Sr Cybersecurity Engineer (IDAM)
Moody's
- Location
- New York, NY
- Work model
- On-Site
- Level
- Senior
- Salary
- $116.5k – $192.3k/yr
Skills
About this role
At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are—with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody’s is transforming how the world sees risk. As a global leader in ratings and integrated risk assessment, we’re advancing AI to move from insight to action—enabling intelligence that not only understands complexity but responds to it. We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed, and confidence. If you are excited about this opportunity but do not meet every single requirement, please apply! You still may be a great fit for this role or other open roles. We are seeking candidates who model our values: invest in every relationship, lead with curiosity, champion diverse perspectives, turn inputs into actions, and uphold trust through integrity. Skills and Competencies 3+ years of hands-on access management engineering experience, including workforce identity configuration, administration, and lifecycle management (Okta preferred) Strong depth in core Identity and Access Management and Single Sign-On protocols and application integration patterns — SAML, OIDC, and SCIM Experience engineering authentication and multi-factor authentication policy using phishing-resistant methods Hands-on experience with identity lifecycle and provisioning automation Experience operating in regulated, audited environments (SOX/ITGC, FedRAMP, or equivalent), including producing audit evidence and control documentation Working knowledge of identity governance concepts — access requests, certifications, separation of duties; Okta Identity Governance experience is preferred Familiarity with Microsoft Entra ID administration, including Conditional Access policy engineering and hybrid identity management, is preferred Strong written communication skills for producing audit-ready documentation and evidence packages Ability to independently lead end-to-end engineering work from requirements through operational support Demonstrated proficiency in artificial intelligence concepts, with hands-on experience using AI tools to streamline workflows and enhance operational efficiency. Proven ability to implement AI-powered solutions to solve business challenges. Demonstrates a growing awareness of AI risk management and a commitment to responsible and ethical AI use.
Education
Bachelor's degree or equivalent qualification in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field Advanced technical certifications preferred, such as Okta Certified Administrator/Professional (Consultant a plus), Microsoft Certified: Identity and Access Administrator (SC-300), CISSP, or equivalent identity/security certifications Prior FedRAMP or US federal identity/compliance experience preferred Responsibilities This role supports Identity and Access Management initiatives end to end — including access management design, engineering, configuration, operations, audit evidence, and Cloud Identity and Access Management engineering and operations. Own end-to-end engineering, configuration, and administration of workforce identities in Moody's Okta tenants, including the FedRAMP workforce, non-production, and Customer Identity and Access Management tenants, applying established standards and requirements Design and maintain Single Sign-On and application integrations using SAML, OIDC, and SCIM across enterprise applications Engineer authentication and multi-factor authentication policy to enforce a phishing-resistant assurance level Own identity lifecycle (joiner/mover/leaver) and provisioning workflows, including automation via Okta Workflows Monitor and respond to identity risk signals and threats Design and administer groups, custom admin roles, and least-privilege