Senior Manager, Emerging Technology Risk
- Bristol Myers Squibb
- Hyderābād, India
- INR 4,000,000 – INR 6,000,000
At Bristol Myers Squibb, our employees often ask, “Who are you working for?”—a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.
Accountabilities
Specialized-level role that requires depth and/or breadth of expertise in own discipline.
Serves as an expert resource on functional teams or projects. Projects may focus on continuous improvement or development of new approaches or technologies.
Key Responsibilities
Support the implementation and ongoing maintenance of BMS's AI governance framework, including archetype-based control models covering risk classification, control objectives, implementation patterns, and acceptable evidence standards.
Conduct structured risk assessments of AI and GenAI tools being considered for enterprise adoption, evaluating each against BMS's risk appetite, security standards, and regulatory obligations prior to deployment approval.
Execute AI risk and conformity assessments aligned to EU AI Act, NIST AI RMF, ISO/IEC 42001, and applicable global privacy regulations (GDPR, EDPB, state-level AI laws), including risk classification for use cases across Clinical, Commercial, and R&D domains.
Assess GenAI tools and LLM deployments — including Claude (via AWS Bedrock), ChatGPT, and other third-party services — for data privacy, contractual, and data residency implications; document findings and escalate issues as appropriate.
Partner with business and technology stakeholders to document and track controls for approved AI technologies, ensuring controls are practical, embedded in workflows, and aligned to identified risks.
Execute control testing activities for AI-specific controls, including pre-deployment validation, post-deployment effectiveness testing, and periodic re-assessments; document results, gaps, and remediation plans and track findings through to closure.
Maintain GRC platform records (ServiceNow, OneTrust) for AI risk assessments, control testing results, and issue tracking, ensuring data quality and audit readiness at all times.
Prepare risk assessment summaries, control testing reports, and governance dashboards to support leadership reporting and stakeholder communications.
Monitor the evolving AI regulatory landscape — including EU AI Act developments, NIST updates, and emerging state-level AI laws — and summarize implications for BMS programs.
Support the tracking and assessment of risks from next-generation AI capabilities including agentic AI, multi-modal GenAI, synthetic data pipelines, and quantum-accelerated inference.
Qualifications & Requirements
Education
- Bachelor's degree required in Information Security, Computer Science, Risk Management, Data Science, or a related field.
Experience — Required
8–10 years of progressive experience in GRC, information security, or technology risk, with at least 1–2 years directly focused on AI, emerging technology, or data governance.
Hands-on experience executing GRC control assessments or technology risk reviews in a large, complex enterprise environment.
Working knowledge of AI governance frameworks: NIST AI RMF, EU AI Act, and/or ISO/IEC 42001 or 23894.
Familiarity with LLM/GenAI risk concepts including prompt injection, hallucination risk, IP leakage, and training data privacy.
Understanding of cloud-based AI deployment architectures and data residency/privacy implications of BMS-controlled vs. third-party SaaS environments.
Strong analytical, documentation, and communication skills with the ability to translate technical risk findings into clear, actionable outputs.
Ability to work effectively in a global, cross-timezone environment with onshore and offshore teams.
Experience — Preferred
Experience in Life Sciences, Pharma, or a highly regulated industry (FDA oversight, GxP, clinical data governance).
Exposure to AI gateway architecture, API security controls, and control plane governance.
Familiarity with agentic AI systems, model cards, data lineage frameworks, and model lifecycle governance.
Experience with GRC platform tooling (ServiceNow, OneTrust).
Certifications — Highly Valued
GARP RAI (Responsible AI) Certificate
CISA or Security+ (for broader security context)
We hire for skills and capabilities, not just credentials – if this role excites you, but doesn’t perfectly match your resume, we encourage you to apply anyway.
How We Work
Where you work matters – because collaboration, innovation and patient impact happen in many settings. Our roles are structured across four work models: site-essential, site-by-design, field-based and remote-by-design. The model assigned to this role is based on its core responsibilities. Learn more at https://careers.bms.com/ways-of-working.
Supporting People with Disabilities
BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to adastaffingsupport@bms.com. Visit careers.bms.com/eeo-accessibility to access our complete Equal Employment Opportunity statement.
Candidate Rights
BMS will consider qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.
For roles based in Los Angeles County only: If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: https://careers.bms.com/california-residents/
Data Protection
We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https://careers.bms.com/fraud-protection.
Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.
If this posting is missing required information required by local law or incorrect, contact BMS at TAEnablement@bms.com with the Job Title and Requisition number. Do not send application-related inquiries to this email. To check your application status, please login to your Candidate Home Account.
R1605475 : Senior Manager, Emerging Technology Risk
Skills
- AI governance
- Risk assessment
- EU AI Act
- NIST AI RMF
- ISO/IEC 42001
- GDPR
- GenAI









