BristolMyers Squibb

Director Data Risk & Protection

BristolMyers Squibb$188K — $228K *
Pharmaceuticals & Biotech
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Computer Science, Cybersecurity, Risk Management, or a related field required; advanced degree preferred.
  • 10+ years of experience in cybersecurity and data risk management within large organizations, preferably in the pharmaceutical or highly regulated sectors.
  • Strong background in data loss prevention, insider threat management, and security investigations, with hands-on program ownership experience.
  • Technical fluency in DLP, UEBA, SIEM, cloud security tools, and identity access management systems.
  • Familiarity with legal regulations around data protection, including GDPR, CCPA, and HIPAA.

Responsibilities

  • Define and lead BMS's enterprise Data Risk and Protection strategy, ensuring alignment with regulatory requirements.
  • Design and implement the Data Risk and Protection operating model and team structure for effective cross-departmental engagement.
  • Establish and evolve a comprehensive Data Risk & Protection program to include governance, monitoring, and remediation processes.
  • Develop a multi-year capability roadmap with measurable KPIs and a focus on risk reduction.
  • Scale and mature the Data Risk & Protection function, fostering a high-performing team.
  • Provide status updates on the program and risk posture to senior leadership and governance bodies.

Benefits

  • Comprehensive health coverage including medical, pharmacy, dental, and vision care.
  • Wellbeing support programs such as Employee Assistance Programs and wellness initiatives.
  • Financial security with a 401(k) plan and various insurance options like life and disability insurance.
  • Work-life benefits including unlimited paid time off (with approval), paid national holidays, and generous sick leave policies.
Full Job Description

Key Responsibilities:

  • Define and lead BMS's enterpriseData Risk and Protection strategy, aligned to the company's risk appetite, regulatory requirements, and broader cybersecurity strategy.
  • Design and implement theData Risk and Protection operating model & engagement, including team structure, roles and responsibilities, process workflows, tooling stack, and an integrated engagement model with Cybersecurity Fusion Center, Legal, HR, Compliance, Audit, and key Business Units.
  • Establish, maintain, and continuously evolve a comprehensiveData Risk & Protection program, encompassing policy governance, use-case development, monitoring, detection, response, and remediation.
  • Develop and execute amulti-year capability roadmapwith clear priorities, milestones, measurable KPIs, and outcome-based risk reduction metrics.
  • Lead the scaling and maturation of the Data Risk & Protection function, building specialist capabilities and fostering a high-performing team.
  • Provide regular program status reporting and risk posture updates to senior leadership, governance bodies.

Inside Risk & Threat Analysis:

  • Establish and operationalizeinsider threat monitoring and behavioral analytics capabilitiesto improve visibility and enable timely response.
  • Define and maintaininsider threat personas, use cases, and detection scenarios(e.g., intellectual property theft, clinical trial data exfiltration, fraud, sabotage, negligent data leakage, Generative AI misuse), informed by threat intelligence, business context, and prior incident trends.
  • Collaborate with technical teams to design, operate, and continuously refinemonitoring and analytics capabilities, including UEBA, DLP, CASB, endpoint and identity telemetry, cloud security monitoring, and privileged access monitoring, with a focus on improving detection coverage and reducing false positives.
  • Oversee theend-to-end insider risk case lifecycle, from alert generation through triage, investigation, response, closure, and lessons learned, coordinating across Cybersecurity Fusion Center, HR, Legal, Compliance, Corporate Security, and Business Units.
  • Ensuretimely and proportionate incident responses, applying a risk-based methodology that distinguishes between malicious, negligent, and compromised actors, and driving root-cause analysis to strengthen controls and processes.
  • Assess andmitigate data risks associated with Generative AI and emerging technologies, including data leakage via AI tools, model misuse, shadow AI adoption, and unapproved application usage.

Data Loss Prevention (DLP) & Information Protection

  • Lead the strategy, design, and operational management of BMS'senterprise DLP program across endpoints, email, cloud, and collaboration platforms (e.g., Microsoft 365, Teams, SharePoint, Copilot, AWS, Google Cloud etc).
  • Define and governdata classification policies and standards, ensuring sensitive BMS data including clinical trial data, intellectual property, PII, and regulated data is appropriately labelled, handled, and protected.
  • Drive continuoustuning, optimization, and lifecycle managementof DLP rules, policies, and controls to improve accuracy, reduce operational burden, and align with evolving business needs.
  • Partner with IT Security Architecture and Engineering teams to ensuredata protection controls are embeddedinto infrastructure, application development, and cloud adoption workflows.
  • Establishmetrics and dashboardsto track DLP program effectiveness, data exposure trends, policy violations, and remediation outcomes, and report regularly to senior leadership.

Policy, Governance, Assurance & Culture

  • Develop, review, and maintaindata risk and protection policies, standards, and guidelines(e.g., acceptable use, data handling, monitoring, GenAI usage) in close collaboration with Legal, HR, Compliance, and Privacy teams.
  • Establish clearescalation paths, decision rights, and documentation standardsfor data-related incidents and insider risk cases, ensuring all activities comply with applicable laws, regulations, and internal policies particularly around privacy, data protection, and employment practices.
  • Lead or supportinternal assurance and audit activitieson data risk and protection as directed by the Audit Committee and senior management, including targeted reviews, thematic risk assessments, and deep-dive investigations into control effectiveness.
  • Build strong relationships with stakeholders across BMS, and design targeted awareness, education, and training on data protection, insider risk, and responsible use of Generative AI tools, tailored to different roles and risk profiles.
  • Foster a culture oftrust, accountability, and security-conscious behavior, balancing deterrence with transparency, and represent BMS in relevant external forums, regulatory engagements, and peer networks to leverage industry best practices.

Qualifications:

Education

  • Bachelor's degree requiredin Computer Science, Information Systems, Cybersecurity, Risk Management, Law, Business Administration, or a related discipline.
  • Advanced degree (Master's or equivalent) preferred.

Certifications

Relevant professional certifications are strongly preferred, including but not limited to:

  • CISSP (Certified Information Systems Security Professional)
  • CISM (Certified Information Security Manager)
  • CISA (Certified Information Systems Auditor)
  • CRISC (Certified in Risk and Information Systems Control)
  • CDPSE (Certified Data Privacy Solutions Engineer)
  • CFE (Certified Fraud Examiner) or equivalent risk/investigation credentials

Experience & Skills

  • 10+ years of progressive experiencein cybersecurity, data risk management, insider risk, information protection, security operations, or related disciplines, with demonstrated experience designing and leading complex, enterprise-scale security or risk programs in large, matrixed organizations preferably in thepharmaceutical, life sciences, or highly regulated industrysector.
  • Demonstrable experiencein data loss prevention (DLP), insider threat management, user and entity behavior analytics, or security investigations, including hands-on program ownership in a large enterprise environment.
  • Strong technical fluencyin tools and platforms commonly used in data risk and protection programs, including:
    • SIEM, UEBA, DLP, EDR/XDR, CASB(e.g., Microsoft Purview, Symantec DLP, Varonis, Securonix, CrowdStrike, Zscaler, Cisco etc)
    • Identity & Access Management (IAM)andPrivileged Access Management (PAM)
    • Cloud security platforms(Microsoft 365 Security, Azure, AWS) and collaboration security tools
  • Familiarity with legal, privacy, employment, and ethical considerationsrelating to employee monitoring, data protection, cross-border data transfers, and applicable regulations (e.g., GDPR, CCPA, HIPAA); prior experience working closely with Legal, HR, and Compliance is required.
  • Proven ability tobuild, lead, and scale a multidisciplinary, high-performing organization, including recruiting and developing top talent, defining team operating models, establishing governance frameworks, and driving measurable outcomes through clear performance metrics.
  • Experience leading or overseeing complex investigations, including cross-functional coordination with HR, Legal, Compliance, Corporate Security, and, where relevant, external counsel or law enforcement.
  • Strong data-driven analytical and problem-solving skills, with demonstrated experience using metrics, dashboards, and risk data to drive decisions, measure program impact, and identify improvements.
  • Excellent communication, influencing, and stakeholder management skills, with experience presenting to senior management, governance bodies, and, ideally, Audit Committees or Boards of Directors.
  • Ability to balance security, privacy, cultural, and operational considerationsin a pragmatic, risk-based manner appropriate to a global pharmaceutical organization.
  • High level of integrity, discretion, and professional judgement, with demonstrated ability to handle sensitive, confidential, and legally privileged information with the utmost care.

If you come across a role that intrigues you but doesn27t perfectly line up with your resume, we encourage you to apply anyway. You could be one step away from work that will transform your life and career.

Compensation Overview:

Princeton - NJ - US: $188,790 - $228,763

The starting compensation range(s) for this role are listed above for a full-time employee (FTE) basis. Additional incentive cash and stock opportunities (based on eligibility) may be available. The starting pay rate takes into account characteristics of the job, such as required skills, where the job is performed, the employee27s work schedule, job-related knowledge, and experience. Final, individual compensation will be decided based on demonstrated experience.

Eligibility for specific benefits listed on our careers site may vary based on the job and location. For more on benefits, please visit

Benefit offerings are subject to the terms and conditions of the applicable plans in effect at the time and may require enrollment. Our benefits include:

  • Health Coverage: Medical, pharmacy, dental, and vision care.

  • Wellbeing Support: Programs such as BMS Well-Being Account, BMS Living Life Better, and Employee Assistance Programs (EAP).

  • Financial Well-being and Protection: 401(k) plan, short- and long-term disability, life insurance, accident insurance, supplemental health insurance, business travel protection, personal liability protection, identity theft benefit, legal support, and survivor support.

0Work-life benefits include:

Paid Time Off

  • US Exempt Employees: flexible time off (unlimited, with manager approval, 11 paid national holidays (not applicable to employees in Phoenix, AZ, Puerto Rico or Rayzebio employees)

  • Phoenix, AZ, Puerto Rico and Rayzebio Exempt, Non-Exempt, Hourly Employees: 160 hours annual paid vacation for new hires with manager approval, 11 national holidays, and 3 optional holidays

Based on eligibility*, additional time off for employees may include unlimited paid sick time, up to 2 paid volunteer days per year, summer hours flexibility, leaves of absence for medical, personal, parental, caregiver, bereavement, and military needs and an annual Global Shutdown between Christmas and New Years Day.

All global employees full and part-time who are actively employed at and paid directly by BMS at the end of the calendar year are eligible to take advantage of the Global Shutdown.

*Eligibility Disclosure: The summer hours program is for United States (U.S.) office-based employees due to the unique nature of their work. Summer hours are generally not available for field sales and manufacturing operations and may also be limited for the capability centers. Employees in remote-by-design or lab-based roles may be eligible for summer hours, depending on the nature of their work, and should discuss eligibility with their manager. Employees covered under a collective bargaining agreement should consult that document to determine if they are eligible. Contractors, leased wo

About BristolMyers Squibb

BristolMyers Squibb Careers

Join the vibrant team at BristolMyers Squibb, a leader in global biopharmaceutical innovation, where your career growth is as important as the life-changing solutions we develop. At BristolMyers Squibb, we are committed to fostering a diverse and inclusive workplace that encourages professional growth and development. Work You’ll Do Embark on a career with BristolMyers Squibb and be part of a company that’s dedicated to discovering, developing, and delivering innovative medicines that help patients prevail over serious diseases. With us, you’ll contribute to a culture that embraces scientific innovation, responsible leadership, and community outreach. Explore job opportunities in various fields from research to marketing, and join a team that values leadership and diversity. Our commitment to career growth means we support your journey with extensive training programs, leadership development opportunities, and a global, diverse network of professionals. Innovative Work At BristolMyers Squibb, innovation is at the core of everything we do. From pioneering research in oncology to breakthroughs in immunology, our professionals have the opportunity to make significant contributions to the field and impact lives globally. Our collaborative environment encourages team members to challenge the status quo and bring forward ideas that pave the way for groundbreaking solutions. Be Part of a Great Team Working at BristolMyers Squibb means being part of a team that supports your aspirations and shares your values. Our culture thrives on teamwork, respect, and diversity, creating a workplace where everyone can achieve their potential. Enjoy the benefits of being part of a company that values work-life balance, provides competitive benefits, and fosters an environment where skills and leadership are developed through hands-on experience and comprehensive mentorship programs. Future-Proof Your Career With a multitude of job opportunities ranging from internships to full-time positions, BristolMyers Squibb is not just hiring; we’re building futures. We equip our employees with the tools needed for success, including advanced training in diverse skill sets, leadership programs, and opportunities for professional networking and growth. Stay Connected Join Our Team Search open positions that match your skills and interests. We are looking for passionate, curious, and innovative team players who are ready to make a difference. Explore our career portal for all current job listings and be sure to submit your resume. Keep Up to Date Stay informed with the latest company news, career tips, and industry insights from BristolMyers Squibb. Our careers blog is a resource for potential and current employees looking to maximize their career potential. Job Alert Emails Customize your subscription to receive job alerts and insider information tailored to your preferences. Discover the exciting and rewarding career opportunities that await at BristolMyers Squibb. At BristolMyers Squibb, your career is just the beginning – it’s a pathway to personal and professional fulfillment. Join us and make a global impact.
Learn more about BristolMyers Squibb
Size
32,200 employees
Market Cap
$156.3 billion
Industry
Net Income
-$9 billion
Founded
1887
5 Year Trend
+19%
Revenue
$42.5 billion
NASDAQ

Similar Jobs

More Jobs at BristolMyers Squibb

More Pharmaceuticals & Biotech Jobs

Find similar Director Data Risk & Protection jobs: