Senior Risk Management Analyst
On-siteWarsaw, Mazovia, Poland
Job Summary
Own the end-to-end third-party cybersecurity risk review process, from intake and assessment scoping through risk analysis, stakeholder follow-up, remediation tracking, risk disposition, and governance reporting. Review completed assessments to identify control gaps, residual risks, compensating controls, and remediation requirements, while supporting contract negotiations by advising on cybersecurity addenda and control standards. Partner with Legal, Privacy, Procurement, and technical stakeholders to align risk decisions, contractual obligations, and governance expectations within a GxP-regulated environment. Analyze risk trends across vendors, AI capabilities, and fourth-party dependencies to strengthen the organization's third-party cybersecurity posture. Support the adoption of automation and agentic workflows by documenting business requirements and control expectations to enable scalable risk processes. Contribute to governance reporting, process documentation, and continuous improvement initiatives to enhance cybersecurity risk management maturity.
Required Qualifications
- 5+ years of experience in a similar or related position, including experience with standard concepts within cybersecurity risk management, third-party risk management, or GRC
- Experience owning or supporting third-party cybersecurity risk reviews, including assessment analysis, risk disposition, remediation tracking, documentation, reporting, and cybersecurity addendum support during contract negotiations
- Sound judgment to identify when risks, control gaps, contractual concerns, or remediation delays require escalation to drive timely decision-making and appropriate risk treatment
- Experience working in a GxP-regulated environment is required
- Strong written and verbal communication skills, including the ability to communicate cybersecurity risk concepts and control expectations to technical and non-technical stakeholders
- Experience using AI to optimize, augment, or streamline risk analysis, documentation, reporting, workflow management, or stakeholder communications
- Proven ability to operate in highly matrixed environments and influence without direct authority
Desired Qualifications
- Four-year degree or equivalent relevant work experience preferred, ideally in information systems, cybersecurity, or risk management
- Familiarity with third-party cybersecurity risk frameworks and assessment standards such as NIST CSF, ISO 27001, CIS Controls, SIG, CAIQ, or similar frameworks
- Experience with GRC, workflow, reporting, and collaboration tools such as OneTrust, ServiceNow, Jira, Power BI, Excel, SharePoint, or similar tools
- Strong attention to detail and commitment to data integrity, auditability, consistent documentation, and transparent risk reporting
- Influential, inclusive, and trusted partner compassionate to the needs and situations of all your stakeholders
- Embrace a culture of continuous service improvement and service excellence
- A desire to make an impact as part of a high-growth, transformational company
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.