Назад
Company hidden
3 дня назад

Senior Risk Management Analyst (Cybersecurity)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US/Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Risk Management Analyst (Cybersecurity): Supporting the assessment, monitoring, and reporting of technology, cybersecurity, AI, and GxP-related risks with an accent on control evaluations, issue management, governance reporting, and auditable risk data. Focus on translating AI and automation requirements into documented controls, decision logic, evidence requirements, escalation points, and human oversight.

Location: Warsaw, Poland; hybrid 70/30 work model with 70% in-office collaboration.

Company

hirify.global develops mRNA medicines and operates a global life sciences organization with a digital technology, cybersecurity, and governance function.

What you will do

  • Identify, assess, monitor, and report digital, technology, cybersecurity, emerging, AI, automation, third-party, and GxP-related risks.
  • Conduct risk assessments and control evaluations, assess residual risk and issue severity, and recommend risk treatment and remediation actions.
  • Partner with technology, cybersecurity, quality, privacy, legal, and business stakeholders to validate risks and controls and support risk-based decisions.
  • Maintain risk data, issue records, remediation plans, dashboards, metrics, governance reports, and executive-ready summaries.
  • Document requirements, decision logic, control expectations, evidence needs, escalation points, and human oversight for AI, automation, agentic workflows, and digital platforms.
  • Develop procedures, templates, workflows, process documentation, and guidance for repeatable and scalable risk management.

Requirements

  • 5+ years of experience in cybersecurity risk management, technology risk management, enterprise risk management, IT controls, compliance, or GRC.
  • Experience with risk assessments, control evaluations, issue management, remediation tracking, risk reporting, and governance activities.
  • Hands-on experience in a GxP-regulated environment is required.
  • Strong written and verbal communication skills, with the ability to explain cybersecurity risks and control expectations to technical and non-technical stakeholders.
  • Experience using AI to improve risk analysis, documentation, reporting, workflow management, or stakeholder communications.
  • A four-year degree or equivalent relevant experience is preferred, ideally in information systems, cybersecurity, or risk management.

Nice to have

  • Familiarity with NIST CSF, ISO 27001, CIS Controls, COBIT, ITIL, or similar frameworks.
  • Experience with OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar GRC and reporting tools.
  • Experience with risk registers, control assessments, governance forums, metrics, dashboards, and executive reporting.
  • Experience in high-growth or transformational organizations and a commitment to continuous service improvement.

Culture & Benefits

  • 70/30 in-office work model focused on collaboration, innovation, teamwork, and direct mentorship.
  • Competitive healthcare and voluntary benefit programs.
  • Fitness, mindfulness, mental health, and family-building support, including fertility, adoption, and surrogacy benefits.
  • Paid vacation, bank holidays, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown.
  • Location-specific perks and savings and investment programs.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →