Senior Risk Analyst

Bristol-Myers Squibb Co

Hyderabad

On-site

INR 1,800,000 - 3,200,000

Full time

5 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Bristol Myers Squibb is seeking a Senior Risk Analyst Data Privacy in Hyderabad to act as the analytical authority on complex risk cases, provide advisory support to IT leadership and stakeholders, and ensure quality risk determinations across programs. The role emphasizes governance, continuous monitoring, and collaboration with Legal, Privacy, IT, and Compliance teams.

Responsibilities include guiding analysts, maintaining risk records, and advancing the integrated risk framework while

Qualifications

  • Required 5–10 years of progressive experience in IT risk management, cybersecurity risk, IT audit, privacy compliance, or a closely related field.
  • Demonstrated track record of independent, senior-level risk judgment — including experience handling complex, ambiguous, or high-stakes risk determinations.
  • Deep knowledge of NIST Cyber Risk Management Framework, NIST 800-53 controls library, and at least one major privacy regulatory framework (GDPR, EU AI Act, GxP, CCPA).
  • Experience working with GRC platforms at an advanced level (ServiceNow GRC or equivalent).
  • Strong executive communication skills; experience preparing and presenting risk findings to senior leadership or audit/compliance audiences.
  • Experience with AI/ML, automation, or emerging technology risk programs — including digital transformation and data privacy risk governance.

Responsibilities

  • Serve as the senior analytical authority for complex, high-tier risk cases — including Cyber Risk, AI risk, cross-jurisdictional privacy complexity, and novel technology types not clearly addressed by existing framework
  • Provide risk advisory support to IT leadership, BISOs, Legal/Privacy, and business stakeholders — translating complex risk landscapes into clear, actionable guidance
  • Own the integrity of the risk determination record for high-profile or sensitive programs; provide independent review where risk signals are ambiguous or where determinations carry material business or regulatory consequence
  • Guide analysts on when to accept, challenge, elevate, or override risk outputs — serving as a calibration resource and quality anchor for the team
  • Monitor patterns across risk assessments — override rates, exception volumes, flag frequencies — to identify systematic accuracy issues, framework gaps, or emerging risk themes
  • Support continuous monitoring initiatives and contribute to the evolution of BMS's integrated risk framework (Scope Screening → Regulatory Classification → Risk‑Tiered Controls) as the operating model matures
  • Identify where the risk tiering model, control library, or assessment logic may need refinement; articulate improvement recommendations with supporting evidence to Risk Leads and leadership
  • Contribute to periodic reviews of auto‑approved projects, leading structured assessments where findings may have broader programmatic implications
  • Lead engagement with senior project sponsors, IT architects, Legal/Privacy SMEs, and Compliance teams on high‑risk or high‑complexity assessments
  • Represent the IT Risk function in cross‑functional forums; provide subject matter expertise on regulatory risk implications (GDPR, EU AI Act, GxP, NIST frameworks)
  • Build and maintain strong partnerships across IT, Legal, Privacy, Cybersecurity, and Business functions; act as a trusted advisor rather than a compliance gatekeeper
  • Support escalation resolution between Risk Leads, BISOs, Privacy SMEs, and project teams; facilitate closure on disputes involving risk determinations and framework interpretation
  • Ensure audit‑ready documentation standards across the team; review and validate complex SNOW and GRC records for accuracy, completeness, and audit defensibility
  • Contribute to or lead training initiatives for analysts on evolving framework components, updated risk tiering logic, and operational workflow changes
  • Support governance reporting; prepare executive‑quality risk summaries, trend analyses, and control attestation packages for senior leadership and compliance audiences
  • Provide UAT support for framework and tooling updates — including validating that risk outputs align with expected SME‑level determinations
  • Provide mentorship and guidance to junior analysts; support calibration, quality review, and professional development within the team
  • Model the expected analyst behavior in an automation‑enabled environment: review‑first, judgment‑driven, override with rationale, and elevate with clarity

Skills

Risk judgment
IT risk management
Cyber risk
Privacy compliance
GRC platforms
Executive communication
AI/ML risk
Automation
Regulatory frameworks

Tools

ServiceNow GRC

Job description

At Bristol Myers Squibb, our employees often ask, “Who are you working for?”—a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.

Key Responsibilities
Senior Risk Judgment & Advisory

Serve as the senior analytical authority for complex, high-tier risk cases — including Cyber Risk, AI risk, cross-jurisdictional privacy complexity, and novel technology types not clearly addressed by existing framework

Provide risk advisory support to IT leadership, BISOs, Legal/Privacy, and business stakeholders — translating complex risk landscapes into clear, actionable guidance

Own the integrity of the risk determination record for high-profile or sensitive programs; provide independent review where risk signals are ambiguous or where determinations carry material business or regulatory consequence

Guide analysts on when to accept, challenge, elevate, or override risk outputs — serving as a calibration resource and quality anchor for the team

Framework Stewardship & Continuous Monitoring

Monitor patterns across risk assessments — override rates, exception volumes, flag frequencies — to identify systematic accuracy issues, framework gaps, or emerging risk themes

Support continuous monitoring initiatives and contribute to the evolution of BMS's integrated risk framework (Scope Screening → Regulatory Classification → Risk‑Tiered Controls) as the operating model matures

Identify where the risk tiering model, control library, or assessment logic may need refinement; articulate improvement recommendations with supporting evidence to Risk Leads and leadership

Contribute to periodic reviews of auto‑approved projects, leading structured assessments where findings may have broader programmatic implications

Stakeholder Leadership & Cross‑Functional Engagement

Lead engagement with senior project sponsors, IT architects, Legal/Privacy SMEs, and Compliance teams on high‑risk or high‑complexity assessments

Represent the IT Risk function in cross‑functional forums; provide subject matter expertise on regulatory risk implications (GDPR, EU AI Act, GxP, NIST frameworks)

Build and maintain strong partnerships across IT, Legal, Privacy, Cybersecurity, and Business functions; act as a trusted advisor rather than a compliance gatekeeper

Support escalation resolution between Risk Leads, BISOs, Privacy SMEs, and project teams; facilitate closure on disputes involving risk determinations and framework interpretation

Operational Excellence & Governance

Ensure audit‑ready documentation standards across the team; review and validate complex SNOW and GRC records for accuracy, completeness, and audit defensibility

Contribute to or lead training initiatives for analysts on evolving framework components, updated risk tiering logic, and operational workflow changes

Support governance reporting; prepare executive‑quality risk summaries, trend analyses, and control attestation packages for senior leadership and compliance audiences

Provide UAT support for framework and tooling updates — including validating that risk outputs align with expected SME‑level determinations

Mentorship & Team Development

Provide mentorship and guidance to junior analysts; support calibration, quality review, and professional development within the team

Model the expected analyst behavior in an automation‑enabled environment: review‑first, judgment‑driven, override with rationale, and elevate with clarity

Qualifications & Experience

Required 5–10 years of progressive experience in IT risk management, cybersecurity risk, IT audit, privacy compliance, or a closely related field

Demonstrated track record of independent, senior‑level risk judgment — including experience handling complex, ambiguous, or high‑stakes risk determinations

Deep knowledge of NIST Cyber Risk Management Framework, NIST 800‑53 controls library, and at least one major privacy regulatory framework (GDPR, EU AI Act, GxP, CCPA)

Experience working with GRC platforms at an advanced level (ServiceNow GRC or equivalent); ability to review, validate, and ensure quality of records produced by others

Strong executive communication skills; experience preparing and presenting risk findings to senior leadership or audit/compliance audiences

Experience with AI/ML, automation, or emerging technology risk programs — including digital transformation and data privacy risk governance

Desired Candidate Characteristics

Highly developed risk judgment — able to form defensible, well‑reasoned positions on complex determinations and explain them clearly to any audience

Advisory mindset: seen as a trusted partner by stakeholders, not just a process owner

Comfortable with automation and system‑generated risk signals as primary inputs — focused on interpreting and acting rather than manually gathering data

Strategic thinker with an eye on where the risk function is heading, not just where it is today

Strong influencer and collaborator; able to drive alignment across Legal, Privacy, IT, and Business without formal authority

Passion for healthcare and the belief that excellent risk management enables better science and better patient outcomes

How We Work

Where you work matters – because collaboration, innovation and patient impact happen in many settings. Our roles are structured across four work models: site‑essential, site‑by‑design, field‑based and remote‑by‑design. The model assigned to this role is based on its core responsibilities. Learn more at https://careers.bms.com/ways‑of‑working.

Supporting People with Disabilities

BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer.

If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to adastaffingsupport@bms.com. Visit careers.bms.com/eeo‑accessibility to access our complete Equal Employment Opportunity statement.

Candidate Rights

BMS will consider qualified applicants with arrest and conviction records, pursuant to applicable laws in your area. For roles based in Los Angeles County only: If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: https://careers.bms.com/california‑residents/

Data Protection

We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https://careers.bms.com/fraud‑protection.

Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations. If this posting is missing required information required by local law or incorrect, contact BMS at TAEnablement@bms.com with the Job Title and Requisition number. Do not send application‑related inquiries to this email. To check your application status, please login to your Candidate Home Account.

R1606940 : Senior Risk Analyst Data Privacy

We’re creating innovative medicines for patients fighting serious diseases. We’re also nurturing our own diverse team with inspiring work and challenging career options. No matter the role, each one of us makes a contribution. And that makes all the difference.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Risk Analyst II
Risk Analyst II

Bristol Myers Squibb • Hyderabad

On-site
INR 1,400,000 - 1,800,000
Internal Audit Analyst III, Global Internal Audit & Assurance
Internal Audit Analyst III, Global Internal Audit & Assurance

Bristol Myers Squibb EU Policy • Hyderabad

On-site
INR 1,800,000 - 2,600,000
Software Development Engineer III, AI Data Engineering
Software Development Engineer III, AI Data Engineering

Bristol Myers Squibb • Hyderabad

On-site
INR 3,000,000 - 6,000,000
Data Science Manager
Data Science Manager

Bristol Myers Squibb • Hyderabad

On-site
INR 2,800,000 - 3,800,000
Sr. Global Trial Acceleration Associate
Sr. Global Trial Acceleration Associate

Bristol-Myers Squibb Co • Hyderabad

On-site
INR 1,200,000 - 1,800,000
Analyst, Perception Analytics & Insights
Analyst, Perception Analytics & Insights

Bristol Myers Squibb • Hyderabad

On-site
INR 800,000 - 1,400,000
Data Engineer I - Transparency Data Operations
Data Engineer I - Transparency Data Operations

Bristol-Myers Squibb Co • Hyderabad

On-site
INR 1,200,000 - 2,200,000
Lead Business Analyst - Project Financial Management
Lead Business Analyst - Project Financial Management

Bristol Myers Squibb • Hyderabad

On-site
INR 4,200,000 - 6,400,000
Manager, Pharmaceutical Product Development GenAI & Data Science Hyderabad - TS - IN R1605511 Posted 15 hours ago
Manager, Pharmaceutical Product Development GenAI & Data Science Hyderabad - TS - IN R1605511 Posted 15 hours ago

Bristol-Myers Squibb • Hyderabad

On-site
INR 4,000,000 - 6,000,000
Software Development Engineer III, AI Data Engineering
Software Development Engineer III, AI Data Engineering

Bristol Myers Squibb EU Policy • Hyderabad

On-site
INR 4,000,000 - 7,000,000