At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are—with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody’s is transforming how the world sees risk. As a global leader in ratings and integrated risk assessment, we’re advancing AI to move from insight to action—enabling intelligence that not only understands complexity but responds to it. We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed, and confidence.
If you are excited about this opportunity but do not meet every single requirement, please apply! You still may be a great fit for this role or other open roles. We are seeking candidates who model our values: invest in every relationship, lead with curiosity, champion diverse perspectives, turn inputs into actions, and uphold trust through integrity.
Skills and Competencies
-
2-4 years of experience in AI risk management, AI governance, technology risk, model risk, IT audit, information security, GRC, or a related discipline, ideally withinfinancial services, a Big Four firm, or a global organization
-
Experience assessing AI solutions, AI-enabled applications, agents, and emerging technologies, with the ability to evaluate risks, controls, and supporting evidence to develop clear, defensible conclusions
-
Strong knowledge of AI risk concepts, including prompt injection, hallucinations, sensitive data exposure, bias, explainability, model drift, shadow AI, third-party dependencies, and human oversight requirements
-
Familiarity with AI governance, risk, and compliance frameworks such as NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP Top 10 for LLM Applications, and other evolving regulatory standards
-
Ability to communicate complex technical and risk concepts effectively to both technical and non-technical stakeholders while collaborating across technology, cybersecurity, legal, compliance, privacy, procurement, and business teams
-
Working understanding of AI technologies, cloud environments, APIs, integrations, access controls, data flows, and automation tools, with proficiency in Microsoft Office and exposure to platforms such as Power BI, Power Automate, ServiceNow, OpenPages, OneTrust, or Microsoft Copilot
Education
-
Bachelor’s degree in Computer Science, Information Systems, Engineering, or a related discipline
-
Professional certifications such as ISO/IEC 42001 Lead Auditor/Implementer, ISO/IEC 27001 Lead Auditor/Implementer, CISA, AAIA, AISM, AAIR, CISSP, or CRISC are preferred
Responsibilities
-
Execute end-to-end control assessments, including planning, walkthroughs, evidence reviews, testing, issue validation, and reporting activities.
-
Conduct AI risk assessments for AI tools, AI-enabled applications, agents, connectors, plugins, and model-driven solutions to evaluate governance, security, data exposure, autonomy, and oversight controls
-
Analyze vendor assurance documentation, including SOC reports, ISO certifications, trust-center materials, security documentation, and technical architecture evidence to assess risk and compliance posture
-
Develop and review Risk and Control Self-Assessments (RCSAs), documenting risk statements, control mappings, effectiveness evaluations, evidence-based conclusions, and residual risk assessments
-
Support ISO/IEC 27001:2022 readiness reviews, internal audits, and continuous control monitoring activities by evaluating policies, procedures, technical configurations, and operational evidence
-
Prepare clear and actionable assessment reports, identifying findings, risks, observations, and improvement opportunities supported by appropriate evidence and recommendations
-
Partner with control owners, product teams, technology teams, and risk stakeholders to facilitate assessments, communicate outcomes, and drive remediation efforts and maintain accurate assessment documentation, workpapers, issue logs, evidence repositories, and governance reporting within approved GRC and collaboration platforms
-
Leverage data analytics, automation, and approved AI tools to enhance assessment efficiency, reporting quality, consistency, and operational effectiveness and stay informed on emerging developments in AI, cybersecurity, regulatory requirements, and risk management practices, translating insights into practical control assessment approaches
About the Team
Our Internal Controls team plays a critical role in strengthening Moody’s control environment by evaluating and enhancing the effectiveness of controls that mitigate financial, cybersecurity, operational, and emerging technology risks. We partner with stakeholders across the organization to drive compliance, resilience, and continuous improvement through a disciplined and risk-focused approach.
As part of this team, you will have the opportunity to work on innovative AI governance and risk initiatives, collaborate with global teams, and contribute to the development of a robust control framework that supports Moody’s strategic objectives. This role offers strong exposure to emerging technologies, ongoing professional development, and the opportunity to make a meaningful impact in a rapidly evolving risk landscape
Moody’s is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender expression, gender identity or any other characteristic protected by law.
Candidates for Moody's Corporation may be asked to disclose securities holdings pursuant to Moody’s Policy for Securities Trading and the requirements of the position. Employment is contingent upon compliance with the Policy, including remediation of positions in those holdings as necessary.