Назад
Company hidden
7 дней назад

Senior Risk Management Analyst (AI)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Risk Management Analyst (AI) (Cybersecurity/GRC): Assessing and monitoring technology, cybersecurity, digital, and emerging risks across applications, infrastructure, data, third parties, AI, and GxP-regulated environments with an accent on control evaluations, remediation tracking, governance reporting, and auditable risk data. Focus on translating AI, automation, agentic workflows, and digital platform risks into documented requirements, decision logic, controls, evidence, and human oversight.

Location: Warsaw, Poland, or Cambridge, Massachusetts, United States; 70% in-office and 30% remote

Company

hirify.global is a biotechnology company developing mRNA-based medicines and vaccines across infectious diseases, immuno-oncology, rare diseases, and cardiovascular diseases.

What you will do

  • Identify, assess, monitor, and report digital, technology, cybersecurity, enterprise, third-party, AI, automation, and GxP-related risks.
  • Conduct risk assessments and control evaluations, assess residual risk and issue severity, and recommend risk treatment and remediation actions.
  • Partner with technology, cybersecurity, quality, privacy, legal, and business stakeholders to validate risks and controls and support risk-based decisions.
  • Maintain risk data, control gaps, remediation plans, governance records, dashboards, metrics, and executive-ready reporting in GRC and related systems.
  • Analyze risk trends and develop repeatable processes, templates, workflows, and guidance for scalable risk management.
  • Support AI, automation, agentic workflows, data pipelines, and digital transformation by documenting requirements, decision logic, controls, evidence, escalation points, and human oversight.

Requirements

  • 5+ years of experience in cybersecurity risk management, technology risk management, enterprise risk management, IT controls, compliance, or GRC.
  • Experience with risk assessments, control evaluations, issue management, remediation tracking, governance activities, and risk reporting.
  • Hands-on experience in a GxP-regulated environment is required.
  • Experience using AI to optimize or streamline risk analysis, documentation, reporting, workflow management, or stakeholder communications.
  • Strong written and verbal communication skills, analytical judgment, attention to detail, and the ability to influence without direct authority.
  • Four-year degree or equivalent relevant experience is preferred, ideally in information systems, cybersecurity, or risk management.

Nice to have

  • Familiarity with NIST CSF, ISO 27001, CIS Controls, COBIT, ITIL, or similar frameworks.
  • Experience with OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools.
  • Experience with risk registers, issue tracking, control assessments, metrics, dashboards, governance forums, and executive reporting.
  • Experience in continuous service improvement and service excellence.

Culture & Benefits

  • In-person collaboration supported by a 70/30 in-office work model.
  • Healthcare and voluntary benefit programs, fitness, mindfulness, and mental health resources.
  • Family-building support, including fertility, adoption, and surrogacy benefits.
  • Paid vacation, bank holidays, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown.
  • Savings and investment programs plus location-specific benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →