Назад
Company hidden
3 дня назад

Sr. Cyber Risk 3rd Party Analyst

145 900 - 234 200$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Sr. Cyber Risk 3rd Party Analyst (Cybersecurity/GRC): Managing end-to-end third-party cybersecurity risk reviews, including assessment scoping, control gap analysis, remediation tracking, contract requirements, and governance reporting with an accent on GxP-regulated risk management, AI-enabled services, and fourth-party dependencies. Focus on evaluating residual risk, defining compensating controls, supporting risk treatment decisions, and translating risk processes into automation and agentic workflow requirements.

Location: Cambridge, Massachusetts, with a 70/30 work model requiring 70% in-office work. Only U.S. persons are eligible due to U.S. export control requirements.

Salary: $145,900–$234,200 per year, with potential discretionary bonus, incentive compensation, or equity.

Company

hirify.global develops mRNA technology and medicines within a regulated life sciences environment.

What you will do

  • Own or support the end-to-end third-party cybersecurity risk review process, from intake and scoping through risk disposition, remediation tracking, and reporting.
  • Review assessments to identify control gaps, residual risks, compensating controls, remediation needs, and recommended risk treatments.
  • Support contract negotiations by interpreting cybersecurity addenda and requirements for incident notification, audit rights, vulnerability management, access control, encryption, monitoring, subcontractors, secure development, business continuity, and AI-enabled services.
  • Partner with Legal, Privacy, Procurement, business owners, and technical stakeholders on risk decisions, contract obligations, and remediation commitments.
  • Analyze risk trends across vendors, services, AI capabilities, fourth-party dependencies, data types, and GxP impacts.
  • Document requirements, decision logic, evidence needs, escalation points, and human oversight for AI, automation, and agentic workflows.

Requirements

  • 5+ years of experience in cybersecurity risk management, third-party risk management, GRC, or a related role.
  • Experience with third-party cybersecurity assessments, risk disposition, remediation tracking, reporting, documentation, and cybersecurity addendum support.
  • Experience working in a GxP-regulated environment is required.
  • Strong judgment, analytical ability, attention to detail, and written and verbal communication skills for technical and non-technical stakeholders.
  • Experience using AI to improve risk analysis, documentation, reporting, workflow management, or stakeholder communications.
  • Ability to influence without direct authority in highly matrixed environments.

Nice to have

  • Four-year degree or equivalent relevant experience in information systems, cybersecurity, risk management, or a related field.
  • Familiarity with NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks.
  • Experience with OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools.
  • Experience with auditability, data integrity, consistent documentation, and transparent risk reporting.

Culture & Benefits

  • In-person collaboration supported through a 70/30 office-based working model.
  • Competitive healthcare and voluntary benefit programs.
  • Fitness, mindfulness, mental health, family planning, fertility, adoption, and surrogacy support.
  • Paid vacation, volunteer days, sabbatical, global recharge days, and discretionary year-end shutdown.
  • Savings and investment programs plus location-specific benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →