Senior Risk Management Analyst
Core
Own end-to-end third-party cybersecurity risk review processes, including assessment scoping, risk analysis, control gap identification, remediation tracking, and governance reporting within a GxP-regulated biotechnology environment.
Role type
Senior IC third-party cybersecurity risk analyst
Builds
Robust governance across Moderna's third-party ecosystem and scalable risk management capabilities
Domain
Life Sciences / Cybersecurity Risk Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure
Required skills
Third-party cybersecurity risk management, GxP-regulated environment experience, risk analysis, control gap identification, remediation tracking, contract negotiation support, stakeholder engagement, AI/automation workflow integration
Preferred skills
NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ frameworks, GRC tools (OneTrust, ServiceNow, Jira, Power BI), Excel, SharePoint
Technologies
OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint
Responsibilities
Own end-to-end third-party cybersecurity risk review process from intake to governance reporting; Review completed assessments to identify control gaps and remediation requirements; Support contract negotiations regarding cybersecurity addenda and control requirements; Partner with Legal, Privacy, Procurement, and business owners to align risk decisions; Analyze cybersecurity risk trends across vendors, services, and AI capabilities; Support adoption of AI and automation to streamline risk processes; Contribute to governance reporting and continuous improvement initiatives.
Seniority
Senior, hands-on IC