4 дня назад
Senior Third Party Risk Analyst (Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Third Party Risk Analyst (Cybersecurity): Managing end-to-end third-party cybersecurity risk reviews across Moderna’s external ecosystem with an accent on risk analysis, remediation tracking, governance reporting, and cybersecurity contract requirements. Focus on evaluating residual risks, analyzing AI-enabled services and fourth-party dependencies, and improving risk workflows through automation while maintaining appropriate governance and oversight.
Location: Warsaw, Poland; 70% in-office work model
Company
is a biotechnology company building an mRNA technology platform and developing medicines.
What you will do
- Own third-party cybersecurity risk reviews from intake and scoping through analysis, remediation tracking, risk disposition, reporting, and documentation.
- Review assessments to identify control gaps, residual risks, compensating controls, contractual considerations, and recommended risk treatments.
- Advise on cybersecurity addenda and requirements covering incident notification, audit rights, vulnerability management, access control, encryption, monitoring, subcontractors, secure development, continuity, and AI-enabled services.
- Partner with Legal, Privacy, Procurement, business owners, and technical stakeholders on risk decisions and contractual obligations.
- Analyze vendor, service, AI capability, fourth-party, data classification, and GxP-related risk trends.
- Improve scalable risk management through clear decision logic, automation, AI, agentic workflows, process documentation, and governance practices.
Requirements
- 5+ years of experience in cybersecurity risk management, third-party risk management, GRC, or a related role.
- Experience with third-party cybersecurity assessments, risk disposition, remediation tracking, reporting, documentation, and cybersecurity contract addenda.
- Experience in a GxP-regulated environment is required.
- Strong judgment and communication skills, including the ability to explain cybersecurity risks and control expectations to technical and non-technical stakeholders.
- Experience using AI to improve risk analysis, documentation, reporting, workflow management, or stakeholder communications.
- Ability to work in matrixed environments and influence without direct authority.
Nice to have
- Four-year degree or equivalent experience in information systems, cybersecurity, risk management, or a related field.
- Knowledge of NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks.
- Experience with OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools.
- Strong attention to detail, data integrity, auditability, consistent documentation, and transparent risk reporting.
Culture & Benefits
- 70/30 work model emphasizing in-office collaboration, innovation, teamwork, and mentorship.
- Competitive healthcare and voluntary benefit programs.
- Fitness, mindfulness, and mental health support.
- Family-building benefits, including fertility, adoption, and surrogacy support.
- Paid time off including vacation, bank holidays, volunteer days, sabbatical, global recharge days, and year-end shutdown.
- Savings and investment programs, plus location-specific benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →