• Competitive
  • Edinburgh, Scotland, United Kingdom
  • Permanent, Full time
  • Moody's
  • 2018-05-24

Cybersecurity Analytics Analyst (SPLUNK)

Location: Edinburgh, Scotland, United Kingdom

Job Description

Moody's Information Risk team is looking for a Cybersecurity Analyst to join its growing organization.
The Cybersecurity Analyst will be responsible for working with Moody's Cybersecurity's SIEM platform based on Splunk and owning the health, accuracy and maintenance of the application on a go forward basis. The individual will be responsible for architecting upgrades and proactively seeking out improvements to the application while working with operations and support teams to implement these upgrades and enhancements. This role will also involve designing Splunk queries that assist the cybersecurity department in identifying potentially malicious activity and assisting other teams at Moody's to make better data driven decisions using Splunk. This role will also involve the development of dashboards and reports in Splunk to assist with compliance to regulation and identifying security control failures. The individual will also be expected to work closely with the operations team to onboard new security related data sources.
This position requires technical background in Information Security practice, and solid communication and organization skills. The successful candidate is very motivated and willing to take on challenges, able to multi-task to succeed and has the ability work independently and with minimal oversight.
The Moody's Information Security team is responsible for helping the organization balance risk by aligning policies and procedures with Moody's business requirements. The team is responsible for the development, enforcement and monitoring of security controls, policies and procedures, and for the delivery of security services. The Information Security team sets strategic direction for security within the organization and aligns with stakeholders throughout the company.

Functional Responsibilities
  • Work as part of the Cybersecurity Analytics program, assisting various departments and individuals at Moody's to onboard new data sources into the SEIM.
  • Own the health and maintenance of the Splunk platform, providing clear guidance and direction to operations teams when managing and improving the application.
  • Work with other Cybersecurity teams such as Incident Response.
  • Keep current on external and internal threat behaviors. Translate these behaviors into Splunk search language queries in the SIEM platform.
  • Work with the Moody's SOX team to help Moody's remain in compliance with SOX using custom reports, alerts and dashboards in Splunk.
  • Construct advanced reports, dashboards and alerts using Splunk and operationalize these capabilities with documentation in the form of standard operating procedures.
  • Ability to exercise sound technical, interpersonal and organizational judgment while evaluating and solving complex problems.
  • Partner with system owners to identify upcoming end of life components, and plan track their decommissioning.


With 400 employees and 800 contractors worldwide, Moody's Shared Services provides technology solutions for Moody's Investors Service, Moody's Shared Services and Moody's Analytics. The organization is going through an exciting period of growth and opportunity as we embark on a corporate-wide Transformation program and partner with the business to drive revenue growth, efficiency, risk management, and expansion of our client base via new solutions and application modernization. The development and ongoing support of key ratings and enterprise systems ensure the company's premier standing among credit rating agencies and enable its evolution alongside regulatory and business demands.

MIT continuously seeks talented individuals to drive the execution of its enterprise technology roadmap, which offers exciting career opportunities across the application delivery lifecycle, architecture, software and platform engineering, IT security and risk management, infrastructure and technology operations, vendor management, and service management.

#LI-DL1

Qualifications

Minimum education and work experience required for this position include:
  • Significant experience in the IT industry, preferably in a financial services organization.
  • Relevant experience in direct security analytics or big data analysis.
  • Expert knowledge of regular expressions and at least one common scripting language (PERL, Python, VB Script).
  • Demonstrated advanced knowledge of the Splunk architecture planning, administration, search language, search techniques, alerts, dashboard and report building.
  • BS or BA degree, preferably in Computer Science, other sciences.
  • Relevant certifications such as CISSP are a plus.
  • Proficiency in a second language is a plus, especially Mandarin, Korean, Japanese or Russian.

Key Competencies
  • Strong knowledge of regulatory standards that govern Information Security Incident Response and Investigation practices such as state and federal privacy laws, Electronic Communications Privacy Act.
  • Hands-on experience using SIEM platforms including Splunk. Expert level of familiarity with SIEM search languages, including mathematical and statistical functions.
  • Hands-on experience managing SEIM platforms including Splunk. Strong familiarity with Splunk architecture, implementation, management and maintenance.
  • Reasonable understanding of Indicators of Compromise and other methodologies to detect incident-related anomalies.
  • Must understand and be familiar with modeling security related data concepts, such as net flow, Web browsing, authentication, email flow, etc.
  • Good written and oral communication skills including the ability to interact directly with customers that do not have an IT background.
  • Proven ability to work within a large enterprise that spans multiple continents, is governed by change management and has a tiered support model.
  • Reporting and dashboards - must be able to create reports and dashboards that represent significant data findings to both technical and executive audiences.
  • Ability to work in a time-sensitive environment; must be detail oriented and able to multitask to meet deadlines and company objectives


Moody's is an essential component of the global capital markets, providing credit ratings, research, tools and analysis that contribute to transparent and integrated financial markets. Moody's Corporation (NYSE: MCO) is the parent company of Moody's Investors Service, which provides credit ratings and research covering debt instruments and securities, and Moody's Analytics, which offers leading-edge software, advisory services and research for credit and economic analysis and financial risk management. The Corporation, which reported revenue of $4.2 billion in 2017, employs approximately 11,900 people worldwide and maintains a presence in 41 countries. Further information is available at www.moodys.com.

Moody's is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation or any other characteristic protected by law.

Candidates for Moody's Corporation may be asked to disclose securities holdings pursuant to Moody's Policy for Securities Trading and the requirements of the position. Employment is contingent upon compliance with the Policy, including remediation of positions in those holdings as necessary.

Edinburgh, Scotland, United Kingdom Edinburgh Scotland GB