Skip to main content
Bristol Myers Squibb logo

Senior Manager, Emerging Technology Risk

Bristol Myers Squibb
August 13, 2026
Remote friendly (Princeton, NJ)
United States
IT
Position Summary
Senior Manager, Emerging Technology Risk (Security & IT Risk). Own governance, risk, and compliance (GRC) strategy for emerging/disruptive technologies with primary emphasis on AI, Generative AI, and LLMs. Lead BMS Secure AI GRC program; ensure AI deployments are safe, compliant, and operationally resilient.

Key Responsibilities
- Design, implement, and continuously improve AI governance framework and archetype-based control models (risk classification, control objectives, evidence standards).
- Review emerging AI technologies/tools for enterprise adoption against risk appetite, security standards, and regulatory obligations.
- Lead AI risk/conformity assessments aligned to EU AI Act, NIST AI RMF, ISO/IEC 42001, and privacy regulations (GDPR/EDPB/state AI laws); classify high-risk use cases across Clinical, Commercial, and R&D.
- Assess GenAI/LLM deployments (e.g., Claude via AWS Bedrock, ChatGPT, third parties) for privacy, contractual terms, data residency; manage legal/licensing constraints.
- Define/implement controls with business/technology/Legal/Privacy; ensure controls are practical and embedded in workflows.
- Execute control testing (pre-deployment validation, post-deployment effectiveness, periodic reassessment); document gaps/remediation and track to closure.
- Partner with Cloud/security to embed GRC controls at AI gateway/control plane levels (traceability, privacy-by-design, audit trails).
- Serve as Secure AI GRC SME; provide executive-ready governance reporting and guidance.
- Provide compliant AI tool usage guidance; monitor risks from agentic AI, multimodal GenAI, synthetic data pipelines, quantum-accelerated inference.

Qualifications
- Education: Bachelor’s degree in Information Security, Computer Science, Risk Management, Data Science, or related.
- Required: 8+ years GRC/infosec/tech risk with 2–3 years focused on AI/emerging tech/data governance; proven AI/advanced-tech GRC framework operationalization; hands-on NIST AI RMF, EU AI Act, and/or ISO/IEC 42001 (or 23894); experience assessing LLM/GenAI risks (prompt injection, hallucination, IP leakage, training data privacy); cloud AI architecture and data residency/privacy knowledge; ability to influence/communicate with senior executives and external advisors.
- Preferred: Life Sciences/pharma or other highly regulated industry; AI gateway/API security/control plane governance; agentic AI, model cards, data lineage, model lifecycle governance.

Key Skills
AI/ML risk & model governance; AI Act/NIST/ISO; GenAI/LLM risk; cloud/AWS-Azure AI gateway controls; data lineage/traceability/audit readiness; GRC tooling (ServiceNow, OneTrust); executive risk communication; cross-functional influence; program management; vendor/consultant management; training/change management.

Certifications (Highly Valued)
GARP RAI; CISSP or CISA.

Benefits (explicitly listed)
Health coverage; wellbeing programs (including EAP); 401(k), disability, life/accident insurance, legal support, survivor support; paid time off (varies by location).

Application Instructions
Apply online for requisition R1604097 (Senior Manager, Emerging Technology Risk).