Senior Risk Management Analyst
Modernatx
via workday
Apply on company site ↗
CareerRiver pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Modernatx.
If you’re interested in this role, please apply in English and include an English version of your Resume/CV.
The Role:
Joining Moderna means advancing mRNA science to transform medicine. Work with exceptional global teams on a broad pipeline and build a career that makes a real difference for patients.
Moderna is strengthening its international business services hub in Warsaw, supporting our growing global operations. We welcome professionals ready to help advance our mission and shape the future of mRNA medicines.
Help shape the future of third-party cybersecurity risk management within a fast-moving, highly regulated biotechnology environment. In this role, you will drive robust governance across Moderna's third-party ecosystem, partnering with stakeholders across Digital, Legal, Privacy, Procurement, and the business to ensure cyber risks are understood, managed, and continuously improved.
You'll also help evolve the program by identifying opportunities to leverage auto
mation, Generative AI, and agentic workflows to create smarter, more scalable risk management capabilities.
Here's What You'll Do:
Own the end-to-end third-party cybersecurity risk review process, from intake and assessment scoping through risk analysis, stakeholder follow-up, remediation tracking, risk disposition, and governance reporting.
Review completed third-party cybersecurity assessments to identify control gaps, residual risks, compensating controls, remediation requirements, contractual considerations, and appropriate risk treatment recommendations.
Help strengthen Moderna's third-party cybersecurity risk management practices by supporting assessment scoping, risk analysis, control gap identification, stakeholder engagement, remediation tracking, governance reporting, process documentation, and cross-functional collaboration.
Support contract negotiations by reviewing, interpreting, and advising on cybersecurity addenda and associated cybersecurity control requirements, including incident notification, audit rights, vulnerability management, access control, encryption, logging and monitoring, subcontractor security, secure development, business continuity, and AI-enabled services where applicable.
Partner closely with Legal, Privacy, Procurement, business owners, and technical stakeholders to align third-party risk decisions, contractual obligations, remediation commitments, and governance expectations.
Help the organization understand third-party cybersecurity risk exposure by evaluating residual risk, identifying compensating controls, prioritizing remediation activities, supporting risk treatment decisions, and maintaining accurate, actionable third-party risk data within a GxP-regulated life sciences environment.
Analyze cybersecurity risk trends across assessments, vendors, services, AI capabilities, fourth-party dependencies, data classifications, and GxP impacts to continuously strengthen Moderna's third-party cybersecurity risk posture.
Support the adoption of AI, automation, and agentic workflows by documenting business requirements, decision logic, control expectations, evidence requirements, escalation points, and human oversight needs to enable scalable and mature third-party cybersecurity risk processes.
Translate third-party cybersecurity risk processes into clear operational requirements that improve governance, consistency, and automation opportunities across the program.
Contribute to governance reporting, process documentation, stakeholder communications, and continuous improvement initiatives that enhance cybersecurity risk management maturity.
Perform additional responsibilities and special projects as required.
The key Moderna Mindsets you’ll need to succeed in the role:
We obsess over learning. We don’t have to be the smartest we have to learn the fastest.
We digitize everywhere possible using the power of code to maximize our impact on patients.
Here’s What You’ll Bring to the Table (Minimum Qualifications)
5+ years of experience in a similar or related position, including experience with standard concepts within cybersecurity risk management, third-party risk management, or GRC.
Experience owning or supporting third-party cybersecurity risk reviews, including assessment analysis, risk disposition, remediation tracking, documentation, reporting, and cybersecurity addendum support during contract negotiations.
Sound judgment to identify when risks, control gaps, contractual concerns, or remediation delays require escalation to drive timely decision-making and appropriate risk treatment.
Experience working in a GxP-regulated environment is required.
Strong written and verbal communication skills, including the ability to communicate cybersecurity risk concepts and control expectations to technical and non-technical stakeholders.
Experience using AI to optimize, augment, or streamline risk analysis, documentation, reporting, workflow management, or stakeholder communications.
Proven ability to operate in highly matrixed environments and influence without direct authority.
Preferred Qualifications (Preferred Qualifications):
Four-year degree or equivalent relevant work experience preferred, ideally in information systems, cybersecurity, or risk management.
Familiarity with third-party cybersecurity risk frameworks and assessment standards such as NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks.
Experience with GRC, workflow, reporting, and collaboration tools such as OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools.
Strong attention to detail and commitment to data integrity, auditability, consistent documentation, and transparent risk reporting.
Influential, inclusive, and trusted partner compassionate to the needs and situations of all your stakeholders
Embrace a culture of continuous service improvement and service excellence
Browse all locations