Senior Data Risk and protection Engineer
Bristol Myers Squibb · Hyderabad
- Experience6–8 yrs
- SalaryNot disclosed
- Work modeonsite
- Levelsenior
- Posted17 Sept 2026
About Bristol Myers Squibb
Bristol Myers Squibb is hiring in Hyderabad in pharma biotech. This role looks for around 6+ years of experience.
Skills
- data loss prevention
- insider risk management
- cyber security
- risk management
- compliance
- SIEM
- SOAR Automation
- GDPR
- CCPA
- HIPAA
The role
A security engineer at a pharmaceutical company protects sensitive data through data loss prevention and insider risk management, integrating SIEM and SOAR Automation. The role applies cyber security, risk management, and compliance to configure detection controls and improve incident response.
Full job description
At Bristol Myers Squibb, our employees often ask, “Who are you working for?”—a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.
Position Summary
Bristol Myers Squibb is seeking an experienced Senior Data Risk and protection Engineer to be a part of our data security and data loss prevention program. The successful candidate will be responsible for assisting with the development and implementation of strategies to protect BMS sensitive and confidential data, while also ensuring compliance with industry regulations and standards.
This position will report to the Senior Manager of Data Protection and will be a member of the Data Protection team in the Hyderabad office. The position will be expected to coordinate with stakeholders in the US and globally.
The ideal candidate will have 6-8 years of experience in data security and DLP, with a strong background in cyber security, risk management, and compliance.
The candidate will be responsible for the successful implementation and integration of insider risk management tools and technologies. This role focuses on configuring security systems to detect and mitigate insider threats effectively. The individual will work closely with cross-functional teams, including IT, security, and compliance, to ensure seamless integration of solutions into the existing infrastructure and requires a strong technical background, attention to detail, and a collaborative approach to problem-solving.
If you want an exciting and rewarding career that is meaningful, consider joining our diverse team!
Key Responsibilities
Functional and TechnicalLead the implementation of Insider risk detection tools, ensuring seamless integration with existing security infrastructure and business applications.Support deployment of DLP monitoring capabilities to new environments, potentially using separate DLP solutions. (M&A’s)Configure and fine-tune systems to optimize performance and detection capabilities, reducing false positives while maintaining effective threat detection.Collaborate with stakeholders to develop comprehensive insider threat policies, defining acceptable use, access controls, and monitoring protocols.Regularly review and update policies based on emerging threats, technological advancements, and regulatory changes.Maintain comprehensive documentation of all system configurations, policy changes, and incident response actions to ensure accountability and compliance.Develop regular reports and dashboards to communicate insider risk metrics, trends, and recommendations to senior management and relevant stakeholders.Stay updated on the latest trends in insider threat detection and mitigation, including emerging technologies and threat vectors.Evaluate and recommend new tools, techniques, and best practices to enhance the organization’s insider risk management capabilities.Familiarity with industry regulations and standards such as GDPR, CCPA, and HIPAA.Lead the integration of SIEM and SOAR Automation within the insider risk and DLP program, ensuring these capabilities accelerate detection, investigation, and response workflows.Champion the exploration and adoption of emerging AI technologies to proactively identify anomalous behaviors, predict insider threat patterns, and continuously improve security posture through automated remediation and adaptive risk controls.
We hire for skills and capabilities, not just credentials – if this role excites you, but doesn’t perfectly match your resume, we encourage you to apply anyway.
How We Work
Where you work matters – because collaboration, innovation and patient impact happen in many settings. Our roles are structured across four work models site-essential, site-by-design, field-based and remote-by-design. The model assigned to this role is based on its core responsibilities. Learn more at https //careers.bms.com/ways-of-working.
Supporting People With Disabilities
BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to adastaffingsupport@bms.com. Visit careers.bms.com/eeo-accessibility to access our complete Equal Employment Opportunity statement.
Candidate Rights
BMS will consider qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.
For roles based in Los Angeles County only If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information https //careers.bms.com/california-residents/
Data Protection
We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https //careers.bms.com/fraud-protection.
Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.
If this posting is missing required information required by local law or incorrect, contact BMS at TAEnablement@bms.com with the Job Title and Requisition number. Do not send application-related inquiries to this email. To check your application status, please login to your Candidate Home Account.
R1604605 Senior Data Risk and protection Engineer