IT Auditor

Moody's Corporation
Charlotte, NC, United States
7 days ago
Apply on find.jobs
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
3 years minimum
Compensation
$82,400.0 - $119,450.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Excel Agile Methodology Artificial Intelligence Data Analysis Cloud Computing Security Cyber Security Information Systems Computer Engineering Data Governance Information Leak Prevention DevOps Disaster Recovery
+14 more
Identity and Access Management Microsoft Office Systems Development Life Cycle Power BI Secure Coding Tableau (Software) Software Vulnerability Management Microsoft Power Automate Software Security Malware Information Technology Data Analytics Patch Management Devsecops

Job description

This role is responsible for leading and executing risk-based IT and cybersecurity audits while providing insights on emerging technology risks across the organization.

  • Lead and execute IT and cybersecurity audits with a focus on emerging risks including cloud, AI, and modern technology practices
  • Develop a deep understanding of technology environments, business processes, and associated risks and controls
  • Plan audit scope through process analysis, risk assessment, and control identification
  • Evaluate cybersecurity governance, cloud security, identity access management, infrastructure security, and data protection controls
  • Assess vulnerability management, secure development practices, and system change management processes
  • Execute audit testing and maintain high-quality, well-documented workpapers
  • Translate technical findings into clear, actionable business insights and recommendations
  • Communicate effectively with stakeholders across Cyber, Technology, Data, and Product teams
  • Draft audit observations, articulate risk impacts, and support remediation efforts
  • Track and validate remediation activities to ensure effective and sustainable control improvements
  • Build strong stakeholder relationships and incorporate business objectives into audit execution
  • Leverage data analytics and automation tools to enhance audit efficiency and continuous monitoring

About the Team

The Internal Audit team is dedicated to delivering independent, objective assurance and advisory services that enhance organizational value. The team partners across the business to strengthen risk management, control, and governance processes while supporting innovation and continuous improvement across Moody’s global operations.

Requirements

  • Minimum of 3 years of experience in a Big 4 firm or global organization in IT audit, cybersecurity, risk, or controls
  • Strong understanding of IT and cybersecurity risk management, controls, and governance frameworks (e.g., NIST, ISO, COBIT, COSO)
  • Experience auditing cloud environments (AWS, Azure, SaaS) including security architecture, configurations, and access controls
  • Knowledge of identity and access management (IAM, PAM, SSO, MFA) and privileged access oversight
  • Familiarity with network, endpoint, infrastructure security, and vulnerability and patch management processes
  • Understanding of secure development practices (SDLC, Agile, DevOps, DevSecOps) and application security controls
  • Experience evaluating data governance and protection practices including encryption, classification, and data loss prevention
  • Ability to assess resilience, disaster recovery, and ransomware recovery readiness
  • Strong analytical, critical thinking, and problem-solving skills with the ability to translate technical findings into business insights
  • Effective written and verbal communication skills, with the ability to influence stakeholders
  • Experience using data analytics tools (e.g., Excel, Power BI, Tableau) to support audit testing and insights
  • Proficiency in Microsoft Office and exposure to GenAI and AI-driven tools (e.g., Microsoft Copilot)
  • Ability to manage multiple priorities in a fast-paced, collaborative environment

Education

  • Bachelor’s degree required in cybersecurity, computer science, computer engineering, information technology, information systems, or a related field
  • Professional certifications such as CISSP, CISA, or equivalent are preferred

Benefits & conditions

For US-based roles only: the anticipated hiring base salary range for this position is $82,400.00 - $119,450.00, depending on factors such as experience, education, level, skills, and location. This range is based on a full-time position. In addition to base salary, this role is eligible for incentive compensation. Moody’s also offers a competitive benefits package, including not but limited to medical, dental, vision, parental leave, paid time off, a 401(k) plan with employee and company contribution opportunities, life, disability, and accident insurance, a discounted employee stock purchase plan, and tuition reimbursement.

About the company

hackajob is collaborating with Moody’s Corporation to connect them with exceptional professionals for this role.

At Moody’s, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are-with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody’s is transforming how the world sees risk. As a global leader in ratings and integrated risk assessment, we’re advancing AI to move from insight to action-enabling intelligence that not only understands complexity but responds to it. We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed, and confidence.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on find.jobs
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

5:13 min

Audience Q&A on maturity assessments and external consultants

Mathias Tausig · LIVE

1:24 min

Moving the semantic layer upstream to avoid vendor lock-in

Piotr Menclewicz Piotr Menclewicz · Europe 2026 Virtual

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

2:17 min

Mapping the maturity roadmap for scaled devops adoption

Dominik Krichbaum Dominik Krichbaum · World Congress 2026 Europe

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

3:48 min

Standardizing data access schemas with OData

Florian Bader Florian Bader · World Congress 2026 Europe

Videos

See all

Related articles

See all