Senior Third Party Risk Analyst
Moderna
- Level
- Senior
- Posted
- 8h ago
Skills
About this role
If you’re interested in this role, please apply in English and include an English version of your Resume/CV.
The Role
Joining Moderna means advancing mRNA science to transform medicine. Work with exceptional global teams on a broad pipeline and build a career that makes a real difference for patients. Moderna is strengthening its international business services hub in Warsaw, supporting our growing global operations. We welcome professionals ready to help advance our mission and shape the future of mRNA medicines. As part of Moderna's Digital Core Governance, Risk and Compliance (GRC) organization, you will help strengthen and mature our third-party cybersecurity risk management program across the enterprise. Working in a highly regulated life sciences environment, you will provide analytical expertise to assess cybersecurity risks across our external ecosystem while enabling the secure adoption of innovative technologies, including AI-enabled services. This is an opportunity to work at the intersection of cybersecurity, digital transformation, governance, and emerging technologies, partnering with cross-functional stakeholders to make informed, risk-based decisions that protect Moderna's mission and patients worldwide. Here's What You'll Do: Own the end-to-end third-party cybersecurity risk review process, from intake and assessment scoping through risk analysis, stakeholder follow-up, remediation tracking, risk disposition, governance reporting, and process documentation. Review completed third-party cybersecurity assessments to identify control gaps, residual risks, compensating controls, remediation requirements, contractual considerations, and recommended risk treatment decisions. Help strengthen Moderna's third-party cybersecurity risk management practices by supporting assessment scoping, risk analysis, governance activities, stakeholder engagement, remediation tracking, and risk disposition across the enterprise. Support cybersecurity contract activities by reviewing, interpreting, and advising on cybersecurity addenda and associated control requirements, including incident notification, audit rights, vulnerability management, access control, encryption, logging and monitoring, subcontractor security, secure development, business continuity, and AI-enabled service requirements where applicable. Partner closely with Legal, Privacy, Procurement, business owners, and technical stakeholders to align third-party cybersecurity risk decisions, contractual obligations, remediation commitments, and governance expectations. Analyze cybersecurity risk trends across vendors, services, AI capabilities, fourth-party dependencies, data classifications, and GxP-regulated processes to strengthen Moderna's third-party cybersecurity posture. Evaluate residual cybersecurity risks, identify compensating controls, prioritize remediation activities, and support informed risk treatment decisions through clear and actionable analysis. Maintain accurate, complete, and actionable third-party cybersecurity risk data to support governance reporting, operational decision-making, and regulatory expectations. Translate third-party cybersecurity risk processes into clear requirements, decision logic, control expectations, evidence requirements, escalation criteria, and human oversight activities to support scalable and consistent execution. Identify opportunities to leverage automation, AI, and agentic workflow capabilities to improve the efficiency, consistency, and maturity of the third-party cybersecurity risk management program while maintaining appropriate governance and oversight. Contribute to process documentation, continuous improvement initiatives, and evolving governance practices that support a growing global cybersecurity program. Perform additional responsibilities and projects as needed. The key Moderna Mindsets you'll need to succeed in the role: We obsess over learning. We don’t have to be the smartest we have to learn the