Hiring.Camp

Senior Third Party Risk Analyst

modernatx

·

Today

Location
POL - Mazowieckie - Warsaw - MESH Rondo Ignacego Daszynskiego 1, Poland · Digital
Type
Full-time
Seniority
Senior
Experience
5+ years
Source
Workday

Description

If you’re interested in this role, please apply in English and include an English version of your Resume/CV.

 

The Role:

Joining Moderna means advancing mRNA science to transform medicine. Work with exceptional global teams on a broad pipeline and build a career that makes a real difference for patients.

Moderna is strengthening its international business services hub in Warsaw, supporting our growing global operations. We welcome professionals ready to help advance our mission and shape the future of mRNA medicines.

As part of Moderna's Digital Core Governance, Risk and Compliance (GRC) organization, you will help strengthen and mature our third-party cybersecurity risk management program across the enterprise. Working in a highly regulated life sciences environment, you will provide analytical expertise to assess cybersecurity risks across our external ecosystem while enabling the secure adoption of innovative technologies, including AI-enabled services.

This is an opportunity to work at the intersection of cybersecurity, digital transformation, governance, and emerging technologies, partnering with cross-functional stakeholders to make informed, risk-based decisions that protect Moderna's mission and patients worldwide.

Here's What You'll Do:

  • Own the end-to-end third-party cybersecurity risk review process, from intake and assessment scoping through risk analysis, stakeholder follow-up, remediation tracking, risk disposition, governance reporting, and process documentation.

  • Review completed third-party cybersecurity assessments to identify control gaps, residual risks, compensating controls, remediation requirements, contractual considerations, and recommended risk treatment decisions.

  • Help strengthen Moderna's third-party cybersecurity risk management practices by supporting assessment scoping, risk analysis, governance activities, stakeholder engagement, remediation tracking, and risk disposition across the enterprise.

  • Support cybersecurity contract activities by reviewing, interpreting, and advising on cybersecurity addenda and associated control requirements, including incident notification, audit rights, vulnerability management, access control, encryption, logging and monitoring, subcontractor security, secure development, business continuity, and AI-enabled service requirements where applicable.

  • Partner closely with Legal, Privacy, Procurement, business owners, and technical stakeholders to align third-party cybersecurity risk decisions, contractual obligations, remediation commitments, and governance expectations.

  • Analyze cybersecurity risk trends across vendors, services, AI capabilities, fourth-party dependencies, data classifications, and GxP-regulated processes to strengthen Moderna's third-party cybersecurity posture.

  • Evaluate residual cybersecurity risks, identify compensating controls, prioritize remediation activities, and support informed risk treatment decisions through clear and actionable analysis.

  • Maintain accurate, complete, and actionable third-party cybersecurity risk data to support governance reporting, operational decision-making, and regulatory expectations.

  • Translate third-party cybersecurity risk processes into clear requirements, decision logic, control expectations, evidence requirements, escalation criteria, and human oversight activities to support scalable and consistent execution.

  • Identify opportunities to leverage automation, AI, and agentic workflow capabilities to improve the efficiency, consistency, and maturity of the third-party cybersecurity risk management program while maintaining appropriate governance and oversight.

  • Contribute to process documentation, continuous improvement initiatives, and evolving governance practices that support a growing global cybersecurity program.

  • Perform additional responsibilities and projects as needed.

The key Moderna Mindsets you'll need to succeed in the role:

  • We obsess over learning. We don’t have to be the smartest we have to learn the fastest.

  • We digitize everywhere possible using the power of code to maximize our impact on patients.

  

Here’s What You’ll Bring to the Table (Minimum Qualifications)  

  • 5+ years of experience in a similar or related position, including experience with standard concepts within cybersecurity risk management, third-party risk management, or GRC. 

  • Experience owning or supporting third-party cybersecurity risk reviews, including assessment analysis, risk disposition, remediation tracking, documentation, reporting, and cybersecurity addendum support during contract negotiations. 

  • Sound judgment to identify when risks, control gaps, contractual concerns, or remediation delays require escalation to drive timely decision-making and appropriate risk treatment. 

  • Experience working in a GxP-regulated environment is required. 

  • Strong written and verbal communication skills, including the ability to communicate cybersecurity risk concepts and control expectations to technical and non-technical stakeholders. 

  • Experience using AI to optimize, augment, or streamline risk analysis, documentation, reporting, workflow management, or stakeholder communications. 

  • Proven ability to operate in highly matrixed environments and influence without direct authority.  

Preferred Qualifications (Preferred Qualifications): 

  • Four-year degree or equivalent relevant work experience preferred, ideally in information systems, cybersecurity, or risk management. 

  • Familiarity with third-party cybersecurity risk frameworks and assessment standards such as NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks. 

  • Experience with GRC, workflow, reporting, and collaboration tools such as OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools. 

  • Strong attention to detail and commitment to data integrity, auditability, consistent documentation, and transparent risk reporting. 

  • Influential, inclusive, and trusted partner compassionate to the needs and situations of all your stakeholders  

  • Embrace a culture of continuous service improvement and service excellence 

  • A desire to make an impact as part of a high-growth, transformational company


Pay & Benefits


At Moderna, we believe that when you feel your best, you can do your best work.  That’s why our benefits and well-being resources are designed to support you—at work, at home, and everywhere in between.

  • Competitive healthcare, plus voluntary benefit programs to support your unique needs
  • A holistic approach to well-being with access to fitness, mindfulness, and mental health support
  • Family building benefits, including fertility, adoption, and surrogacy support
  • Generous paid time off, including vacation, bank holidays, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown
  • Savings and investments to help you plan for the future
  • Location-specific perks and extras

The benefits offered may vary depending on the nature of your employment with Moderna and the country where you work.


About Moderna

Since our founding in 2010, we have aspired to build the leading mRNA technology platform, the infrastructure to reimagine how medicines are created and delivered, and a world-class team. We believe in giving our people a platform to change medicine and an opportunity to change the world.  


By living our mission, values, and mindsets every day, our people are the driving force behind our scientific progress and our culture. Together, we are creating a culture of belonging and building an organization that cares deeply for our patients, our employees, the environment, and our communities. 


We are proud to have been recognized as a Science Magazine Top Biopharma Employer, a Fast Company Best Workplace for Innovators, and a Great Place to Work in the U.S. 


As we build our company, we have always believed an in-person culture is critical to our success. Moderna champions the significant benefits of in-office collaboration by embracing a 70/30 work model. This 70% in-office structure helps to foster a culture rich in innovation, teamwork, and direct mentorship. Join us in shaping a world where every interaction is an opportunity to learn, contribute, and make a meaningful impact. 


If you want to make a difference and join a team that is changing the future of medicine, we invite you to visit modernatx.com/careers to learn more about our current opportunities. 


Moderna is a smoke-free, alcohol-free, and drug-free work environment. 


Moderna is a place where everyone can grow. If you meet the Basic Qualifications for the role and you would be excited to contribute to our mission every day, please apply! 


Moderna is committed to equal opportunity in employment and non-discrimination for all employees and qualified applicants without regard to a person's race, color, sex, gender identity or expression, age, religion, national origin, ancestry or citizenship, ethnicity, disability, military or protected veteran status, genetic information, sexual orientation, marital or familial status, or any other personal characteristic protected under applicable law. We consider qualified applicants regardless of criminal histories, consistent with legal requirements. 


We’re focused on attracting, retaining, developing, and advancing our employees. By cultivating a workplace that values diverse experiences, backgrounds, and ideas, we create an environment where every employee can contribute their best. 


Moderna is committed to offering reasonable accommodation or adjustments to qualified job applicants with disabilities. Any applicant requiring an accommodation or adjustment in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should contact the Accommodations and Adjustments team at [email protected]

-

Skills

JiraExcelPower BIServiceNowCybersecurityRisk ManagementComplianceProcurementISO 27001

Similar Jobs

30

Assurance Senior, Third Party Attestation

BDO Seidman · San Francisco, CA, United States, US

6 days ago

Assurance Experienced Senior, Third Party Attestation

BDO Seidman · Chicago, IL, United States, US

6 days ago

Senior Third-Party Logistics Manager

RTX · US-AZ-MARANA-GXO-CUST ~ 10070 West Clark Farms Blvd ~ GXO (External Site), United States of America · Onsite

2 weeks ago

Senior Third-Party Cyber Security Risk Analyst

Toyota · Plano, United States of America

2 weeks ago

Senior Third-Party Risk Analyst

Western Governors University · Salt Lake City Office, United States of America

1 month ago

Senior Analyst, Third-Party Risk Management (TPRM)

American Tower Global · Boston, MA, United States, US · Hybrid

3 days ago

Senior Manager, Third-Party Events (Remote US)

Veeamsoftware · Remote, United States · Remote

1 week ago

Senior Manager, Third Party Risk Management Oversight and Advisory (5183)

Td · TD Centre - TD Tower - 66 Wellington Street West, Toronto, Ontario, Canada · Onsite

2 weeks ago

Senior Manager, Third Party Lifecycle Oversight (5213)

Td · TD Centre - TD Tower - 66 Wellington Street West, Toronto, Ontario, Canada · Onsite

2 weeks ago

Senior Analyst, Third-Party Risk Management (TPRM)

Doordash USA · Milwaukee WI; Chicago, IL; New York, NY; San Francisco, CA; Phoenix, AZ; Austin, TX; United States - Remote · Remote

2 weeks ago

Senior Security Third Party Risk (TPRM) Analyst

OneTrust · Atlanta, Georgia +1

3 weeks ago

Senior Analyst, Third Party Risk Management

Nab

1 month ago

Senior Consultant, Third Party Issue Management - Third Party Risk Management

NT Careers · Tempe, AZ, United States of America · onsite

1 month ago

Senior Counsel, Senior AVP: Third Party Technology

Wells Fargo · 141753-NC-Three Wells Fargo Center, Charlotte, United States of America +1 · Hybrid, Onsite

1 month ago

Third Party Risk Senior Consultant

Crowe Careers · Chicago, United States of America +2

1 month ago

Senior Manager, Third Party & Contract Risk

Mgmresorts · Office - US, Las Vegas, NV 3260 Sammy Davis Jr, United States of America

1 month ago

Senior Manager, Third Party & Contract Risk

Mgmresorts · Office - US, Las Vegas, NV 3260 Sammy Davis Jr, United States of America

1 month ago

Assurance Senior Manager, Third Party Attestation

BDO Seidman · Tampa, FL, United States, US

2 months ago

Senior Manager, Third Party Risk Portfolio & Operational Excellence

Rbc · RBC WATERPARK PLACE, 88 QUEENS QUAY W:TORONTO, Canada

2 months ago

Senior Consultant, Third Party Risk Management

NT Careers · Chicago, IL, United States of America

3 months ago

Third Party Risk Senior Associate (US Shift)

Depository Trust Company · Manila, Philippines

3 months ago

Third Party (Vendor) Insights Senior Analyst

ATB · Calgary, AB,CA, CA +1

4 days ago

Senior Project Manager -Third Party Applications

Brightspring · LOUISVILLE, KY, US

1 week ago

Senior Vice President, Third Party Application Engineering

0101022-GIA PROD US LOS ANGELES · Pune, MH, India

1 week ago

Senior Manager – Finance Third Party Risk Management

M&G · Mumbai Central Avenue, India

2 weeks ago

Senior Vice President, Third Party Application Engineering

0101022-GIA PROD US LOS ANGELES · Boston, MA, United States, US

2 weeks ago

Third-Party Procurement & Sourcing Senior Manager

Western Alliance Bancorporation · Block 23, United States of America

1 month ago

Senior Project Manager -Third Party Applications

Brightspring · LOUISVILLE, KY, US

1 month ago

Executive/Senior Executive Stores- Third party payroll

Sika · Tarapur, MH, India

2 months ago

Senior Director, Enterprise Third Party Risk

vrtx · 5000 - Vertex US - Fan Pier, United States of America

2 months ago