Senior Risk Management Analyst

Initial Therapeutics, Inc.

Poland

On-site

PLN 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Competitive healthcare benefits
Well-being programs and time off
Family building benefits and sabbatial

Job summary

Moderna is expanding its cybersecurity risk program in Warsaw, driving governance across third-party ecosystems in a highly regulated biopharma environment. You will own end-to-end risk reviews, analyze control gaps, and support contract negotiations while collaborating with Legal, Privacy, Procurement, and business owners to align risk decisions with governance expectations.

You’ll also help evolve the program by leveraging AI, automation, and agentic workflows to create scalable risk

Qualifications

  • 5+ years of experience in a similar or related position or cybersecurity risk management
  • Experience owning or supporting third-party cybersecurity risk reviews and contract negotiation support
  • Strong judgment to escalate risks or remediation delays
  • Experience working in a GxP-regulated environment
  • Strong written and verbal communication for technical and non-technical stakeholders
  • Experience using AI to optimize risk analysis, documentation and reporting
  • Proven ability to operate in matrixed environments and influence without authority

Responsibilities

  • Own end-to-end third-party cybersecurity risk review process from intake to governance reporting
  • Review assessments to identify control gaps, residual risks and remediation requirements
  • Strengthen risk management practices through scoping, risk analysis, remediation tracking and governance reporting
  • Support contract negotiations by reviewing cybersecurity addenda and control requirements
  • Partner with Legal, Privacy, Procurement and business owners to align risk decisions with governance expectations
  • Evaluate residual risk and prioritize remediation activities within a GxP-regulated context
  • Analyze risk trends across assessments, vendors, AI capabilities, and data classifications
  • Document requirements and evidence for scalable risk processes and human oversight
  • Contribute to governance reporting, process documentation and stakeholder communications
  • Perform additional responsibilities and special projects as needed

Skills

Cyber risk management
GRC experience
AI in risk analysis
Stakeholder management
Contract negotiations

Education

Four-year degree or equivalent

Tools

OneTrust
ServiceNow
Jira
Power BI
Excel
SharePoint

Job description

The Role:

Joining Moderna means advancing mRNA science to transform medicine. Work with exceptional global teams on a broad pipeline and build a career that makes a real difference for patients.

Moderna is strengthening its international business services hub in Warsaw, supporting our growing global operations. We welcome professionals ready to help advance our mission and shape the future of mRNA medicines.

Help shape the future of third-party cybersecurity risk management within a fast-moving, highly regulated biotechnology environment. In this role, you will drive robust governance across Moderna's third-party ecosystem, partnering with stakeholders across Digital, Legal, Privacy, Procurement, and the business to ensure cyber risks are understood, managed, and continuously improved.

You’ll also help evolve the program by identifying opportunities to leverage auto

mation, Generative AI, and agentic workflows to create smarter, more scalable risk management capabilities.

Here’s What You’ll Do:
  • Own the end-to-end third-party cybersecurity risk review process, from intake and assessment scoping through risk analysis, stakeholder follow-up, remediation tracking, risk disposition, and governance reporting.

  • Review completed third-party cybersecurity assessments to identify control gaps, residual risks, compensating controls, remediation requirements, contractual considerations, and appropriate risk treatment recommendations.

  • Help strengthen Moderna's third-party cybersecurity risk management practices by supporting assessment scoping, risk analysis, control gap identification, stakeholder engagement, remediation tracking, governance reporting, process documentation, and cross-functional collaboration.

  • Support contract negotiations by reviewing, interpreting, and advising on cybersecurity addenda and associated cybersecurity control requirements, including incident notification, audit rights, vulnerability management, access control, encryption, logging and monitoring, subcontractor security, secure development, business continuity, and AI-enabled services where applicable.

  • Partner closely with Legal, Privacy, Procurement, business owners, and technical stakeholders to align third-party risk decisions, contractual obligations, remediation commitments, and governance expectations.

  • Help the organization understand third-party cybersecurity risk exposure by evaluating residual risk, identifying compensating controls, prioritizing remediation activities, supporting risk treatment decisions, and maintaining accurate, actionable third-party risk data within a GxP-regulated life sciences environment.

  • Analyze cybersecurity risk trends across assessments, vendors, services, AI capabilities, fourth-party dependencies, data classifications, and GxP impacts to continuously strengthen Moderna's third-party cybersecurity risk posture.

  • Support the adoption of AI, automation, and agentic workflows by documenting business requirements, decision logic, control expectations, evidence requirements, escalation points, and human oversight needs to enable scalable and mature third-party cybersecurity risk processes.

  • Translate third-party cybersecurity risk processes into clear operational requirements that improve governance, consistency, and automation opportunities across the program.

  • Contribute to governance reporting, process documentation, stakeholder communications, and continuous improvement initiatives that enhance cybersecurity risk management maturity.

  • Perform additional responsibilities and special projects as required.

The key Moderna Mindsets you'll need to succeed in the role:
  • We obsess over learning. We don’t have to be the smartest we have to learn the fastest.

  • We digitize everywhere possible using the power of code to maximize our impact on patients.

Here’s WhatYouBring to the Table (Minimum Qualifications)
  • 5+ years of experience in a similar or related position, including experience with standard concepts within cybersecurity risk management, third-party risk management, or GRC.

  • Experience owning or supporting third-party cybersecurity risk reviews, including assessment analysis, risk disposition, remediation tracking, documentation, reporting, and cybersecurity addendum support during contract negotiations.

  • Sound judgment to identify when risks, control gaps, contractual concerns, or remediation delays require escalation to drive timely decision-making and appropriate risk treatment.

  • Experience working in a GxP-regulated environment is required.

  • Strong written and verbal communication skills, including the ability to communicate cybersecurity risk concepts and control expectations to technical and non-technical stakeholders.

  • Experience using AI to optimize, augment, or streamline risk analysis, documentation, reporting, workflow management, or stakeholder communications.

  • Proven ability to operate in highly matrixed environments and influence without direct authority.

Preferred Qualifications (Preferred Qualifications):
  • Four-year degree or equivalent relevant work experience preferred, ideally in information systems, cybersecurity, or risk management.

  • Familiarity with third-party cybersecurity risk frameworks and assessment standards such as NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks.

  • Experience with GRC, workflow, reporting, and collaboration tools such as OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools.

  • Strong attention to detail and commitment to data integrity, auditability, consistent documentation, and transparent risk reporting.

  • Influential, inclusive, and trusted partner compassionate to the needs and situations of all your stakeholders

  • Embrace a culture of continuous service improvement and service excellence

  • A desire to make an impact as part of a high-growth, transformational company

Pay & Benefits
  • Competitive healthcare, plus voluntary benefit programs to support your unique needs
  • A holistic approach to well-being with access to fitness, mindfulness, and mental health support
  • Family building benefits, including fertility, adoption, and surrogacy support
  • Generous paid time off, including vacation, bank holidays, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown
  • Savings and investments to help you plan for the future
  • Location-specific perks and extras

The benefits offered may vary depending on the nature of your employment with Moderna and the country where you work.

About Moderna

Since our founding in 2010, we have aspired to build the leading mRNA technology platform, the infrastructure to reimagine how medicines are created and delivered, and a world-class team. We believe in giving our people a platform to change medicine and an opportunity to change the world.

By living our mission, values, and mindsets every day, our people are the driving force behind our scientific progress and our culture. Together, we are creating a culture of belonging and building an organization that cares deeply for our patients, our employees, the environment, and our communities.

We are proud to have been recognized as a Science Magazine Top Biopharma Employer, a Fast Company Best Workplace for Innovators, and a Great Place to Work in the U.S.

As we build our company, we have always believed an in-person culture is critical to our success. Moderna champions the significant benefits of in-office collaboration by embracing a 70/30 work model. This 70% in-office structure helps to foster a culture rich in innovation, teamwork, and direct mentorship. Join us in shaping a world where every interaction is an opportunity to learn, contribute, and make a meaningful impact.

Moderna is a smoke-free, alcohol-free, and drug-free work environment.

Moderna is committed to equal opportunity in employment and non-discrimination for all employees and qualified applicants without regard to a person's race, color, sex, gender identity or expression, age, religion, national origin, ancestry or citizenship, ethnicity, disability, military or protected veteran status, genetic information, sexual orientation, marital or familial status, or any other personal characteristic protected under applicable law. We consider qualified applicants regardless of criminal histories, consistent with legal requirements.

We're focused on attracting, retaining, developing, and advancing our employees. By cultivating a workplace that values diverse experiences, backgrounds, and ideas, we create an environment where every employee can contribute their best.

Moderna is committed to offering reasonable accommodation or adjustments to qualified job applicants with disabilities. Any applicant requiring an accommodation or adjustment in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should contact the Accommodations and Adjustments team at leavesandaccommodations@modernatx.com.

-

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Third Party Risk Analyst
Senior Third Party Risk Analyst

Initial Therapeutics, Inc. • Poland

Hybrid
PLN 180,000 - 280,000
Competitive healthcare
Well-being resources
Paid time off and holidays
+1
Senior Third Party Risk Analyst
Senior Third Party Risk Analyst

BioSpace • Warszawa

On-site
PLN 180,000 - 260,000
Healthcare benefits
Well-being resources
Paid time off
Senior Third Party Risk Analyst
Senior Third Party Risk Analyst

Moderna • Warszawa

On-site
PLN 180,000 - 250,000
Healthcare benefits
Well-being resources
Generous time off & holidays
+1
Software Security Engineer
Software Security Engineer

Initial Therapeutics, Inc. • Poland

Hybrid
PLN 683,000 - 798,000
Competitive healthcare
Well-being resources
Family building benefits
+3
Software Security Engineer
Software Security Engineer

Moderna Therapeutics • Warszawa

Hybrid
PLN 260,000 - 420,000
Competitive healthcare
Well-being resources
Family building benefits
Associate Director, Regulatory Data Management & Intelligence
Associate Director, Regulatory Data Management & Intelligence

BioSpace • Warszawa

On-site
PLN 480,000 - 760,000
Healthcare benefits
Well-being resources
Paid time off & holidays
Software Security Engineer
Software Security Engineer

BioSpace • Warszawa

Hybrid
PLN 558,000 - 707,000
Healthcare
Well-being programs
Generous PTO
Software Engineer, DevSecOps
Software Engineer, DevSecOps

Initial Therapeutics, Inc. • Poland

On-site
PLN 180,000 - 320,000
Healthcare
Well‑being programs
Generous paid time off
Sr. AI Security Engineer
Sr. AI Security Engineer

Initial Therapeutics, Inc. • Poland

Hybrid
PLN 240,000 - 400,000
Healthcare benefits
Well-being resources
Family building benefits
+3
Software Engineer, DevSecOps
Software Engineer, DevSecOps

Moderna • Warszawa

On-site
PLN 240,000 - 320,000
Competitive healthcare
Well-being resources
Family building benefits
+2