ActiveJobs

Senior Manager, Emerging Technology Risk

Bristol-Myers Squibb (BMS) · Hyderabad - TS - IN

Full-timeOn-sitePosted 25 August 2026
Apply on Company Site →

Job description

Working with Us Challenging. Meaningful. Life-changing. Those aren’t words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You’ll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams. Take your career farther than you thought possible. Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives. Read more: careers.bms.com/working-with-us. AccountabilitiesSpecialized-level role that requires depth and/or breadth of expertise in own discipline. Serves as an expert resource on functional teams or projects. Projects may focus on continuous improvement or development of new approaches or technologies. Key ResponsibilitiesSupport the implementation and ongoing maintenance of BMS's AI governance framework, including archetype-based control models covering risk classification, control objectives, implementation patterns, and acceptable evidence standards. Conduct structured risk assessments of AI and GenAI tools being considered for enterprise adoption, evaluating each against BMS's risk appetite, security standards, and regulatory obligations prior to deployment approval. Execute AI risk and conformity assessments aligned to EU AI Act, NIST AI RMF, ISO/IEC 42001, and applicable global privacy regulations (GDPR, EDPB, state-level AI laws), including risk classification for use cases across Clinical, Commercial, and R&D domains. Assess GenAI tools and LLM deployments — including Claude (via AWS Bedrock), ChatGPT, and other third-party services — for data privacy, contractual, and data residency implications; document findings and escalate issues as appropriate. Partner with business and technology stakeholders to document and track controls for approved AI technologies, ensuring controls are practical, embedded in workflows, and aligned to identified risks. Execute control testing activities for AI-specific controls, including pre-deployment validation, post-deployment effectiveness testing, and periodic re-assessments; document results, gaps, and remediation plans and track findings through to closure. Maintain GRC platform records (ServiceNow, OneTrust) for AI risk assessments, control testing results, and issue tracking, ensuring data quality and audit readiness at all times. Prepare risk assessment summaries, control testing reports, and governance dashboards to support leadership reporting and stakeholder communications. Monitor the evolving AI regulatory landscape — including EU AI Act developments, NIST updates, and emerging state-level AI laws — and summarize implications for BMS programs. Support the tracking and assessment of risks from next-generation AI capabilities including agentic AI, multi-modal GenAI, synthetic data pipelines, and quantum-accelerated inference. Qualifications & RequirementsEducationBachelor's degree required in Information Security, Computer Science, Risk Management, Data Science, or a related field. Experience — Required8–10 years of progressive experience in GRC, information security, or technology risk, with at least 1–2 years directly focused on AI, emerging technology, or data governance. Hands-on experience executing GRC control assessments or technology risk reviews in a large, complex enterprise environment. Working knowledge of AI governance frameworks: NIST AI RMF, EU AI Act, and/or ISO/IEC 42001 or 23894. Familiarity with LLM/GenAI risk concepts including prompt injection, hallucination risk, IP leakage, and training data privacy. Understanding of cloud-based AI deployment architectures and data residency/privacy implications of BMS-controlled vs. third-party SaaS environments. Strong analytical, documentation, and communication skills with the ability to translate technical risk findings into clear, actionable outputs. Ability to work effectively in a global, cross-timezone environment with onshore and offshore teams. Experience — PreferredExperience in Life Sciences, Pharma, or a highly regulated industry (FDA oversight, GxP, clinical data governance). Exposure to AI gateway architecture, API security controls, and control plane governance. Familiarity with agentic AI systems, model cards, data lineage frameworks, and model lifecycle governance. Experience with GRC platform tooling (ServiceNow, OneTrust). Certifications — Highly ValuedGARP RAI (Responsible AI) Certificate CISA or Security+ (for broader security context) If you come across a role that intrigues you but doesn’t perfectly line up with your resume, we encourage you to apply anyway. You could be one step away from work that will transform your life and career. Uniquely Interesting Work, Life-changing Careers With a single vision as inspiring as “Transforming patients’ lives through science™ ”, every BMS employee plays an integral role in work that goes far beyond ordinary. Each of us is empowered to apply our individual talents and unique perspectives in a supportive culture, promoting global participation in clinical trials, while our shared values of passion, innovation, urgency, accountability, inclusion and integrity bring out the highest potential of each of our colleagues. On-site Protocol BMS has an occupancy structure that determines where an employee is required to conduct their work. This structure includes site-essential, site-by-design, field-based and remote-by-design jobs. The occupancy type that you are assigned is determined by the nature and responsibilities of your role: Site-essential roles require 100% of shifts onsite at your assigned facility. Site-by-design roles may be eligible for a hybrid work model with at least 50% onsite at your assigned facility. For these roles, onsite presence is considered an essential job function and is critical to collaboration, innovation, productivity, and a positive Company culture. For field-based and remote-by-design roles the ability to physically travel to visit customers, patients or business partners and to attend meetings on behalf of BMS as directed is an essential job function. Supporting People with Disabilities BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to adastaffingsupport@bms.com. Visit careers.bms.com/eeo-accessibility to access our complete Equal Employment Opportunity statement. Candidate Rights BMS will consider for employment qualified applicants with arrest and conviction records, pursuant to applicable laws in your area. If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: https://careers.bms.com/california-residents/ Data Protection We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https://careers.bms.com/fraud-protection. Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations. If you believe that the job posting is missing information required by local law or incorrect in any way, please contact BMS at TAEnab

Verified and listed by ActiveJobs. Applications are made directly on Bristol-Myers Squibb (BMS)'s own career page — we never sit in the middle.