Risk Analyst II (Hyderabad)

Risk Analyst II (Hyderabad)

07 Aug
|
Bristol-Myers Squibb
|
Hyderabad

07 Aug

Bristol-Myers Squibb

Hyderabad

Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives. Read more.

Job Description 1: IT Risk Analyst - Risk Operations (3-5 Years Experience) Position Summary

The IT Risk Analyst, IT Risk Operations is a judgment-driven role responsible for reviewing, interpreting, and acting on risk signals produced by BMS's automated risk assessment infrastructure. As BMS transitions to a more automated operating model - where structured tiering, continuous monitoring, and integrated assessment frameworks handle intake and classification - the analysts focus shifts decisively toward review, challenge, exception handling, and stakeholder engagement.

This is not primarily a processing or intake role. It is an analytical and advisory role where sound risk judgment, clear communication, and accountability for final risk determinations are the core expectations.

Key Responsibilities Risk Review Judgment

- Review and validate risk determinations produced through BMS's integrated risk assessment framework, including Cyber Tier assignments (Tie-5), regulatory classifications (GDPR, EU AI Act, GxP, etc. ), and control recommendations across 9 risk domains
- Apply independent analytical judgment to accept, challenge, or override system-generated risk outputs; document rationale clearly in ServiceNow (SNOW) for all override decisions
- Identify missing context, ambiguous scope, or inconsistencies between risk outputs and known project characteristics; engage project teams to resolve gaps before closing records
- Interpret and communicate risk signals and outputs in clear, stakeholder-facing language - translating technical determinations into actionable guidance without relying on raw tier scores or regulatory jargon

Exception Handling Escalation
- Own exception handling for edge cases, novel technology types, cross-jurisdictional complexity, and cases where risk assessments indicate insufficient or ambiguous input
- Escalate material discrepancies to Risk Leads, BISOs, or Privacy SMEs with documented rationale; serve as the first line of analytical accountability for the risk record
- Support periodic review of auto-approved projects, identifying patterns or anomalies that warrant re-evaluation

Stakeholder Engagement




- Lead or participate in structured touchpoints with project teams, informing them of assessment status, applicable controls, and required documentation
- Serve as a point of contact for project team questions about risk outputs; translate technical risk determinations into clear, actionable guidance
- Collaborate with Legal/Privacy SMEs (DPIA, TIA, SCC workflows) at defined handoff points to ensure risk findings are correctly consumed downstream

Audit Readiness Documentation
- Maintain auditor-ready records in SNOW and GRC platforms; ensure every determination - accepted, challenged, or overridden - is traceable with documented rationale
- Prepare concise, high-quality assessment summaries and control attestations for management and compliance audiences
- Support internal and external audit activities by clearly articulating the basis for risk determinations and the human review actions that followed

Continuous Improvement
- Identify patterns in override rates, exception types, and assessment flags that may indicate framework gaps or emerging risk themes
- Apply a continuous improvement mindset to enhance assessment quality, SLA performance, and the overall stakeholder experience

Qualifications Experience

Required

- 3-5 years of experience in IT risk management, cybersecurity risk, IT audit, privacy compliance, or a directly related field
- Demonstrated ability to interpret and act on risk outputs or signals - not just execute process steps - with a clear track record of sound analytical judgment
- Working knowledge of NIST Cyber Risk Management Framework and NIST 800-53 controls library
- Familiarity with major data privacy regulations (GDPR, CCPA, EU AI Act, GxP)
- Experience with GRC platforms (ServiceNow GRC or equivalent)
- Strong written and verbal communication skills; ability to explain risk determinations clearly to both technical and non-technical audiences
- Experience with pre/post-implementation risk assessments, cybersecurity, data privacy, and/or digital transformation initiatives

Preferred

- Exposure to AI/ML risk assessment frameworks or emerging technology risk




- Experience working in automated or tool-assisted workflow environments
- Relevant certifications: CISA, CRISC, CISSP, CISM, or equivalent

Desired Candidate Characteristics

- Strong analytical and risk judgment instincts - comfortable forming a defensible view from incomplete information
- Inquisitive and bold; willing to challenge outputs, ask difficult questions, and escalate when warranted
- Cooperative across IT, Legal, Privacy, and Business functions
- Comfortable working with system-generated risk signals and outputs rather than manually gathering inputs
- Adaptable to a continuously evolving, automation-enabled operating model with a growth mindset
- Commitment to healthcare and patient impact as the guiding north star for all risk decisions

If you come across a role that intrigues you but doesn't perfectly line up with your resume, we encourage you to apply anyway. You could be one step away from work that will transform your life and career.

With a single vision as inspiring as Transforming patients lives through science, every BMS employee plays an integral role in work that goes far beyond ordinary. Each of us is empowered to apply our individual talents and unique perspectives in a supportive culture, promoting global participation in clinical trials, while our shared values of passion, innovation, urgency, accountability, inclusion and integrity bring out the highest potential of each of our colleagues.

On-site Protocol

BMS has an occupancy structure that determines where an employee is required to conduct their work. This structure includes site-essential, site-by-design, field-based and remote-by-design jobs. The occupancy type that you are assigned is determined by the nature and responsibilities of your role.

BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations in completing this application, or in any part of the recruitment process, do not include an email or URL in this text.

Disclaimer : This job posting has been aggregated from external source. Role details, content, and availability are subject to change. Applicants are advised to confirm the latest information directly on the company website before applying.

📌 Risk Analyst II (Hyderabad)
🏢 Bristol-Myers Squibb
📍 Hyderabad

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: risk analyst ii (hyderabad) / hyderabad

Subscribe to this job alert:

Get the latest job offers by email for: risk analyst ii (hyderabad) / hyderabad