The Role:
Moderna Digital Core Governance, Risk and Compliance (GRC) is seeking a Risk Management Analyst to support the end-to-end third-party cybersecurity risk review process across Moderna. This role will help strengthen Moderna’s third-party cybersecurity risk management practices by supporting assessment scoping, risk analysis, control gap identification, stakeholder follow-up, remediation tracking, risk disposition, governance reporting, process documentation, and cross-functional engagement.
The Risk Management Analyst will play a key role in helping the organization understand third-party cybersecurity risk exposure, evaluate residual risk, identify compensating controls, prioritize remediation activities, support risk treatment decisions, and maintain clear, accurate, and actionable third-party risk data in a regulated life sciences environment. This individual will also support contract-related cybersecurity risk activities by helping review and interpret cybersecurity control requirements, remediation commitments, and governance expectations in partnership with Legal, Privacy, Procurement, business owners, and technical stakeholders.
To excel in this role, the Risk Management Analyst should have strong analytical, communication, and organizational skills, excellent attention to detail, experience working in GxP-regulated environments, a solid understanding of cybersecurity and third-party risk management concepts, and curiosity about emerging risks introduced by artificial intelligence, fourth-party dependencies, and evolving regulatory expectations. This individual should also be able to translate third-party cybersecurity risk processes into clear requirements, decision logic, control expectations, evidence needs, escalation points, and human oversight requirements to help identify and implement opportunities where automation and agentic workflow capabilities can scale and mature the program.
Here's WhatYoullDo:
- Own the end-to-end third-party cybersecurity risk review process, from intake and assessment scoping through risk analysis, stakeholder follow-up, remediation tracking, risk disposition, and reporting.
- Review completed third-party cybersecurity assessments toidentifycontrol gaps, residual risks, compensating controls, remediation needs, contractual considerations, and recommended risk treatment decisions.
- Support contract negotiations by reviewing, interpreting, and advising on the cybersecurity addendum and associated cybersecurity control requirements, including requirements related to incident notification, audit rights, vulnerability management, access control, encryption, logging and monitoring, subcontractor security, secure development, business continuity, and AI-enabled services where applicable.
- Partner with Legal, Privacy, Procurement, business owners, and technical stakeholders to align third-party risk decisions, contract obligations, remediation commitments, and governance expectations.
- Analyze third-party risk trends across assessments, vendors, services, AI capabilities, fourth-party dependencies, data types, and GxPimpactsto improve Moderna’s third-party cybersecurity risk posture.
- Support the use of AI, automation, and agentic workflows to improve third-party cybersecurity risk processes by documenting requirements, decision logic, control expectations, evidence needs, escalation points, and human oversight requirements.
- Additionaltasks as needed
0
Here’s WhatYoullBring to the Table (Minimum Qualifications)
- 5+ years of experience in a similar or related position, including experience with standard concepts within cybersecurity risk management, third-party risk management, or GRC.
- Experience owning or supporting third-party cybersecurity risk reviews, including assessment analysis, risk disposition, remediation tracking, documentation, reporting, and cybersecurity addendum support during contract negotiations.
- Sound judgment toidentifywhen risks, control gaps, contractual concerns, or remediation delays require escalation to drivetimelydecision-making andappropriate risktreatment.
- Experience working in a GxP-regulated environment isrequired.
- Strong written and verbal communication skills, including the ability to communicate cybersecurity risk concepts and control expectations to technical and non-technical stakeholders.
- Experience using AI tooptimize, augment, or streamline risk analysis, documentation, reporting, workflow management, or stakeholder communications.
- Proven ability tooperatein highly matrixed environments and influence without direct authority.
Preferred Qualifications (Preferred Qualifications):
- Four-year degree or equivalent relevant work experience preferred, ideally in information systems, cybersecurity, or risk management.
- Familiarity with third-party cybersecurity risk frameworks and assessment standards such as NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks.
- Experience with GRC, workflow, reporting, and collaboration tools such asOneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools.
- Strong attention to detail and commitment to data integrity, auditability, consistent documentation, and transparent risk reporting.
- Influential, inclusive, and trusted partner compassionate to the needs and situations of all your stakeholders
- Embrace a culture of continuous service improvement and service excellence
- A desire to make an impact as part of a high-growth, transformational company
Our Working Model
As we build our company, we have always believed an in-person culture is critical to our success. Moderna champions the significant benefits of in-office collaboration by embracing a 70/30 work model. This 70% in-office structure helps to foster a culture rich in innovation, teamwork, and direct mentorship. Join us in shaping a world where every interaction is an opportunity to learn, contribute, and make a meaningful impact.
Moderna is a smoke-free, alcohol-free, and drug-free work environment.
Pay & Benefits
At Moderna, we believe that when you feel your best, you can do your best work. That’s why our benefits and well-being resources are designed to support you—at work, at home, and everywhere in between.
- Competitive healthcare, plus voluntary benefit programs to support your unique needs
- A holistic approach to well-being, with access to fitness, mindfulness, and mental health support
- Family planning benefits, including fertility, adoption, and surrogacy support
- Generous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdown
- Savings and investments to help you plan for the future
- Location-specific perks and extras
The salary range for this role is $145,900.00 - $234,200.00. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An individual’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, performance, and business or organizational needs.
The successful candidate may be eligible for an annual discretionary bonus, other incentive compensation, or equity award, subject to company plan eligibility criteria and individual performance.
-