Назад
Company hidden
4 дня назад

Senior Risk Management Analyst (AI/GRC)

Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Poland
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Risk Management Analyst (AI/GRC): Supporting technology, cybersecurity, and emerging-risk assessments, control evaluations, remediation tracking, and governance reporting across a regulated mRNA medicines organization with an accent on GxP environments, risk data integrity, and cross-functional decision-making. Focus on documenting controls and oversight for AI, automation, agentic workflows, data pipelines, and digital platforms while producing actionable metrics and executive-ready risk insights.

Location: Warsaw, Poland; 70% in-office work under hirify.global's 70/30 model

Company

hirify.global develops mRNA technology and medicines, supported by global operations and a regulated life sciences environment.

What you will do

  • Identify, assess, monitor, and report digital, technology, cybersecurity, emerging, third-party, AI, automation, and GxP-related risks.
  • Evaluate risk exposure, control effectiveness, residual risk, issue severity, remediation needs, and risk treatment recommendations.
  • Partner with technology, cybersecurity, quality, privacy, legal, business, and other stakeholders on risk assessments and remediation plans.
  • Document control gaps, track remediation commitments, maintain GRC data, and escalate material risks or delays.
  • Prepare risk metrics, dashboards, governance reports, and executive-ready summaries.
  • Define requirements, decision logic, controls, evidence, escalation points, and human oversight for AI, automation, and agentic workflows.

Requirements

  • 5+ years of experience in cybersecurity risk management, technology risk management, enterprise risk management, IT controls, compliance, or GRC.
  • Experience with risk assessments, control evaluations, issue management, remediation tracking, risk reporting, and governance activities.
  • Hands-on experience in a GxP-regulated environment is required.
  • Strong written and verbal communication skills for technical and non-technical stakeholders.
  • Experience using AI to optimize risk analysis, documentation, reporting, workflows, or stakeholder communications.
  • Ability to work in highly matrixed environments and influence without direct authority.

Nice to have

  • Four-year degree or equivalent relevant experience in information systems, cybersecurity, or risk management.
  • Familiarity with NIST CSF, ISO 27001, CIS Controls, COBIT, ITIL, or similar frameworks.
  • Experience with OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools.
  • Experience with risk registers, control assessments, dashboards, governance forums, and executive reporting.

Culture & Benefits

  • 70/30 work model emphasizing in-office collaboration, teamwork, innovation, and mentorship.
  • Healthcare and voluntary benefit programs.
  • Fitness, mindfulness, and mental health support.
  • Family-building benefits, including fertility, adoption, and surrogacy support.
  • Paid vacation, bank holidays, volunteer days, sabbatical, global recharge days, and year-end shutdown.
  • Savings and investment programs plus location-specific benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →