Skills and Competencies
The Risk Management team within the Insurance Business Unit serves as the first line of defense, driving the adoption of effective risk management practices and fostering a strong culture of risk awareness. Working closely with engineering, product, and business stakeholders, the team proactively manages technology and operational risks, strengthens control environments, supports regulatory and customer expectations, and enables sustainable business growth.
- Proven experience in technology risk, operational risk, cybersecurity, or compliance within a regulated or enterprise environment, with expertise in identifying, assessing, and mitigating business and technology risks
- Strong knowledge of risk and control frameworks, including ISO 27001, SOC, NIST, COSO, GDPR, and related governance, risk, and compliance practices
- Experience managing vulnerability governance processes, validating remediation plans, monitoring control effectiveness, and reducing technology risk exposure
- Understanding of application security, secure software development lifecycle (SDLC), security-by-design principles, technical debt management, and infrastructure risk mitigation
- Strong analytical, problem-solving, and stakeholder management skills, with the ability to communicate complex technical risks to both technical and non-technical audiences
- Experience supporting audits, regulatory compliance activities, customer assurance programs, vendor risk assessments, and GRC platforms such as ServiceNow, Archer, OneTrust, or AuditBoard
- Bachelor's degree in Business, Risk Management, Computer Science, or a related discipline
- Professional certifications such as CISA, CRISC, CISSP, Security+, or ISO 27001 Lead Implementor/Auditor are preferred
- Identify, assess, monitor, and report technology, operational, and cybersecurity risks across the Insurance Business Unit to support business objectives and regulatory requirements
- Manage vulnerability governance processes, including remediation tracking, risk treatment validation, escalation management, and control gap closure
- Partner with engineering and product teams to embed secure development practices, vulnerability management, secure design principles, and testing standards
- Evaluate technology risk drivers, including technical debt, legacy platforms, infrastructure weaknesses, and control deficiencies, while supporting remediation prioritization
- Support governance, compliance, and assurance activities through control assessments, issue management, policy reviews, audit coordination, and framework alignment
- Contribute to customer assurance and commercial initiatives by supporting RFP responses, vendor assessments, security reviews, and customer due diligence activities
- Collaborate with stakeholders across engineering, cybersecurity, legal, compliance, and business teams to strengthen controls and improve risk outcomes
- Develop and maintain risk dashboards, metrics, and reporting capabilities that provide actionable insights for decision-making and continuous improvement
The Risk Management team within the Insurance Business Unit serves as the first line of defense, driving the adoption of effective risk management practices and fostering a strong culture of risk awareness. Working closely with engineering, product, and business stakeholders, the team proactively manages technology and operational risks, strengthens control environments, supports regulatory and customer expectations, and enables sustainable business growth.
Job ID 14452
About Moody's
In a world shaped by increasingly interconnected risks, Moody’s helps customers develop a holistic view of these risks to advance their ...
More Jobs From Moody's
Moody's
Singapore
Moody's
Singapore
Boost your career
Find thousands of job opportunities by signing up to eFinancialCareers today.More Jobs Like This