Manager, Cybersecurity - Manufacturing

Bristol-Myers Squibb

United States

Hybrid

USD 140,000 - 190,000

Full time

6 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Bristol-Myers Squibb is seeking a Cyber Resiliency Manager to safeguard IT/OT systems across the manufacturing site and ensure uninterrupted production.

You will lead cyber resiliency strategy, incident response, and regulatory readiness, partnering with IT, Engineering, QA, and external vendors. The role emphasizes risk-based decision making, governance, and training to embed resilience into daily operations.

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Engineering, or related field.
  • At least five years in cybersecurity/OT security with three in manufacturing/critical infra.
  • Experience in GxP regulated environments (FDA/EMA).
  • Familiarity with NIST CSF, IEC 62443; Purdue/ISA-95 OT knowledge.
  • Strong stakeholder management and executive reporting.

Responsibilities

  • Lead site cyber resiliency program aligned with policies and standards.
  • Define site RTOs/RPOs for critical digital systems.
  • Report cyber resiliency KPIs to site leadership.
  • Coordinate incident response with IT/OT and CFC teams.
  • Test DR/backup for MES, LIMS, ERP and automation.
  • Support regulatory readiness and documentation for audits.
  • Deliver resiliency training for operators and leadership.

Skills

Cybersecurity
OT security
Regulatory compliance
Risk reporting
Stakeholder management
Incident response
GxP familiarity

Education

Bachelor's degree in Cybersecurity

Tools

MES
LIMS
ERP (SAP)
CSV tools

Job description

At Bristol Myers Squibb, our employees often ask, "Who are you working for?"-a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.

The Cyber Resiliency Manager for the manufacturing site is responsible for protecting and strengthening the resilience of site-specific IT and OT systems that support pharmaceutical production. This role ensures that the site can anticipate, withstand, respond to, and recover quickly from cyber incidents without compromising product quality, patient safety, or regulatory compliance. The manager acts as the site focal point for cyber risk management, incident response, and recovery planning, working closely with both site IT leadership and cybersecurity functions. This role is critical to ensuring uninterrupted pharmaceutical production and protecting patient safety in an increasingly complex threat environment.

Major Responsibilities and Accountabilities
Cyber Risk Resiliency Strategy & Governance
  • Develop and execute a site-level cyber resiliency program, aligned with BMS policies and standards.
  • Identify and assess cyber risks across IT, OT, automation, and manufacturing execution systems (MES, SCADA, PLCs, Laboratory Instruments).
  • Define and validate site-specific recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical digital systems.
  • Maintain and report site cyber resiliency KPIs and KRIs to site leadership and the enterprise cybersecurity function on a regular cadence.
  • Align with the Site General Manager, Quality, and EHS functions on resiliency priorities and risk tolerance.
Incident Response & Recovery
  • Lead or co-lead the site cyber incident response process, coordinating with the CFC, IT, and OT teams.
  • Oversee and test disaster recovery (DR) and backup strategies for site systems (e.g., MES, LIMS, ERP, automation).
  • Support cyber crisis simulations, ransomware drills, and tabletop exercises with site leadership and operators.
  • Ensure lessons learned from incidents are embedded into site resiliency practices.
Operational Technology (OT) & Manufacturing Systems Resilience
  • Partner with Engineering and Automation to secure IRS/OT environments, including patching, network segmentation, and secure remote access.
  • Ensure redundancy and contingency measures for critical control systems and data flows.
  • Collaborate with vendors and system integrators to strengthen the resilience of third-party technology supporting production.
Compliance & Regulatory Readiness
  • Ensure cybersecurity controls comply with GxP requirements and 21 CFR Part 11 as applicable to digital manufacturing systems.
  • Support FDA, EMA, and other regulatory audit readiness, providing evidence of cyber resiliency controls and incident response capability.
  • Collaborate with Quality and Validation teams on computer system validation (CSV/CSA) activities that intersect with cybersecurity.
  • Maintain documentation and records to support regulatory inspections and internal audits.
Awareness & Training
  • Deliver cyber resiliency awareness training for site employees, with tailored sessions for operators, engineers, and leadership.
  • Act as the resilience advocate at the site, embedding cyber recovery readiness into daily operations.
Qualifications
Minimum Requirements
  • Minimum education of a bachelor's degree in Cybersecurity, Computer Science, Engineering, or a related field is required.
  • Minimum of five (5) years of experience in cybersecurity, OT security, or cyber resiliency, with at least three (3) years in a manufacturing or critical infrastructure setting is required.
  • Strong understanding of OT/ICS environments, pharmaceutical manufacturing systems, and automation technologies.
  • Demonstrated experience operating within a GxP-regulated environment (required).
  • Familiarity with regulatory frameworks and expectations for cybersecurity in pharma (FDA, EMA).
  • Familiarity with NIST CSF, IEC 62443 frameworks.
  • Understanding of the Purdue Model or ISA/IEC OT network architecture.
  • Hands-on experience with pharma manufacturing systems such as MES, LIMS, and ERP platforms (e.g., SAP).
  • Strong stakeholder management and communication skills; ability to influence site leadership and cross-functional teams without direct authority.
  • Experience developing and presenting risk reports, KPIs, and executive summaries.
Preferred Qualifications
  • GICSP (Global Industrial Cyber Security Professional) - highly relevant to OT/ICS context
  • CISSP, CISM, or CRISC
  • ISA/IEC 62443 certifications orICS-CERT training

#LI-Hybrid

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Cybersecurity - Manufacturing
Manager, Cybersecurity - Manufacturing

BRISTOL MYERS SQUIBB CO • Bothell (WA)

On-site
USD 125,000 - 152,000
Flexible Time Off (FTO)
11 paid holidays
Comprehensive benefits package
Cyber Resiliency Manager – Manufacturing IT/OT
Cyber Resiliency Manager – Manufacturing IT/OT

Bristol-Myers Squibb • United States

Hybrid
USD 140,000 - 190,000
Cyber Resiliency Manager, Manufacturing Site
Cyber Resiliency Manager, Manufacturing Site

BRISTOL MYERS SQUIBB CO • Bothell (WA)

On-site
USD 125,000 - 152,000
Flexible Time Off (FTO)
11 paid holidays
Comprehensive benefits package
OT Cybersecurity Architect (ICS / Mfg Security)
OT Cybersecurity Architect (ICS / Mfg Security)

Bull City Talent Group • Georgia

Hybrid
USD 150,000 - 230,000
Sr OT Cybersecurity Engineer (ICS / Mfg)
Sr OT Cybersecurity Engineer (ICS / Mfg)

Bull City Talent Group • South Carolina

On-site
USD 120,000 - 160,000
Sr OT Cybersecurity Engineer (ICS / Mfg)
Sr OT Cybersecurity Engineer (ICS / Mfg)

Bull City Talent Group • King of Prussia (PA)

On-site
USD 120,000 - 180,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Vivos Holdings • Smyrna (TN)

On-site
USD 120,000 - 190,000
Sr. Manager InfoSec Operations-Plants
Sr. Manager InfoSec Operations-Plants

Philip Morris International U.S. • Tampa (FL)

On-site
USD 160,000 - 200,000
OT Cybersecurity Architect
OT Cybersecurity Architect

Plexus • Neenah (WI)

Hybrid
USD 129,000 - 195,000
Chief Information Security Officer CISO
Chief Information Security Officer CISO

Mission Critical Group • Tempe (AZ)

On-site
USD 180,000 - 260,000