not have an IT background.
- Proven ability to work within a large enterprise that spans multiple continents, is governed by change management and has a tiered support model.
- Reporting and dashboards - must be able to create reports and dashboards that represent significant data findings to both technical and executive audiences.
- Ability to work in a time-sensitive environment; must be detail oriented and able to multitask to meet deadlines and company objectives
Moody's is an essential component of the global capital markets, providing credit ratings, research, tools and analysis that contribute to transparent and integrated financial markets. Moody's Corporation (NYSE: MCO) is the parent company of Moody's Investors Service, which provides credit ratings and research covering debt instruments and securities, and Moody's Analytics, which offers leading-edge software, advisory services and research for credit and economic analysis and financial risk management. The Corporation, which reported revenue of $3.6 billion in 2016, employs approximately 10,700 people worldwide and maintains a presence in 36 countries. Further information is available at www.moodys.com.
Moody's is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, sex, gender, age, religion, national origin, citizen status, marital status, physical or mental disability, military or veteran status, sexual orientation, gender identity, gender expression, genetic information, or any other characteristic protected by law. Moody's also provides reasonable accommodation to qualified individuals with disabilities in accordance with applicable laws. If you need to inquire about a reasonable accommodation, or need assistance with completing the application process, please email email@example.com.. This contact information is for accommodation requests only, and cannot be used to inquire about the status of applications.
For San Francisco positions, qualified applicants with criminal histories will be considered for employment consistent with the requirements of the San Francisco Fair Chance Ordinance. For New York City positions, qualified applicants with criminal histories will be considered for employment consistent with the requirements of the New York City Fair Chance Act. For all other applicants, qualified applicants with criminal histories will be considered for employment consistent with the requirements of applicable law.
Click here to view our full EEO policy statement. Click here for more information on your EEO rights under the law.
Candidates for Moody's Corporation may be asked to disclose securities holdings pursuant to Moody's Policy for Securities Trading and the requirements of the position. Employment is contingent upon compliance with the Policy, including remediation of positions in those holdings as necessary.