Bristol-Myers Squibb Business Services India Private Limited Posted August 5, 2026

Risk Analyst II

Hyderabad, India Full time
Information Technology

Bristol-Myers Squibb Business Services India Private Limited is the source of truth for this posting and owns the application process. We surface normalized context and market comparison you won't find on the original listing.

About this opportunity

Working with Us

Challenging. Meaningful. Life-changing. Those aren’t words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You’ll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams. Take your career farther than you thought possible.

Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives. Read more: careers.bms.com/working-with-us .

 Job Description 1: IT Risk Analyst, Risk Operations (3–5 Years Experience)

Position Summary

The IT Risk Analyst, IT Risk Operations is a judgment-driven role responsible for reviewing, interpreting, and acting on risk signals produced by BMS's automated risk assessment infrastructure. As BMS transitions to a more automated operating model, where structured tiering, continuous monitoring, and integrated assessment frameworks handle intake and classification, the analyst's focus shifts decisively toward review, challenge, exception handling, and stakeholder engagement.

This is not primarily a processing or intake role. It is an analytical and advisory role where sound risk judgment, clear communication, and accountability for final risk determinations are the core expectations.

Key Responsibilities

Risk Review & Judgment

Review and validate risk determinations produced through BMS's integrated risk assessment framework, including Cyber Tier assignments (Tiers 0–5), regulatory classifications (GDPR, EU AI Act, GxP, etc.), and control recommendations across 9 risk domains

Apply independent analytical judgment to accept, challenge, or override system-generated risk outputs; document rationale clearly in ServiceNow (SNOW) for all override decisions

Identify missing context, ambiguous scope, or inconsistencies between risk outputs and known project characteristics; engage project teams to resolve gaps before closing records

Interpret and communicate risk signals and outputs in clear, stakeholder-facing language, translating technical determinations into actionable guidance without relying on raw tier scores or regulatory jargon

Exception Handling & Escalation

Own exception handling for edge cases, novel technology types, cross-jurisdictional complexity, and cases where risk assessments indicate insufficient or ambiguous input

Escalate material discrepancies to Risk Leads, BISOs, or Privacy SMEs with documented rationale; serve as the first line of analytical accountability for the risk record

Support periodic review of auto-approved projects, identifying patterns or anomalies that warrant re-evaluation

Stakeholder Engagement

Lead or participate in structured touchpoints with project teams, informing them of assessment status, applicable controls, and required documentation

Serve as a point of contact for project team questions about risk outputs; translate technical risk determinations into clear, actionable guidance

Collaborate with Legal/Privacy SMEs (DPIA, TIA, SCC workflows) at defined handoff points to ensure risk findings are correctly consumed downstream

Audit Readiness & Documentation

Maintain auditor-ready records in SNOW and GRC platforms; ensure every determination, accepted, challenged, or overridden, is traceable with documented rationale

Prepare concise, high-quality assessment summaries and control attestations for management and compliance audiences

Support internal and external audit activities by clearly articulating the basis for risk determinations and the human review actions that followed

Continuous Improvement

Identify patterns in override rates, exception types, and assessment flags that may indicate framework gaps or emerging risk themes

Apply a continuous improvement mindset to enhance assessment quality, SLA performance, and the overall stakeholder experience

Qualifications & Experience

Required

3–5 years of experience in IT risk management, cybersecurity risk, IT audit, privacy compliance, or a directly related field

Demonstrated ability to interpret and act on risk outputs or signals, not just execute process steps, with a clear track record of sound analytical judgment

Working knowledge of NIST Cyber Risk Management Framework and NIST 800-53 controls library

Familiarity with major data privacy regulations (GDPR, CCPA, EU AI Act, GxP)

Experience with GRC platforms (ServiceNow GRC or equivalent)

Strong written and verbal communication skills; ability to explain risk determinations clearly to both technical and non-technical audiences

Experience with pre/post-implementation risk assessments, cybersecurity, data privacy, and/or digital transformation initiatives

Preferred

Exposure to AI/ML risk assessment frameworks or emerging technology risk

Experience working in automated or tool-assisted workflow environments

Relevant certifications: CISA, CRISC, CISSP, CISM, or equivalent

Desired Candidate Characteristics

Strong analytical and risk judgment instincts, comfortable forming a defensible view from incomplete information

Inquisitive and bold; willing to challenge outputs, ask difficult questions, and escalate when warranted

Collaborative across IT, Legal, Privacy, and Business functions

Comfortable working with system-generated risk signals and outputs rather than manually gathering inputs

Adaptable to a continuously evolving, automation-enabled operating model with a growth mindset

Commitment to healthcare and patient impact as the guiding north star for all risk decisions

If you come across a role that intrigues you but doesn’t perfectly line up with your resume, we encourage you to apply anyway. You could be one step away from work that will transform your life and career.

Uniquely Interesting Work, Life-changing Careers

With a single vision as inspiring as “Transforming patients’ lives through science™ ”, every BMS employee plays an integral role in work that goes far beyond ordinary. Each of us is empowered to apply our individual talents and unique perspectives in a supportive culture, promoting global participation in clinical trials, while our shared values of passion, innovation, urgency, accountability, inclusion and integrity bring out the highest potential of each of our colleagues.

On-site Protocol

BMS has an occupancy structure that determines where an employee is required to conduct their work. This structure includes site-essential, site-by-design, field-based and remote-by-design jobs. The occupancy type that you are assigned is determined by the nature and responsibilities of your role:

Site-essential roles require 100% of shifts onsite at your assigned facility. Site-by-design roles may be eligible for a hybrid work model with at least 50% onsite at your assigned facility. For these roles, onsite presence is considered an essential job function and is critical to collaboration, innovation, productivity, and a positive Company culture. For field-based and remote-by-design roles the ability to physically travel to visit customers, patients or business partners and to attend meetings on behalf of BMS as directed is an essential job function.

Supporting People with Disabilities

BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to adastaffingsupport@bms.com . Visit careers.bms.com/ eeo -accessibility to access our complete Equal Employment Opportunity statement.

Candidate Rights

BMS will consider for employment qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.

If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information:  https://careers.bms.com/california-residents/

Data Protection

We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https://careers.bms.com/fraud-protection .

Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.

If you believe that the job posting is missing information required by local law or incorrect in any way, please contact BMS at TAEnablement@bms.com . Please provide the Job Title and Requisition number so we can review. Communications related to your application should not be sent to this email and you will not receive a response. Inquiries related to the status of your application should be directed to Chat with Ripley.

R1604969 : Risk Analyst II

Job details

Seniority
Not listed
Function
Information Technology
Therapeutic area
Not listed
Location
Hyderabad, India
Employment type
Full time

How this role compares

Computed from every other active Information Technology role in our database, not just this employer's listings.

We currently track 1097 comparable Information Technology roles across 55 biopharma companies.

1097Comparable roles tracked
1035Currently active
55Companies hiring similar roles
29Countries represented

Salary context

143 of 1097 peers report a salary range (USD, annualized)

Peers share this role's job function. This posting doesn't list a seniority level, so peers aren't narrowed by seniority either -- the range below may span more levels than usual.

This roleSubject Not listed on this posting
Lowest disclosed · Senior Data Security Engineer (Insider Risk Management – Engineering) · AbbVie $0/hr – $0/hr (≈ $0–$0/yr)
Highest disclosed · Senior Director, Targets and Mechanisms Solutions · Pfizer $230,900/yr – $384,800/yr
Peer group range $0 – $307,850 (median $165,900)

Where these roles are based

Top locations among the 1097 comparable roles

India506
United States241
Spain106
Poland72
Portugal32
China13

+ 23 more countries

Seniority mix

612 of 1097 peers have a known seniority level

Senior290
Manager135
Associate52
Principal50
Associate Director39
Director28
Senior Director13
Intern/Fellow/Postdoc4
Executive/VP1

Therapeutic area mix

1 of 1097 peers have a known therapeutic area; the rest are genuinely unlabeled, not hidden

Oncology1

Similar opportunities

The closest matches from our peer group, ranked by how similar they are, not how well you'd qualify for them -- treat this as market context, not a guaranteed shortlist; a weak match is labeled as one below.

40%similar
Novartis Hyderabad (Office), India Associate Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Associate Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Director
Same function Same country
40%similar
Novartis Hyderabad (Office), India Director
Same function Same country
40%similar
Regeneron India Private Limited Hyderabad, India Senior Director
Same function Same country
40%similar
Regeneron India Private Limited Hyderabad, India Director
Same function Same country

How we calculate "similar"

No black box, no LLM guesswork: a deterministic score built from four normalized attributes. Here's this role's own peer group at different match levels, so you can see the mechanism, not just the result.

Every comparison starts from the same 100-point budget: 25 for working in the same function, 40 for the same therapeutic area, 20 for the same or adjacent seniority, 15 for the same country. A dimension we can't confirm on both sides contributes nothing, never a guess, never a free pass.

40%
Associate Director, Technical Project Management & Digital Enablement(Sharepoint)
Novartis · Hyderabad (Office), India · Associate Director
Function Therapeutic area Seniority Country
40%
Director - Data & Analytics Integration & Eventing Platforms
Novartis · Hyderabad (Office), India · Director
Function Therapeutic area Seniority Country
40%
Director Information Security - GCC India & JAPAC
Regeneron India Private Limited · Hyderabad, India · Director
Function Therapeutic area Seniority Country
40%
Software Engineer II Workday Integrations
Bristol-Myers Squibb Business Services India Private Limited · Hyderabad, India · Seniority not listed
Function Therapeutic area Seniority Country
Unmatched or unknown dimensions score exactly the same: 0 points, never a partial guess. A role we know almost nothing about beyond its function bottoms out at 25%; it never inflates to 100% just because there's little to compare against. Seniority uses a defined ladder (Associate → Manager → Associate Director → Senior → Principal → Director → Senior Director → Executive/VP) so "Director" and "Senior Director" count as adjacent, but "Director" and "Executive/VP" do not.