Job description
The Role: Moderna Digital Core Governance, Risk and Compliance (GRC) is seeking a Risk Management Analyst to support the identification, assessment, monitoring, and reporting of technology, cybersecurity and emerging risks across Moderna. This role will help strengthen Moderna’s risk management practices by supporting risk assessments, control evaluations, issue tracking, governance reporting, process documentation, and cross-functional engagement. The Risk Analyst will play a key role in helping the organization understand risk exposure, prioritize remediation activities, improve control maturity, and maintain clear, accurate, and actionable risk data in a regulated life sciences environment. This individual will also support AI-readiness and digital transformation initiatives by documenting risk management requirements, control expectations, process flows, decision points, evidence needs, and governance requirements that enable automation, repeatable processes, and responsible agentic workflows. To excel in this role, the Risk Analyst should have strong analytical, communication, and organizational skills, excellent attention to detail, hands-on experience working in GxP-regulated environments, a solid understanding of cybersecurity and technology risk concepts, and curiosity about emerging risks, including risks introduced by artificial intelligence, automation, AI-assisted engineering, agentic workflows, data pipelines, digital platforms, and evolving regulatory expectations. Here's What You’ll Do: Support the identification, assessment, monitoring, and reporting of digital, technology, cybersecurity, and emerging risks across Moderna, including risks related to applications, infrastructure, data, business processes, third parties, AI, automation, and GxP-regulated environments. Conduct and support risk assessments to evaluate risk exposure, control effectiveness, residual risk, issue severity, remediation needs, and appropriate risk treatment recommendations. Partner with technology, cybersecurity, quality, privacy, legal, business, and other cross-functional stakeholders to gather information, validate risks and controls, align on remediation plans, and support timely risk-based decision-making. Support control evaluations and issue management activities, including documenting control gaps, tracking remediation commitments, monitoring action plans, and escalating risks or delays when appropriate. Maintain accurate, complete, and actionable risk data in GRC systems and related repositories to support governance reporting, auditability, transparency, and trend analysis. Prepare risk reporting, metrics, dashboards, and executive-ready summaries that communicate key risks, control gaps, remediation status, trends, and decision points to stakeholders and governance forums. Analyze risk trends across assessments, issues, controls, platforms, business processes, third parties, GxP impacts, AI use cases, and emerging technologies to help mature Moderna’s risk management program. Support the use of AI, automation, and agentic workflows to improve risk management processes by documenting requirements, decision logic, control expectations, evidence needs, escalation points, and human oversight requirements. Develop and maintain process documentation, procedures, templates, workflows, and guidance materials that support consistent, repeatable, and scalable risk management practices. Additional tasks as needed Here’s What You’ll Bring to the Table (Minimum Qualifications) 5+ years of experience in a similar or related position, including experience with cybersecurity risk management, technology risk management, enterprise risk management, IT controls, compliance, or GRC. Experience supporting or conducting risk assessments, control evaluations, issue management, remediation tracking, risk reporting, and governance activities. Sound judgment to identify when risks, control gaps, contractual concerns, or remediation delays require escalation to drive timely decision-making and appropriate risk treatment. Experience working in a GxP-regulated environment is required. Strong written and verbal communication skills, including the ability to communicate cybersecurity risk concepts and control expectations to technical and non-technical stakeholders. Experience using AI to optimize, augment, or streamline risk analysis, documentation, reporting, workflow management, or stakeholder communications. Proven ability to operate in highly matrixed environments and influence without direct authority. Preferred Qualifications (Preferred Qualifications): Four-year degree or equivalent relevant work experience preferred, ideally in information systems, cybersecurity, or risk management. Familiarity with third-party cybersecurity risk frameworks and assessment standards such as NIST CSF, ISO 27001, CIS Controls, COBIT, ITIL, or similar frameworks. Experience with GRC, workflow, reporting, and collaboration tools such as OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools. Experience supporting risk governance processes, including risk registers, issue tracking, control assessments, metrics, dashboards, governance forums, and executive reporting. Strong attention to detail and commitment to data integrity, auditability, consistent documentation, and transparent risk reporting. Influential, inclusive, and trusted partner compassionate to the needs and situations of all your stakeholders </
Stand out for this role
NoxPharm tailors your CV to this job description by aligning your experience with the role requirements and terminology. Built for pharma & life sciences.
Tailor my CV now — free to trySimilar Pharma jobs
Associate, Project Management (Pharmaceutical Labeling)
Open Scientific — Hauppauge, us
Maintenance Coordinator
Open Scientific — Bohemia, us
Manufacturing Operators - Pharmaceutical
Open Scientific — Melville, us
Pharmaceutical Mechanics - Packaging, Production, Maintanence
Open Scientific — Hauppauge, us
Warehouse - Pharmaceutical
Open Scientific — Hauppauge, us
Pharmaceutical Machine Operators
Open Scientific — Hauppauge, us