CareerMoonshot

Senior Risk Management Analyst

Modernatx

via workdayFirst listed here 2026-09-21
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to Modernatx.
If you’re interested in this role, please apply in English and include an English version of your Resume/CV.   The Role: Joining Moderna means advancing mRNA science to transform medicine. Work with exceptional global teams on a broad pipeline and build a career that makes a real difference for patients. Moderna is strengthening its international business services hub in Warsaw, supporting our growing global operations. We welcome professionals ready to help advance our mission and shape the future of mRNA medicines. Join Moderna Digital Core Governance, Risk and Compliance (GRC) as an individual contributor helping strengthen how we identify, assess, monitor, and communicate technology, cybersecurity, and emerging risks across the organization. You’ll turn complex risk and control information into clear, actionable insight, enabling teams to understand risk exposure, prioritize remediation, improve control maturity, and maintain accurate and auditable risk data in a highly regulated life sciences environment. Working across technology, cybersecurity, quality, privacy, legal, and business teams, you’ll support risk assessments, control evaluations, issue management, governance reporting, process documentation, and risk-based decision-making. You’ll bring hands-on understanding of GxP-regulated environments together with strong analytical rigor and knowledge of cybersecurity and technology risk concepts. This is also an opportunity to help shape the next generation of risk management at Moderna. You’ll get close to Generative AI, automation, AI-assisted engineering, agentic workflows, data pipelines, and digital platforms—documenting the risk requirements, decision logic, controls, evidence, escalation points, and human oversight needed to make increasingly automated processes responsible, repeatable, scalable, and AI-ready. Here's What You'll Do: Support the identification, assessment, monitoring, and reporting of digital, technology, cybersecurity, and emerging risks across Moderna, including risks associated with applications, infrastructure, data, business processes, third parties, AI, automation, and GxP-regulated environments. Conduct and support risk assessments to evaluate risk exposure, control effectiveness, residual risk, issue severity, remediation needs, and appropriate risk treatment recommendations. Partner cross-functionally with technology, cybersecurity, quality, privacy, legal, business, and other stakeholders to gather information, validate risks and controls, align on remediation plans, and enable timely, risk-based decision-making. Support control evaluations and issue management activities, including documenting control gaps, tracking remediation commitments, monitoring action plans, and escalating risks or delays when appropriate. Maintain accurate, complete, and actionable risk data within GRC systems and related repositories, strengthening governance reporting, auditability, transparency, and trend analysis. Prepare risk reporting, metrics, dashboards, and executive-ready summaries that clearly communicate key risks, control gaps, remediation status, trends, and decision points to stakeholders and governance forums. Analyze risk trends across assessments, issues, controls, platforms, business processes, third parties, GxP impacts, AI use cases, and emerging technologies to generate insights that help mature Moderna’s risk management program. Support the use of AI, automation, and agentic workflows to improve risk management processes by documenting requirements, decision logic, control expectations, evidence needs, escalation points, and human oversight requirements. Help enable AI-readiness and digital transformation initiatives by translating risk management and governance needs into documented requirements, process flows, decision points, control expectations, and evidence requirements that can support automation and repeatable processes. Develop and maintain process documentation, procedures, templates, workflows, and guidance materials that enable consistent, repeatable, and scalable risk management practices. Apply strong analytical, communication, and organizational skills, with excellent attention to detail, to help stakeholders understand risk exposure and prioritize appropriate remediation activities. Bring hands-on experience working in GxP-regulated environments and a solid understanding of cybersecurity and technology risk concepts to risk and control activities within a regulated life sciences environment. Stay curious about evolving and emerging risks, including those introduced by artificial intelligence, automation, AI-assisted engineering, agentic workflows, data pipelines, digital platforms, and evolving regulatory expectations. Take on additional tasks as needed to support Digital Core GRC and Moderna’s broader risk management objectives. The key Moderna Mindsets you’ll need to succeed in the role: We digitize everywhere possible using the power of code to maximize our impact on patients. We obsess over learning. We don’t have to be the smartest we have to learn the fastest. Here’s What You’ll Bring to the Table (Minimum Qualifications)    5+ years of experience in a similar or related position, including experience with cybersecurity risk management, technology risk management, enterprise risk management, IT controls, compliance, or GRC.  Experience supporting or conducting risk assessments, control evaluations, issue management, remediation tracking, risk reporting, and governance activities.  Sound judgment to identify when risks, control gaps, contractual concerns, or remediation delays require escalation to drive timely decision-making and appropriate risk treatment.  Experience working in a GxP-regulated environment is required.  Strong written and verbal communication skills, including the ability to communicate cybersecurity risk concepts and control expe

Browse all locations