Senior Vice President- Application Security

Moody's Corporation

Charlotte (NC)

On-site

USD 228,000 - 333,000

Full time

5 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Dental
Vision
Parental leave
Paid time off
401(k) plan with employee and company 
Life insurance
Disability insurance
Accident insurance
Employee stock purchase plan
Tuition reimbursement

Job summary

Moody's Corporation in Charlotte seeks a senior cybersecurity leader to define and drive enterprise application security strategy across global teams. You will evolve the secure-by-design framework and oversee VMDR, CSPM, and SSPM programs while partnering with engineering, risk, and compliance functions.

The role requires extensive leadership in App/Sec, strong executive communication, and a track record of transforming security postures at scale in cloud-native environments.

Qualifications

  • 15+ years of cybersecurity experience with leadership in App Security and Product Security.
  • Expert in secure SDLC, threat modeling, secure design reviews, and OWASP Top 10.
  • Ability to review production code and influence engineering teams.
  • Experience scaling DevSecOps and AI-enabled security capabilities.
  • Strong knowledge of cloud-native architectures, microservices, containers, Kubernetes, APIs, and SaaS platforms.

Responsibilities

  • Define and evolve enterprise App Security strategy, roadmap, and operating model.
  • Build and lead a global organization of App Security, Product Security, and DevSecOps professionals.
  • Embed security across the software development lifecycle with secure-by-design practices.
  • Drive threat modeling, secure coding standards, automated testing, and software supply chain controls.
  • Provide strategic oversight for VMDR, including risk-based prioritization and metrics reporting.
  • Guide CSPM and SSPM capabilities with platform and engineering teams.
  • Consolidate security findings into a unified enterprise risk view for data-driven decisions.
  • Partner with Engineering, Risk, Legal, Privacy, Compliance, and executives.

Skills

Cybersecurity leadership
Application Security
Product Security
Secure SDLC
Threat modeling
Secure architecture
OWASP Top 10
AI-enabled security
DevSecOps
SAST/DAST/IAST
CI/CD security
SCA
Cloud security
VMDR
Kubernetes
Executive communication
Stakeholder management

Education

Bachelor's degree in CS/Engineering/InfoSec
Advanced degree or relevant certifications (CISSP, CSSLP, CISM, GWAPT, OSCP)

Tools

Kubernetes
CI/CD tooling
SAST/DAST/IAST
SCA
Cloud security tooling

Job description

At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are—with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody’s is transforming how the world sees risk. As a global leader in ratings and integrated risk assessment, we’re advancing AI to move from insight to action—enabling intelligence that not only understands complexity but responds to it.

Skills And Competencies
  • 15+ years of progressive cybersecurity experience, including significant leadership experience in Application Security, Product Security, or related security disciplines
  • Deep expertise in secure software development lifecycle practices, threat modeling, secure architecture and design reviews, secure coding standards, OWASP Top 10, CWE, and modern application security programs
  • Strong software engineering background with the ability to review and assess production code and influence engineering organizations as a trusted technical leader
  • Proven experience implementing and scaling DevSecOps practices, including security automation, AI-enabled security capabilities, SAST, DAST, IAST, SCA, CI/CD security integration, and software supply chain security controls; experience leveraging AI to enhance security operations, risk identification, and engineering efficiency is preferred
  • Strong knowledge of modern technology architectures including cloud-native environments, microservices, containers, Kubernetes, APIs, and SaaS platforms
  • Demonstrated success building and leading high-performing global teams, driving enterprise-wide security transformation, and influencing outcomes across multiple levels of leadership
  • Exceptional executive communication and stakeholder management skills, with the ability to translate complex technical risks into actionable business decisions for senior leaders, clients, auditors, regulators, and boards
  • Experience leading Vulnerability Management, Detection and Response (VMDR), Cloud Security Posture Management (CSPM), and SaaS Security Posture Management (SSPM) programs within large, complex, or regulated organizations is a plus
Education
  • Bachelor's degree in Computer Science, Engineering, Information Security, or a related field, or equivalent practical experience
  • Advanced degree (Master's degree or MBA) and/or relevant certifications such as CISSP, CSSLP, CISM, GWAPT, or OSCP are a plus
Responsibilities

Lead enterprise application security strategy and posture management capabilities to enable secure, resilient, and scalable software delivery.

  • Define, own, and evolve the enterprise Application Security strategy, roadmap, and operating model in alignment with business objectives and the broader cybersecurity program
  • Build, lead, and develop a global organization of Application Security, Product Security, and DevSecOps professionals, fostering innovation, accountability, and continuous learning
  • Embed security throughout the software development lifecycle by establishing secure-by-design and secure-by-default practices across engineering teams
  • Drive adoption of threat modeling, secure coding standards, secure design reviews, automated security testing, and software supply chain security controls
  • Provide strategic oversight for the enterprise Vulnerability Management, Detection and Response (VMDR) program, including risk-based prioritization, remediation governance, penetration testing, and security metrics reporting
  • Guide Cloud Security Posture Management (CSPM) and SaaS Security Posture Management (SSPM) capabilities in partnership with platform and engineering teams, supporting security baselines, guardrails, continuous monitoring, and remediation strategies
  • Consolidate application, cloud, and SaaS security findings into a unified view of enterprise risk, enabling data-driven prioritization and decision-making
  • Partner with Engineering, Product, Infrastructure, Risk, Legal, Privacy, Compliance, and executive stakeholders to strengthen security posture, regulatory readiness, and shared ownership of cyber risk
About The Team

The Cybersecurity Services Group (CSG) drives cybersecurity strategy and innovation across Moody's, enabling the business to deliver trusted products and services in a rapidly evolving digital landscape. By joining our team, you will help define the future of application security, lead transformative security initiatives at enterprise scale, and empower global teams to build secure, resilient, and innovative technology solutions.

For US-based roles only: the anticipated hiring base salary range for this position is $228,000 - $333,150.00, depending on factors such as experience, education, level, skills, and location. This range is based on a full-time position. In addition to base salary, this role is eligible for incentive compensation.

Moody’s also offers a competitive benefits package, including not but limited to

  • medical
  • dental
  • vision
  • parental leave
  • paid time off
  • 401(k) plan with employee and company contribution opportunities
  • life insurance
  • disability insurance
  • accident insurance
  • discounted employee stock purchase plan
  • tuition reimbursement

Moody’s is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, sex, gender, age, religion or creed, national origin, ancestry, citizenship, marital or familial status, sexual orientation, gender identity, gender expression, genetic information, physical or mental disability, military or veteran status, or any other characteristic protected by law. Moody’s also provides reasonable accommodation to qualified individuals with disabilities or based on a sincerely held religious belief in accordance with applicable laws. If you need to inquire about a reasonable accommodation, or need assistance with completing the application process, please email accommodations@moodys.com. This contact information is for accommodation requests only, and cannot be used to inquire about the status of applications

For San Francisco positions, qualified applicants with criminal histories will be considered for employment consistent with the requirements of the San Francisco Fair Chance Ordinance.

This position may be considered a promotional opportunity, pursuant to the Colorado Equal Pay for Equal Work Act.

Candidates for Moody's Corporation may be asked to disclose securities holdings pursuant to Moody’s Policy for Securities Trading and the requirements of the position. Employment is contingent upon compliance with the Policy, including remediation of positions in those holdings as necessary.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Vice President- Application Security
Senior Vice President- Application Security

Moody's Investors Service • New York (NY)

On-site
USD 228,000 - 333,000
Senior Vice President- Application Security
Senior Vice President- Application Security

Moody • Charlotte (NC)

On-site
USD 228,000 - 333,000
Senior Data Engineer- Cybersecurity
Senior Data Engineer- Cybersecurity

Moody • Golden (CO)

On-site
USD 117,000 - 169,000
Medical
Dental
Vision
+8
Senior Data Engineer- Cybersecurity
Senior Data Engineer- Cybersecurity

PassFort • Golden (CO)

On-site
USD 117,000 - 169,000
Senior Data Engineer- Cybersecurity
Senior Data Engineer- Cybersecurity

Moody's Corporation • Golden (CO)

On-site
USD 117,000 - 169,000
Medical insurance
Dental insurance
Vision insurance
+8
Senior IT Auditor- IT & Cyber
Senior IT Auditor- IT & Cyber

Moody's Investors Service • Charlotte (NC)

On-site
USD 82,000 - 120,000
Medical insurance
401(k) plan
Tuition reimbursement
+1
Staff Software Engineer
Staff Software Engineer

PassFort • Newark (CA)

On-site
USD 168,100 - 243,700
Medical, dental, and vision insurance
401(k) plan
Tuition reimbursement
+1
Senior Data Engineer- Cybersecurity
Senior Data Engineer- Cybersecurity

Koitecc Solutions • Golden (CO)

On-site
USD 117,000 - 169,000
Medical, dental, vision benefits
Parental leave
Paid time off
+3
Senior IT Auditor
Senior IT Auditor

Moody's Investors Service • Charlotte (NC)

On-site
USD 82,000 - 120,000
Medical, dental and vision insurance
401(k) plan with contributions
Tuition reimbursement
+1
Customer Success Mgmt Assoc
Customer Success Mgmt Assoc

PowerToFly • New York (NY)

On-site
USD 68,000 - 98,000
Medical, dental, vision
401(k) with company match
Tuition reimbursement
+1