Assc Dir-Risk Management

3 hours ago


Noida, Uttar Pradesh, India Moody's Full time ₹ 10,00,000 - ₹ 25,00,000 per year
At Moody's, we unite the brightest minds to turn today's risks into tomorrow's opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are-with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways.
If you are excited about this opportunity but do not meet every single requirement, please apply You still may be a great fit for this role or other open roles. We are seeking candidates who model our values: invest in every relationship, lead with curiosity, champion diverse perspectives, turn inputs into actions, and uphold trust through integrity.
Skills and Competencies:
  • Excellent verbal and written communication skills. Ability to handle negotiations and difficult conversations.
  • Organized, attentive to detail, and able to prioritize and meet deadlines.
  • Strong analytical, problem-solving, collaboration, and project management skills.
  • Knowledge of IT and cyber controls and frameworks (SOC 1 and SOC 2, C5, NIST, ISO 27001, COBIT).
  • 8 to 10 years' experience in IT audit, enterprise risk management, information security, or vendor risk management.
  • Familiarity with software development practices and enterprise technology operations, particularly in public cloud environments.
  • Proficient with Microsoft Office applications; familiarity with GRC platforms.
  • CISA, CRISC, CISSP, PMP certification or equivalent experience.
Education
  • Minimum Bachelor's degree in Engineering or related major from top institutions, Master's degree is a plus.
Responsibilities This role will support our risk management and compliance efforts, with a primary focus on assisting in managing SOC1/SOC2/C5, ISO audits, and customer audits of Insurance BU's software products and services. This role will also support technology and cyber risk assessments and monitoring risk remediation activities. Responsibilities include:
  • Assist in SOC1/SOC2/C5 Audits: Collaborate with product teams to assist in the preparation, coordination, and execution of SOC1, SOC2 and C5 audits. This includes gathering relevant documentation, conducting internal assessments, and liaising with external auditors.
  • Support ISO Audits: Assist in the management of ISO audits by helping to maintain compliance with ISO standards (e.g., ISO Contribute to the development and maintenance of policies, procedures, and controls in alignment with ISO requirements.
  • Perform Technology and Cyber Risk Assessments: Perform internal technology and cyber risk assessments of products and services. Identify vulnerabilities, threats, and potential risks to our products and services. Work with product, technology and cybersecurity teams to mitigate identified risks.
  • Risk Remediation Monitoring: Monitor and track the progress of risk remediation activities. Collaborate with stakeholders to ensure timely and effective remediation of identified risks and issues.
  • Third-Party & Vendor Risk Management: Conduct due diligence assessments of vendors, review their security posture, and track risk remediation efforts. Integrate vendor risks into overall ERM reporting.
  • Vulnerability Management: Oversee vulnerability identification, assessment, prioritization, and remediation efforts, working closely with engineering and operations teams. Establish and track key metrics to measure reduction of vulnerabilities and residual risk.
  • Application security/product security: Lead the strategy and execution of application security risk management, ensuring security is embedded across the SDLC.
    Documentation and Reporting: Maintain accurate and up-to-date records of audit activities, findings, and remediation efforts. Assist in the preparation of audit reports and documentation for internal and external stakeholders.
  • Compliance Monitoring: Support ongoing compliance efforts by monitoring adherence to policies, procedures, and regulatory requirements. Collaborate with teams across the organization to identify areas of improvement and assist in implementing necessary changes. Support efforts to automate and improve monitoring efficiency and coverage.
  • Training and Awareness: Participate in training sessions related to risk management, compliance, and audit processes. Assist in raising awareness of compliance requirements within the organization.
About the team Risk management team within Insurance BU group oversees Insurance BU risk management framework and implements its risk management activities, with the objectives of safeguarding sensitive business data, protecting data privacy, addressing information security threats, ensuring legal and regulatory compliance, meeting customer requirements for controls assurance, and promoting risk awareness. The team collaborates with lines of business across MA risk management team and Moody's Shared Services to reduce risk to acceptable levels while enabling business priorities.
Moody's is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender expression, gender identity or any other characteristic protected by law.

Candidates for Moody's Corporation may be asked to disclose securities holdings pursuant to Moody's Policy for Securities Trading and the requirements of the position. Employment is contingent upon compliance with the Policy, including remediation of positions in those holdings as necessary.


  • Risk Manager

    7 days ago


    Noida, Uttar Pradesh, India Krishna Enterprise's Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    We are looking for a Risk Manager to advise us on various types of risks (business, financial, legal and security.) You will identify potential threats and create plans to prevent and mitigate problems.In this role, you should be highly perceptive and methodical. You should also have the ability to communicate effectively and present your plans in a...

  • Risk Management

    2 weeks ago


    Noida, Uttar Pradesh, India Allianz Insurance Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Job PurposeUnder the guidance of senior management, the IT General Control Testing Lead will be responsible for overseeing the planning and execution of IT General Controls (ITGC) testing. This includes the collection and review of evidence, coordination with service owners and Allianz Technology (AZ Tech) for any missing documentation, and ensuring timely...


  • Noida, Uttar Pradesh, India EXL Full time ₹ 15,00,000 - ₹ 25,00,000 per year

    Qualifications:Bachelors degree in business, Information Technology, Risk Management, Finance, or related field is mandatory; Masters degree or relevant certifications are strongly preferred4–10 years of experience in TPRM, vendor risk management, or related domainsStrong understanding of third-party risk lifecycle management, enterprise risk management...


  • Noida, Uttar Pradesh, India Capgemini Full time ₹ 5,00,000 - ₹ 15,00,000 per year

    Role & responsibilitiesRole ObjectivesEnsures that all Third-Party Risk Management (TPRM) Policies & Procedures are adhered to in the execution of the program throughout the full TPRM Lifecycle through the completion of the responsibilities defined below.Primary TPRM support partner for Subject Matter Experts (SMEs), Third Party Business Representatives...


  • Noida, Uttar Pradesh, India Capgemini Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    YOUR ROLE  We are seeking a talented and driven Third-Party Management Operations role to join our team. The ideal candidate will be responsible for collecting, analysing, and interpreting complex data sets to drive informed business decisions. You will work closely & Directly with the Client & cross-functional teams to identify trends, patterns, and...


  • Noida, Uttar Pradesh, India Allianz Insurance Full time ₹ 9,00,000 - ₹ 12,00,000 per year

    Job Details / Role Purpose:This role consists of supporting the organization's efforts to manage non-financial risks effectively. As a Non-financial Risk Management (NFRM) professional, you will be part of a collaborative team, assisting in the identification and assessment of risks, implementing risk management frameworks, and supporting the development of...


  • Noida, Uttar Pradesh, India Capgemini Full time ₹ 6,00,000 - ₹ 18,00,000 per year

    Choosing Capgemini means choosing a company where you will be empowered to shape your career in the way you'd like, where you'll be supported and inspired by a collaborative community of colleagues around the world, and where you'll be able to reimagine what's possible. Join us and help the world's leading organizations unlock the value of technology and...


  • Noida, Uttar Pradesh, India Allianz Full time ₹ 5,00,000 - ₹ 12,00,000 per year

    Job Details / Role Purpose: This role consists of supporting the organization's efforts to manage non-financial risks effectively. As a Non-financial Risk Management (NFRM) professional, you will be part of a collaborative team, assisting in the identification and assessment of risks, implementing risk management frameworks, and supporting the...


  • Noida, Uttar Pradesh, India Capgemini Full time ₹ 6,00,000 - ₹ 12,00,000 per year

    Role DescriptionThe Third-Party Management Operations role will be joining our Third Party Management Operations team, which sits within the Procurement organization, to work with business units throughout the SMBC Americas Division to identify and manage the risks facing the organization through its use of third-party service providers. In this role, you...


  • Noida, Uttar Pradesh, India UKG Full time ₹ 12,00,000 - ₹ 36,00,000 per year

    About the roleWe are seeking a Director of Product, to play a pivotal role in shaping and executing our product strategy, driving innovation, and leading a talented team of product managers within our Unified Platform team. This role will lead a team of Product Managers, coaching and developing the team to identify, design, deliver and execute on the...