# Senior Third Party Risk Analyst

Hiring organization: [Moderna](https://career.thegoodapps.co/organizations/moderna)

Canonical page: https://career.thegoodapps.co/jobs/53066b22-0682-48a4-8253-b5b567cb93d2

Listed on Moderna's own careers site. Applications go to them directly.

- Seniority: Senior

## Summary

A Third Party Risk Analyst role within Moderna's governance and compliance organization, responsible for managing cybersecurity risk assessments of external vendors and partners in a regulated pharmaceutical environment. The position suits experienced risk professionals who can evaluate complex security controls, influence stakeholders across departments, and help mature enterprise risk management practices for a rapidly growing biotech company.

_Our summary, not Moderna's wording._

## Skills named

Jira, Microsoft Excel, Microsoft SharePoint, Power BI, ServiceNow

## Required

- 5+ years in third-party risk management or GRC
- Experience owning third-party cybersecurity risk reviews including assessment analysis and remediation tracking
- Experience in GxP-regulated environments
- Sound judgment to escalate risks and drive timely decisions
- Strong written and verbal communication skills
- Experience using AI to optimize risk analysis or workflow management
- Ability to operate in matrixed environments and influence without direct authority

## Nice to have

- Four-year degree in information systems, cybersecurity, or risk management
- Familiarity with third-party risk frameworks such as NIST CSF, ISO 27001, CIS Controls, or CAIQ
- Experience with GRC tools like OneTrust, ServiceNow, Jira, Power BI, or Excel
- Strong attention to detail and commitment to data integrity
- Track record of service improvement and continuous enhancement

Apply on Moderna's site: https://modernatx.wd1.myworkdayjobs.com/en-US/M_tx/job/Warsaw---Poland/Senior-Third-Party-Risk-Analyst_R19490
