Senior Vice President- Application Security
Job in
Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listed on 2026-08-25
Listing for:
Moody's Corporation
Full Time
position Listed on 2026-08-25
Job specializations:
-
IT/Tech
Cybersecurity, Security Management & Operations, Information Security & Data Protection
Job Description & How to Apply Below
At Moody's, we unite the brightest minds to turn today’s risks into tomorrow’s opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are—with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moody’s is transforming how the world sees risk. As a global leader in ratings and integrated risk assessment, we’re advancing AI to move from insight to action—enabling intelligence that not only understands complexity but responds to it.
SkillsAnd Competencies
- 15+ years of progressive cybersecurity experience, including significant leadership experience in Application Security, Product Security, or related security disciplines
- Deep expertise in secure software development lifecycle practices, threat modeling, secure architecture and design reviews, secure coding standards, OWASP Top 10, CWE, and modern application security programs
- Strong software engineering background with the ability to review and assess production code and influence engineering organizations as a trusted technical leader
- Proven experience implementing and scaling Dev Sec Ops practices, including security automation, AI-enabled security capabilities, SAST, DAST, IAST, SCA, CI/CD security integration, and software supply chain security controls; experience leveraging AI to enhance security operations, risk identification, and engineering efficiency is preferred
- Strong knowledge of modern technology architectures including cloud-native environments, microservices, containers, Kubernetes, APIs, and SaaS platforms
- Demonstrated success building and leading high-performing global teams, driving enterprise-wide security transformation, and influencing outcomes across multiple levels of leadership
- Exceptional executive communication and stakeholder management skills, with the ability to translate complex technical risks into actionable business decisions for senior leaders, clients, auditors, regulators, and boards
- Experience leading Vulnerability Management, Detection and Response (VMDR), Cloud Security Posture Management (CSPM), and SaaS Security Posture Management (SSPM) programs within large, complex, or regulated organizations is a plus
- Bachelor's degree in Computer Science, Engineering, Information Security, or a related field, or equivalent practical experience
- Advanced degree (Master's degree or MBA) and/or relevant certifications such as CISSP, CSSLP, CISM, GWAPT, or OSCP are a plus
Lead enterprise application security strategy and posture management capabilities to enable secure, resilient, and scalable software delivery.
- Define, own, and evolve the enterprise Application Security strategy, roadmap, and operating model in alignment with business objectives and the broader cybersecurity program
- Build, lead, and develop a global organization of Application Security, Product Security, and Dev Sec Ops professionals, fostering innovation, accountability, and continuous learning
- Embed security throughout the software development lifecycle by establishing secure-by-design and secure-by-default practices across engineering teams
- Drive adoption of threat modeling, secure coding standards, secure design reviews, automated security testing, and software supply chain security controls
- Provide strategic oversight for the enterprise Vulnerability Management, Detection and Response (VMDR) program, including risk-based prioritization, remediation governance, penetration testing, and security metrics reporting
- Guide Cloud Security Posture Management (CSPM) and SaaS Security Posture Management (SSPM) capabilities in partnership with platform and engineering teams, supporting security baselines, guardrails, continuous monitoring, and remediation strategies
- Consolidate application, cloud, and SaaS security findings into a unified view of enterprise risk, enabling data-driven prioritization and decision-making
- Partner with Engineering, Product, Infrastructure, Risk, Legal, Privacy, Compliance, and executive stakeholders to strengthen security posture, regulatory readiness, and shared ownership of cyber risk
Position Requirements
10+ Years
work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×