Sr. Cyber Risk 3rd Party Analyst
$145.9k - $234.2kModerna Therapeutics
The Role:Moderna Digital Core Governance, Risk and Compliance (GRC) is seeking a Risk Management Analyst to support the end-to-end third-party cybersecurity risk review process across Moderna. This role will help strengthen Moderna’s third-party cybersecurity risk management practices by supporting assessment scoping, risk analysis, control gap identification, stakeholder follow-up, remediation tracking, risk disposition, governance reporting, process documentation, and cross-functional engagement. The Risk Management Analyst will play a key role in helping the organization understand third-party cybersecurity risk exposure, evaluate residual risk, identify compensating controls, prioritize remediation activities, support risk treatment decisions, and maintain clear, accurate, and actionable third-party risk data in a regulated life sciences environment. This individual will also support contract-related cybersecurity risk activities by helping review and interpret cybersecurity control requirements, remediation commitments, and governance expectations in partnership with Legal, Privacy, Procurement, business owners, and technical stakeholders. To excel in this role, the Risk Management Analyst should have strong analytical, communication, and organizational skills, excellent attention to detail, experience working in GxP-regulated environments, a solid understanding of cybersecurity and third-party risk management concepts, and curiosity about emerging risks introduced by artificial intelligence, fourth-party dependencies, and evolving regulatory expectations. This individual should also be able to translate third-party cybersecurity risk processes into clear requirements, decision logic, control expectations, evidence needs, escalation points, and human oversight requirements to help identify and implement opportunities where automation and agentic workflow capabilities can scale and mature the program. Here's What You’ll Do: Own the end-to-end third-party cybersecurity risk review process, from intake and assessment scoping through risk analysis, stakeholder follow-up, remediation tracking, risk disposition, and reporting. Review completed third-party cybersecurity assessments to identify control gaps, residual risks, compensating controls, remediation needs, contractual considerations, and recommended risk treatment decisions. Support contract negotiations by reviewing, interpreting, and advising on the cybersecurity addendum and associated cybersecurity control requirements, including requirements related to incident notification, audit rights, vulnerability management, access control, encryption, logging and monitoring, subcontractor security, secure development, business continuity, and AI-enabled services where applicable. Partner with Legal, Privacy, Procurement, business owners, and technical stakeholders to align third-party risk decisions, contract obligations, remediation commitments, and governance expectations. Analyze third-party risk trends across assessments, vendors, services, AI capabilities, fourth-party dependencies, data types, and GxP impacts to improve Moderna’s third-party cybersecurity risk posture. Support the use of AI, automation, and agentic workflows to improve third-party cybersecurity risk processes by documenting requirements, decision logic, control expectations, evidence needs, escalation points, and human oversight requirements. Additional tasks as needed Here’s What You’ll Bring to the Table (Minimum Qualifications) 5+ years of experience in a similar or related position, including experience with standard concepts within cybersecurity risk management, third-party risk management, or GRC. Experience owning or supporting third-party cybersecurity risk reviews, including assessment analysis, risk disposition, remediation tracking, documentation, reporting, and cybersecurity addendum support during contract negotiations. Sound judgment to identify when risks, control gaps, contractual concerns, or remediation delays require escalation to drive timely decision-making and appropriate risk treatment. Experience working in a GxP-regulated environment is required. Strong written and verbal communication skills, including the ability to communicate cybersecurity risk concepts and control expectations to technical and non-technical stakeholders. Experience using AI to optimize, augment, or streamline risk analysis, documentation, reporting, workflow management, or stakeholder communications. Proven ability to operate in highly matrixed environments and influence without direct authority. Preferred Qualifications (Preferred Qualifications): Four-year degree or equivalent relevant work experience preferred, ideally in information systems, cybersecurity, or risk management. Familiarity with third-party cybersecurity risk frameworks and assessment standards such as NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks. Experience with GRC, workflow, reporting, and collaboration tools such as OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools. Strong attention to detail and commitment to data integrity, auditability, consistent documentation, and transparent risk reporting. Influential, inclusive, and trusted partner compassionate to the needs and situations of all your stakeholders Embrace a culture of continuous service improvement and service excellence A desire to make an impact as part of a high-growth, transformational company Our Working Model As we build our company, we have always believed an in-person culture is critical to our success. Moderna champions the significant benefits of in-office collaboration by embracing a 70/30 work model. This 70% in-office structure helps to foster a culture rich in innovation, teamwork, and direct mentorship. Join us in shaping a world where every interaction is an opportunity to learn, contribute, and make a meaningful impact.Moderna is a smoke-free, alcohol-free, and drug-free work environment.Pay & BenefitsAt Moderna, we believe that when you feel your best, you can do your best work. That’s why our benefits and well-being resources are designed to support you—at work, at home, and everywhere in between.Competitive healthcare, plus voluntary benefit programs to support your unique needsA holistic approach to well-being, with access to fitness, mindfulness, and mental health supportFamily planning benefits, including fertility, adoption, and surrogacy supportGenerous paid time off, including vacation, volunteer days, sabbatical, global recharge days, and a discretionary year-end shutdownSavings and investments to help you plan for the futureLocation-specific perks and extrasThe salary range for this role is $145,900.00 - $234,200.00. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An individual’s position within the salary range will be based on several factors including, but not limited to, specific competencies, relevant education, qualifications, certifications, experience, skills, performance, and business or organizational needs. The successful candidate may be eligible for an annual discretionary bonus, other incentive compensation, or equity award, subject to company plan eligibility criteria and individual performance.About ModernaSince our founding in 2010, we have aspired to build the leading mRNA technology platform, the infrastructure to reimagine how medicines are created and delivered, and a world-class team. We believe in giving our people a platform to change medicine and an opportunity to change the world. By living our mission, values, and mindsets every day, our people are the driving force behind our scientific progress and our culture. Together, we are creating a culture of belonging and building an organization that cares deeply for our patients, our employees, the environment, and our communities. We are proud to have been recognized as a Science Magazine Top Biopharma Employer, a Fast Company Best Workplace for Innovators, and a Great Place to Work in the U.S. If you want to make a difference and join a team that is changing the future of medicine, we invite you to visit modernatx.com/careers to learn more about our current opportunities. Equal OpportunitiesModerna is committed to equal employment opportunity and non-discrimination for all employees and qualified applicants without regard to a person's race, color, sex, gender identity or expression, age, religion, national origin, ancestry or citizenship, ethnicity, disability, military or protected veteran status, genetic information, sexual orientation, marital or familial status, or any other personal characteristic protected under applicable law. Moderna is a place where everyone can grow. If you meet the Basic Qualifications for the role and you would be excited to contribute to our mission every day, please apply!Moderna is an E-Verify Employer in the United States. We consider qualified applicants regardless of criminal histories, consistent with legal requirements. AccommodationsWe’re focused on attracting, retaining, developing, and advancing our employees. By cultivating a workplace that values diverse experiences, backgrounds, and ideas, we create an environment where every employee can contribute their best. Moderna is committed to offering reasonable accommodations to qualified job applicants with disabilities. Any applicant requiring an accommodation in connection with the hiring process and/or to perform the essential functions of the position for which the applicant has applied should contact the Accommodations team at View email address on click.appcast.io. Export Control Notice This position may involve access to technology or data that is subject to U.S. export control laws, including the Export Administration Regulations (EAR). As such, employment is contingent upon the applicant’s ability to access export-controlled information in accordance with U.S. law. Due to the nature of the work and regulatory requirements, only individuals who qualify as U.S. persons (citizens, permanent residents, asylees, or refugees) are eligible for this position. For this role Moderna is unable to sponsor non-U.S. persons to apply for an export control license. -SummaryLocation: Cambridge, Massachusetts; DigitalType: Full time
$145.9k - $234.2k
The Role:Moderna Digital Core Governance, Risk and Compliance (GRC) is seeking a Risk Management Analyst to support the end-to-end third-party cybersecurity risk review process across Moderna. This role will help strengthen Moderna’s third-party cybersecurity risk management...CyberSeniorRiskPermanent employmentFull timeContract workWork experience placementFor subcontractorWork at officeWork from home$119k - $193k
...currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management leaders and their teams... ...deep knowledge and expertise in cyber risk quantification; and deep... ...topics: risk quantification, third‑party risk, systemic risk, compliance,...CyberSeniorRiskFor contractors$85k - $95k
Black Kite is the global leader in third‑party cyber risk intelligence, trusted by more than 3,000 organizations worldwide. We give security... ...earned consistent recognition from customers and industry analysts alike. WHY BLACK KITE We’re a fast‑moving, high‑impact team...CyberRiskWorldwideFlexible hours$100k - $117k
Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and...CyberSeniorRiskFull timeFlexible hours$150k - $180k
...Senior Technology Governance Analyst Location: Boston, MAJob Id... ...Utilizing your background in technology audit, risk management, and information security, you... ...in Computer Science, Information Systems, Cyber Security, or a related fieldPreferred certifications...CyberSeniorRiskWork at officeRemote workMonday to Friday$160k - $180k
...to join their Boston-based Technology Governance Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst. In this newly created role, the Technology... ...Technology risk, Technology audit/compliance, or cyber GRC.Experience running RCSAs, defining KRIs/KPIs...CyberSeniorRiskTemporary workFlexible hours$111k - $189k
...cybersecurity team at American Family Insurance. We're seeking a Cyber Threat Intelligence leader to advance the maturity and impact of... ...tools, and knowledge management practices.Communicate security risks and recommendations effectively to technical and non-technical stakeholders...CyberSeniorRiskFull timeLocal areaRelocation package$105.4k - $207.8k
Position Summary Cyber Security & Risk Strategy Senior Consultant Our Deloitte Cyber team understands the unique challenges and opportunities businesses face in cybersecurity. Join our team to deliver powerful solutions to help our clients navigate the ever-changing...CyberSeniorRiskLocal areaVisa sponsorship$105.4k - $207.8k
...regulations, and general knowledge of integrating technologies with third-party tools and APIs.Configure, integrate, test, and deploy privacy... ..., privacy impact assessments, incident response, third-party risk, etc.Knowledge of Data Privacy Laws and Regulations: Familiarity...CyberSeniorRiskLocal area$93.66k - $106.26k
...Counterintelligence Analyst Ensure the safety and security of our nation as a Counterintelligence... ...potential issues and mitigating risks associated with intelligence operations.... ...mission-ready capabilities in AI, cloud, cyber and software development. Equal Opportunity...CyberRiskTemporary workImmediate startRemote workWorldwideFlexible hours$141k - $176k
Bitsight is a cyber risk management leader transforming how companies manage exposure, performance... ...and risk for themselves and their third parties. Companies rely on Bitsight to... ...driven security challenges.Engage customers, analysts, and industry influencers to strengthen...CyberSeniorRiskFull timeRemote workFlexible hours$119k - $150k
Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their ecosystem, and...CyberSeniorRiskFull timeFlexible hours- ...opportunity for a motivated Operations Research Analyst to join MITRE’s Operations Analysis... ...sector, and serve as trusted third-party advisors to government sponsors on a variety... ...develop & code customized algorithms, identify risks, and incorporate domain-specific context,...SeniorRiskWork experience placementInternshipLocal areaImmediate startRemote work
- ...intrusion detection, threat detection/analysis, or information risk management preferred Experience with SIEM systems is a plus GIAC... ...communication skills Familiarity with malware analysis, computer forensics, cyber incident response, network intrusion detection, network traffic...CyberRisk
$140k - $187k
About This Role:As a Sr. Manager, Omnichannel Techno-Functional Business Analyst for Omnichannel in the Commercial Marketing data space, you will be a pivotal member... ...alongside MarTech delivery to avoid downstream risk.Proactively identify delivery risks, cross‑team dependencies...SeniorRiskFull timeTemporary workLocal area- ...SummaryAt Leader Bank, the Information Security Analyst is responsible for the daily operational... ...detection/analysis, or information risk management preferred.Experience with SIEM... ...as: malware analysis, computer forensics, cyber incident response, network intrusion...CyberRiskTemporary workWork at officeLocal area
- ...Cybersecurity to serve as the company’s Chief Information Security Officer, shaping the overall cybersecurity strategy and roadmap for risk-based protection of people, data, and IP. You will partner with CIO and business leaders to mature capabilities across...CyberSeniorRisk
- The Senior Technical Business Analyst will report to the Assistant CIO (ACIO) of Executive... ...conducting peer reviews, maintaining project risks and defects (In excel, Jira or other... ...integration. Experience managing and working with 3rd party vendors. Experienced in use cases and...SeniorRiskWork experience placementWork at officeRemote work
$90k - $157.5k
We are looking for a Threat Assurance Analyst (AVP) to join the Assurance Analysis team -... ...posture and provide assurance insights to our cyber partners and leadership.The ideal... ...investors rely on us to help them manage risk, respond to challenges, and drive performance...CyberRiskFull timeTemporary workFlexible hours$88k - $109.5k
...Senior Csm Bitsight is a cyber risk management leader transforming how companies manage exposure, performance, and risk for themselves and their third parties. Companies rely on Bitsight to prioritize their cybersecurity investments, build greater trust within their...CyberSeniorRiskFull timeWork experience placementRemote workFlexible hours- ...data-driven decisions in a rapidly evolving risk landscape. Here, you’ll be part of a team... ...-track your career as a Catastrophe Risk Analyst through our REACH Program.This is a 24-... ...natural catastrophes to cyber or political risks, you will play a pivotal...CyberRiskFull timeWork experience placementInternshipWork at officeLocal areaRemote workHome office
- ...applications technology platforms data integrations tools and third party services.Build and maintain a riskbased view of the enterprise... ...due diligence.Translate technical findings into clear business risk statements priorities remediation plans and executive decisions....CyberRisk
- ...is seeking a highly analytical and scientifically curious Senior Analyst to support strategic decision-making across our growing drug... ...-making; prioritize team over individual successTake calculated risks and challenge convention in the quest for exceptional outcomesAbout...SeniorRiskWork at office
$82.3k - $220k
...of technical challenges• Identify program/system-level technical risks and develop and execute mitigation strategies.• Actively mentor... ...tools• Knowledge of GN&C, avionics architectures, fault tolerance, cyber/security, comms/encryption, threat modeling or other...CyberSeniorRiskFull timeLocal area$90k - $115k
Senior Analyst, Paid MediaLocation: Cambridge, MA / Hybrid (This role requires working in-office 3 days per week: Tuesday, Wednesday, and... ...against monthly and quarterly targets; forecast spend and flag risk early.Serve as the primary day-to-day contact for our media agency...SeniorRiskFull timeWork at officeLocal area3 days per week$82.3k - $220k
...of technical challenges• Identify program/system-level technical risks and develop and execute mitigation strategies.• Actively mentor... ...tools• Knowledge of GN&C, avionics architectures, fault tolerance, cyber/security, comms/encryption, threat modeling or other...CyberSeniorRiskFull timeLocal area$95k - $110k
Title of role: Sr. Analyst, Growth Marketing- Google Shopping Location: New York or Boston; Hybrid (2 days in the office required) Approved... ...Communication & LeadershipInfluence leadership by articulating risks, opportunities, and growth paths through clear, concise...SeniorRiskFull timeWork at officeRemote workFlexible hoursShift workWeekend work$75k - $150k
...analyses to determine the viability of a proposed loan.Analyzes and understands financial statements and other documents to evaluate the risk profile of more complex transactions, which could include institutional ownership structures and site-specific matters.Conducts more...SeniorRiskFull timeTemporary workPart timeWork experience placementWork at office- ...Security, Risk and Compliance Consultant WHO WE LOOK FOR An SEI-er is amaster communicator and active listenerwho understands how to... ...Security Strategies/Programs/Controls Design and enablement of cyber controls functions and processes Change management related to regulatory...CyberRiskPermanent employmentWork experience placement
- ...Information TechnologyCGS is looking for business analysts to work with a large federal agency! As a... ...voice across all documentationPerform risk management, including identifying,... ...AnalyticsProject Management, Agile, and/or Cyber Certifications (PMP / ACP / CSM / SAFe /...CyberRiskFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. Cyber Risk 3rd Party Analyst. Be the first to apply!
- senior mulesoft developer Somerville, MA
- senior mainframe developer Somerville, MA
- senior level Somerville, MA
- senior network engineer remote Somerville, MA
- senior manager product development Somerville, MA
- senior implementation engineer Somerville, MA
- senior manager creative operations Somerville, MA
- senior medical science liaison Somerville, MA
- senior manager m&a tax Somerville, MA
- senior manager product engineering Somerville, MA


