(Application Security Testing) DevOps Engineer
Moody's
- Location
- India
- Level
- Entry
Skills
About this role
At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are—with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody’s is transforming how the world sees risk. As a global leader in ratings and integrated risk assessment, we’re advancing AI to move from insight to action—enabling intelligence that not only understands complexity but responds to it. We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed, and confidence. If you are excited about this opportunity but do not meet every single requirement, please apply! You still may be a great fit for this role or other open roles. We are seeking candidates who model our values: invest in every relationship, lead with curiosity, champion diverse perspectives, turn inputs into actions, and uphold trust through integrity. Skills and Competencies 1-3 years of experience conducting application security reviews including static application security testing, dynamic application security testing, and penetration testing. Strong knowledge of secure software development practices, threat modeling, and secure architecture design Ability to assess security risks within applications and provide practical remediation guidance Understanding of network and web protocols including Transmission Control Protocol/Internet Protocol, User Datagram Protocol, Internet Protocol Security, Hypertext Transfer Protocol, and Hypertext Transfer Protocol Secure Experience securing cloud environments including Amazon Web Services, Microsoft Azure, and other public cloud platforms Proficiency in one or more programming languages such as Java, C++, Python, Ruby, or Perl Strong communication and stakeholder management skills with the ability to influence technical decisions and build partnerships with development teams Demonstrated proficiency in artificial intelligence concepts, with hands-on experience using AI tools to streamline workflows and enhance operational efficiency. Proven ability to implement AI-powered solutions to solve business challenges. Demonstrates a growing awareness of AI risk management and a commitment to responsible and ethical AI use.
Education
Bachelor’s degree in computer science, Information Security, Engineering, or a related field, or equivalent practical experience Responsibilities Partner with product and engineering teams to embed security into the software development lifecycle and drive proactive risk management. Conduct application security reviews including static application security testing, dynamic application security testing, and penetration testing activities Perform threat modeling exercises and provide recommendations to address identified risks Design and review secure architectures for applications, services, and cloud-based solutions Develop security guidance, standards, and documentation for internal development teams Deliver security metrics, analyze trends, and identify opportunities for continuous improvement Build strong relationships with product and engineering teams to promote security best practices and awareness Drive security risk assessments and support risk-based decision making across projects and initiatives Influence technical architecture decisions to ensure security requirements are effectively incorporated into solutions About the Team Team is responsible for protecting applications, platforms, and data across the organization by embedding security throughout the development lifecycle. The team partners closely with engineering and product stakeholders to identify risks, strengthen security controls, and drive adoption of secure-by-design principles. By joining this team, you will contribute to securing innovative technology solutions, enhancing organizational resilience, and supporting