Senior Manager, Emerging Technology Risk
Bristol-Myers Squibb
- Location
- Hyderabad - TS - IN
- Work model
- On-Site
- Level
- Senior
- H-1B history
- 57 approvals (FY2023)
- Posted
- Aug 25, 2026
Skills
About this role
Working with Us Challenging. Meaningful. Life-changing. Those aren’t words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You’ll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams. Take your career farther than you thought possible. Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives. Read more: careers.bms.com/working-with-us . Accountabilities Specialized-level role that requires depth and/or breadth of expertise in own discipline. Serves as an expert resource on functional teams or projects. Projects may focus on continuous improvement or development of new approaches or technologies.
Key Responsibilities
Support the implementation and ongoing maintenance of BMS's AI governance framework, including archetype-based control models covering risk classification, control objectives, implementation patterns, and acceptable evidence standards. Conduct structured risk assessments of AI and GenAI tools being considered for enterprise adoption, evaluating each against BMS's risk appetite, security standards, and regulatory obligations prior to deployment approval. Execute AI risk and conformity assessments aligned to EU AI Act, NIST AI RMF, ISO/IEC 42001, and applicable global privacy regulations (GDPR, EDPB, state-level AI laws), including risk classification for use cases across Clinical, Commercial, and R&D domains. Assess GenAI tools and LLM deployments — including Claude (via AWS Bedrock), ChatGPT, and other third-party services — for data privacy, contractual, and data residency implications; document findings and escalate issues as appropriate. Partner with business and technology stakeholders to document and track controls for approved AI technologies, ensuring controls are practical, embedded in workflows, and aligned to identified risks. Execute control testing activities for AI-specific controls, including pre-deployment validation, post-deployment effectiveness testing, and periodic re-assessments; document results, gaps, and remediation plans and track findings through to closure. Maintain GRC platform records (ServiceNow, OneTrust) for AI risk assessments, control testing results, and issue tracking, ensuring data quality and audit readiness at all times. Prepare risk assessment summaries, control testing reports, and governance dashboards to support leadership reporting and stakeholder communications. Monitor the evolving AI regulatory landscape — including EU AI Act developments, NIST updates, and emerging state-level AI laws — and summarize implications for BMS programs. Support the tracking and assessment of risks from next-generation AI capabilities including agentic AI, multi-modal GenAI, synthetic data pipelines, and quantum-accelerated inference. Qualifications & Requirements Education Bachelor's degree required in Information Security, Computer Science, Risk Management, Data Science, or a related field. Experience — Required 8–10 years of progressive experience in GRC, information security, or technology risk, with at least 1–2 years directly focused on AI, emerging technology, or data governance. Hands-on experience executing GRC control assessments or technology risk reviews in a large, complex enterprise environment. Working knowledge of AI governance frameworks: NIST AI RMF, EU AI Act, and/or ISO/IEC 42001 or 23894. Familiarity with LLM/GenAI risk concepts including prompt injection, hallucination risk, IP leakage,