Risk Analyst II
BRISTOL MYERS SQUIBB CO · Indiana
📍 Hyderabad - TS - INvia workdayFirst listed here 2026-09-20
Apply on company site ↗
Career Moonshot pulls this listing straight from the employer's hiring system — no recruiter middleman, no reposts. Applying takes you directly to BRISTOL MYERS SQUIBB CO.
Working with Us
Challenging. Meaningful. Life-changing. Those aren’t words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You’ll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams. Take your career farther than you thought possible.
Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives. Read more: careers.bms.com/working-with-us .
Job Description 1: IT Risk Analyst — Risk Operations (3–5 Years Experience)
Position Summary
The IT Risk Analyst, IT Risk Operations is a judgment-driven role responsible for reviewing, interpreting, and acting on risk signals produced by BMS's automated risk assessment infrastructure. As BMS transitions to a more automated operating model — where structured tiering, continuous monitoring, and integrated assessment frameworks handle intake and classification — the analyst's focus shifts decisively toward review, challenge, exception handling, and stakeholder engagement.
This is not primarily a processing or intake role. It is an analytical and advisory role where sound risk judgment, clear communication, and accountability for final risk determinations are the core expectations.
Key Responsibilities
Risk Review & Judgment
Review and validate risk determinations produced through BMS's integrated risk assessment framework, including Cyber Tier assignments (Tiers 0–5), regulatory classifications (GDPR, EU AI Act, GxP, etc.), and control recommendations across 9 risk domains
Apply independent analytical judgment to accept, challenge, or override system-generated risk outputs; document rationale clearly in ServiceNow (SNOW) for all override decisions
Identify missing context, ambiguous scope, or inconsistencies between risk outputs and known project characteristics; engage project teams to resolve gaps before closing records
Interpret and communicate risk signals and outputs in clear, stakeholder-facing language — translating technical determinations into actionable guidance without relying on raw tier scores or regulatory jargon
Exception Handling & Escalation
Own exception handling for edge cases, novel technology types, cross-jurisdictional complexity, and cases where risk assessments indicate insufficient or ambiguous input
Escalate material discrepancies to Risk Leads, BISOs, or Privacy SMEs with documented rationale; serve as the first line of analytical accountability for the risk record
Support periodic review of auto-approved projects, identifying patterns or anomalies that warrant re-evaluation
Stakeholder Engagement
Lead or participate in structured touchpoints with project teams, informing them of assessment status, applicable controls, and required documentation
Serve as a point of contact for project team questions about risk outputs; translate technical risk determinations into clear, actionable guidance
Collaborate with Legal/Privacy SMEs (DPIA, TIA, SCC workflows) at defined handoff points to ensure risk findings are correctly consumed downstream
Audit Readiness & Documentation
Maintain auditor-ready records in SNOW and GRC platforms; ensure every determination — accepted, challenged, or overridden — is traceable with documented rationale
Prepare concise, high-quality assessment summaries and control attestations for management and compliance audiences
Support internal and external audit activities by clearly articulating the basis for risk determinations and the human review actions that followed
Continuous Improvement
Identify patterns in override rates, exception types, and assessment flags that may indicate framework gaps or emerging risk themes
Apply a continuous improvement mindset to enhance assessment quality, SLA performance, and the overall stakeholder experience
Qualifications & Experience
Required
3–5 years of experience in IT risk management, cybersecurity risk, IT audit, privacy compliance, or a directly related field
Demonstrated ability to interpret and act on risk outputs or signals — not just execute process steps — with a clear track record of sound analytical judgment
Working knowledge of NIST Cyber Risk Management Framework and NIST 800-53 controls library
Familiarity with major data privacy regulations (GDPR, CCPA, EU AI Act, GxP)
Experience with GRC platforms (ServiceNow GRC or equivalent)
Strong written and verbal communication skills; ability to explain risk determinations clearly to both technical and non-technical audiences
Experience with pre/post-implementation risk assessments, cybersecurity, data privacy, and/or digital transformation initiatives
Preferred
Exposure to AI/ML risk assessment frameworks or emerging technology risk
Experience working in automated or tool-assisted workflow environments
Relevant certifications: CISA, CRISC, CISSP, CISM, or equivalent
Desired Candidate Characteristics
Strong analytical and risk judgment instincts — comfortable forming a defensible view from incomplete information
Inquisitive and bold; willing to challenge outputs, ask difficult questions, and escalate when warranted
Collaborative across IT, Legal, Privacy, and Business functions
Comfortable working with system-generated risk signals and outputs rather than manually gathering inputs
Adaptable to a continuously evolving, automation-enabled operating model with a growth mindset
Commitment to healthcare and patient impact as the guiding north star for all risk decisions
If you come across a role
More Indiana jobs
Indiana jobs · Browse all locations