Senior Manager, Emerging Technology Risk
Bristol Myers Squibb
August 13, 2026
Remote friendly (Princeton, NJ)
United States
IT
Position Summary
Senior Manager, Emerging Technology Risk (Security & IT Risk). Own governance, risk, and compliance (GRC) strategy for emerging/disruptive technologies with primary emphasis on AI, Generative AI, and LLMs. Lead BMS Secure AI GRC program; ensure AI deployments are safe, compliant, and operationally resilient.
Key Responsibilities
- Design, implement, and continuously improve AI governance framework and archetype-based control models (risk classification, control objectives, evidence standards).
- Review emerging AI technologies/tools for enterprise adoption against risk appetite, security standards, and regulatory obligations.
- Lead AI risk/conformity assessments aligned to EU AI Act, NIST AI RMF, ISO/IEC 42001, and privacy regulations (GDPR/EDPB/state AI laws); classify high-risk use cases across Clinical, Commercial, and R&D.
- Assess GenAI/LLM deployments (e.g., Claude via AWS Bedrock, ChatGPT, third parties) for privacy, contractual terms, data residency; manage legal/licensing constraints.
- Define/implement controls with business/technology/Legal/Privacy; ensure controls are practical and embedded in workflows.
- Execute control testing (pre-deployment validation, post-deployment effectiveness, periodic reassessment); document gaps/remediation and track to closure.
- Partner with Cloud/security to embed GRC controls at AI gateway/control plane levels (traceability, privacy-by-design, audit trails).
- Serve as Secure AI GRC SME; provide executive-ready governance reporting and guidance.
- Provide compliant AI tool usage guidance; monitor risks from agentic AI, multimodal GenAI, synthetic data pipelines, quantum-accelerated inference.
Qualifications
- Education: Bachelorβs degree in Information Security, Computer Science, Risk Management, Data Science, or related.
- Required: 8+ years GRC/infosec/tech risk with 2β3 years focused on AI/emerging tech/data governance; proven AI/advanced-tech GRC framework operationalization; hands-on NIST AI RMF, EU AI Act, and/or ISO/IEC 42001 (or 23894); experience assessing LLM/GenAI risks (prompt injection, hallucination, IP leakage, training data privacy); cloud AI architecture and data residency/privacy knowledge; ability to influence/communicate with senior executives and external advisors.
- Preferred: Life Sciences/pharma or other highly regulated industry; AI gateway/API security/control plane governance; agentic AI, model cards, data lineage, model lifecycle governance.
Key Skills
AI/ML risk & model governance; AI Act/NIST/ISO; GenAI/LLM risk; cloud/AWS-Azure AI gateway controls; data lineage/traceability/audit readiness; GRC tooling (ServiceNow, OneTrust); executive risk communication; cross-functional influence; program management; vendor/consultant management; training/change management.
Certifications (Highly Valued)
GARP RAI; CISSP or CISA.
Benefits (explicitly listed)
Health coverage; wellbeing programs (including EAP); 401(k), disability, life/accident insurance, legal support, survivor support; paid time off (varies by location).
Application Instructions
Apply online for requisition R1604097 (Senior Manager, Emerging Technology Risk).
Senior Manager, Emerging Technology Risk (Security & IT Risk). Own governance, risk, and compliance (GRC) strategy for emerging/disruptive technologies with primary emphasis on AI, Generative AI, and LLMs. Lead BMS Secure AI GRC program; ensure AI deployments are safe, compliant, and operationally resilient.
Key Responsibilities
- Design, implement, and continuously improve AI governance framework and archetype-based control models (risk classification, control objectives, evidence standards).
- Review emerging AI technologies/tools for enterprise adoption against risk appetite, security standards, and regulatory obligations.
- Lead AI risk/conformity assessments aligned to EU AI Act, NIST AI RMF, ISO/IEC 42001, and privacy regulations (GDPR/EDPB/state AI laws); classify high-risk use cases across Clinical, Commercial, and R&D.
- Assess GenAI/LLM deployments (e.g., Claude via AWS Bedrock, ChatGPT, third parties) for privacy, contractual terms, data residency; manage legal/licensing constraints.
- Define/implement controls with business/technology/Legal/Privacy; ensure controls are practical and embedded in workflows.
- Execute control testing (pre-deployment validation, post-deployment effectiveness, periodic reassessment); document gaps/remediation and track to closure.
- Partner with Cloud/security to embed GRC controls at AI gateway/control plane levels (traceability, privacy-by-design, audit trails).
- Serve as Secure AI GRC SME; provide executive-ready governance reporting and guidance.
- Provide compliant AI tool usage guidance; monitor risks from agentic AI, multimodal GenAI, synthetic data pipelines, quantum-accelerated inference.
Qualifications
- Education: Bachelorβs degree in Information Security, Computer Science, Risk Management, Data Science, or related.
- Required: 8+ years GRC/infosec/tech risk with 2β3 years focused on AI/emerging tech/data governance; proven AI/advanced-tech GRC framework operationalization; hands-on NIST AI RMF, EU AI Act, and/or ISO/IEC 42001 (or 23894); experience assessing LLM/GenAI risks (prompt injection, hallucination, IP leakage, training data privacy); cloud AI architecture and data residency/privacy knowledge; ability to influence/communicate with senior executives and external advisors.
- Preferred: Life Sciences/pharma or other highly regulated industry; AI gateway/API security/control plane governance; agentic AI, model cards, data lineage, model lifecycle governance.
Key Skills
AI/ML risk & model governance; AI Act/NIST/ISO; GenAI/LLM risk; cloud/AWS-Azure AI gateway controls; data lineage/traceability/audit readiness; GRC tooling (ServiceNow, OneTrust); executive risk communication; cross-functional influence; program management; vendor/consultant management; training/change management.
Certifications (Highly Valued)
GARP RAI; CISSP or CISA.
Benefits (explicitly listed)
Health coverage; wellbeing programs (including EAP); 401(k), disability, life/accident insurance, legal support, survivor support; paid time off (varies by location).
Application Instructions
Apply online for requisition R1604097 (Senior Manager, Emerging Technology Risk).