Skip to main content
Moderna logo

Sr. Cyber Risk 3rd Party Analyst

Moderna
October 2, 2026
Full-time
Remote friendly (Cambridge, MA)
Worldwide
IT
Role: Support Modernaโ€™s third-party cybersecurity risk management as a Risk Management Analyst. Primary objectives include end-to-end oversight of third-party cybersecurity assessments, risk analysis, control gap identification, remediation tracking, and governance reporting within a regulated life sciences environment. Responsibilities encompass reviewing cybersecurity assessments to identify control deficiencies, supporting contract negotiations related to cybersecurity controls, and partnering with Legal, Privacy, Procurement, and technical stakeholders to align risk decisions and remediation efforts. The role also involves analyzing risk trends across vendors, AI capabilities, and GxP impacts, and advancing automation and workflow improvements. Qualifications: 5+ years in cybersecurity risk management, third-party risk, or GRC, with experience in cybersecurity assessment analysis, risk disposition, remediation, and supporting cybersecurity contract negotiations. Must have experience in GxP-regulated settings, strong communication skills, and familiarity with AI-driven risk processes. Preferred: Degree in information systems, cybersecurity, or risk management; knowledge of frameworks like NIST CSF, ISO 27001; experience with GRC tools such as ServiceNow, Jira, Power BI; and a detail-oriented approach supporting transparent risk reporting. High-Value: Focus on third-party cybersecurity risk within a life sciences context, including AI-enabled services, with emphasis on regulated processes and cross-functional collaboration. Work setup follows a 70/30 in-office model with some flexibility. Travel is not specified.