Controls Analyst
Moody's
| Company | Moody's |
| Category | Operations & Admin |
| Location | Gurugram, Haryana |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Mid |
| Salary | INR 260k–600k |
| Posted | 10 Aug 2026 |
| Last verified | 12 Aug 2026 |
| Source | The employer's own careers page (company_site) |
Description
At Moodys, we unite the brightest minds to turn todays risks into tomorrows opportunities. We do this by striving to create an inclusive environment where everyone feels welcome to be who they are—with the freedom to exchange ideas, think innovatively, and listen to each other and customers in meaningful ways. Moodys is transforming how the world sees risk. As a global leader in ratings and integrated risk assessment, were advancing AI to move from insight to action—enabling intelligence that not only understands complexity but responds to it. We decode risk to unlock opportunity, helping our clients navigate uncertainty with clarity, speed, and confidence.If you are excited about this opportunity but do not meet every single requirement, please apply! You still may be a great fit for this role or other open roles. We are seeking candidates who model our values: invest in every relationship, lead with curiosity, champion diverse perspectives, turn inputs into actions, and uphold trust through integrity.Skills And Competencies2-4 years of experience in AI risk management, AI governance, technology risk, model risk, IT audit, information security, GRC, or a related discipline, ideally withinfinancial services, a Big Four firm, or a global organizationExperience assessing AI solutions, AI-enabled applications, agents, and emerging technologies, with the ability to evaluate risks, controls, and supporting evidence to develop clear, defensible conclusionsStrong knowledge of AI risk concepts, including prompt injection, hallucinations, sensitive data exposure, bias, explainability, model drift, shadow AI, third-party dependencies, and human oversight requirementsFamiliarity with AI governance, risk, and compliance frameworks such as NIST AI RMF, ISO/IEC 42001, EU AI Act, OWASP Top 10 for LLM Applications, and other evolving regulatory standardsAbility to communicate complex technical and risk concepts effectively to both technical and non-technical stakeholders while collaborating across technology, cybersecurity, legal, compliance, privacy, procurement, and business teamsWorking understanding of AI technologies, cloud environments, APIs, integrations, access controls, data flows, and automation tools, with proficiency in Microsoft Office and exposure to platforms such as Power BI, Power Automate, ServiceNow, OpenPages, OneTrust, or Microsoft CopilotEducationBachelors degree in Computer Science, Information Systems, Engineering, or a related disciplineProfessional certifications such as ISO/IEC 42001 Lead Auditor/Implementer, ISO/IEC 27001 Lead Auditor/Implementer, CISA, AAIA, AISM, AAIR, CISSP, or CRISC are preferredResponsibilitiesExecute end-to-end control assessments, including planning, walkthroughs, evidence reviews, testing, issue validation, and reporting activities.Conduct AI risk assessments for AI tools, AI-enabled applications, agents, connectors, plugins, and model-driven solutions to evaluate governance, security, data exposure, autonomy, and oversight controlsAnalyze vendor assurance documentation, including SOC reports, ISO certifications, trust-center materials, security documentation, and technical architecture evidence to assess risk and compliance postureDevelop and review Risk and Control Self-Assessments (RCSAs), documenting risk statements, control mappings, effectiveness evaluations, evidence-based conclusions, and residual risk assessmentsSupport ISO/IEC 27001:2022 readiness reviews, internal audits, and continuous control monitoring activities by evaluating policies, procedures, technical configurations, and operational evidencePrepare clear and actionable assessment reports, identifying findings, risks, observations, and improvement opportunities supported by appropriate evidence and recommendationsPartner with control owners, product teams, technology teams, and risk stakeholders to facilitate assessments, communicate outcomes, and drive remediation efforts and maintain accurate assessment documentation, workpapers, issue logs, evidence repositories, and governance reporting within approved GRC and collaboration platformsLeverage data analytics, automation, and approved AI tools to enhance assessment efficiency, reporting quality, consistency, and operational effectiveness and stay informed on emerging developments in AI, cybersecurity, regulatory requirements, and risk management practices, translating insights into practical control assessment approachesAbout The TeamOur Internal Controls team plays a critical role in strengthening Moodys control environment by evaluating and enhancing the effectiveness of controls that mitigate financial, cybersecurity, operational, and emerging technology risks. We partner with stakeholders across the organization to drive compliance, resilience, and continuous improvement through a disciplined and risk-focused approach.As part of this team, you will have the opportunity to work on innovative AI governance and risk initiatives, collaborate with global teams, and contribute to the development of a robust control framework that supports Moodys strategic objectives. This role offers strong exposure to emerging technologies, ongoing professional development, and the opportunity to make a meaningful impact in a rapidly evolving risk landscapeMoodys is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability, protected veteran status, sexual orientation, gender expression, gender identity or any other characteristic protected by law.Candidates for Moodys Corporation may be asked to disclose securities holdings pursuant to Moodys Policy for Securities Trading and the requirements of the position. Employment is contingent upon compliance with the Policy, including remediation of positions in those holdings as necessary.