10 дней назад
Senior Third Party Risk Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Third Party Risk Analyst (Cybersecurity): Managing end-to-end third-party cybersecurity risk reviews in a regulated life sciences environment with an accent on risk analysis, remediation tracking, contractual controls, and AI-enabled services. Focus on evaluating residual risks, strengthening GRC processes, and translating cybersecurity requirements into scalable governance and oversight.
Location: Warsaw, Poland; hybrid 70/30 work model with 70% in-office collaboration.
Company
develops mRNA-based medicines, vaccines, and related technologies for infectious diseases, immuno-oncology, rare diseases, and cardiovascular diseases.
What you will do
- Own the end-to-end third-party cybersecurity risk review process, including intake, scoping, assessment, risk disposition, remediation tracking, reporting, and documentation.
- Review third-party assessments to identify control gaps, residual risks, compensating controls, contractual requirements, and remediation needs.
- Review and advise on cybersecurity contract addenda covering incident notification, audit rights, vulnerability management, access control, encryption, monitoring, subcontractors, secure development, business continuity, and AI-enabled services.
- Partner with Legal, Privacy, Procurement, business owners, and technical stakeholders on risk decisions and contractual obligations.
- Analyze vendor, fourth-party, AI, data classification, and GxP-related cybersecurity risks and support risk treatment decisions.
- Improve governance processes by defining requirements, evidence standards, escalation criteria, automation opportunities, and appropriate AI oversight.
Requirements
- 5+ years of experience in cybersecurity risk management, third-party risk management, GRC, or a related role.
- Experience with third-party cybersecurity assessments, risk disposition, remediation tracking, reporting, documentation, and cybersecurity contract addenda.
- Experience in a GxP-regulated environment is required.
- Experience using AI to optimize or streamline risk analysis, documentation, reporting, workflows, or stakeholder communications.
- Strong written and verbal communication skills, with the ability to explain cybersecurity risks to technical and non-technical stakeholders.
- Ability to work in highly matrixed environments and influence without direct authority; English is required for the application and role communication.
Nice to have
- Four-year degree or equivalent relevant experience in information systems, cybersecurity, or risk management.
- Familiarity with NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks.
- Experience with OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools.
- Strong focus on data integrity, auditability, consistent documentation, and transparent risk reporting.
Culture & Benefits
- 70/30 in-office work model focused on collaboration, innovation, teamwork, and mentorship.
- Healthcare and voluntary benefit programs, with offerings varying by employment type and country.
- Fitness, mindfulness, mental health, family-building, fertility, adoption, and surrogacy support.
- Paid time off including vacation, bank holidays, volunteer days, sabbatical, global recharge days, and year-end shutdown.
- Savings and investment programs plus location-specific benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Senior Risk Analyst, Privacy & Third-Party Risk
87 000 - 148 000$
11 дней назад
Cyber Specialist (Cybersecurity)
CoreWeave
12 дней назад
Senior Technical Program Manager, Third Party Risk Management
157 000 - 210 000$
13 дней назад
Lead Security Analyst - GRC (Cybersecurity)
172 500 - 215 625$
CoreWeave
12 дней назад
Technical Program Manager, Third Party Risk Management
157 000 - 210 000$
10 дней назад
Security GRC Analyst II (Cybersecurity)
130 000 - 135 000$