At Bristol Myers Squibb, our employees often ask, “Who are you working for?”—a question that fuels collaboration, accountability, and urgency in our work. Our purpose-driven culture inspires us to discover, develop, and deliver innovative medicines to prevail over serious diseases. We offer uniquely interesting and meaningful work, opportunities for growth, and a supportive environment that values inclusion, wellbeing, flexibility, and comprehensive benefits. This is work that transforms the lives of patients, and the careers of those who do it.
The Cyber Resiliency Manager for the manufacturing site is responsible for protecting and strengthening the resilience of site-specific IT and OT systems that support pharmaceutical production. This role ensures that the site can anticipate, withstand, respond to, and recover quickly from cyber incidents without compromising product quality, patient safety, or regulatory compliance. The manager acts as the site focal point for cyber risk management, incident response, and recovery planning, working closely with both site IT leadership and cybersecurity functions. This role is critical to ensuring uninterrupted pharmaceutical production and protecting patient safety in an increasingly complex threat environment.
Major Responsibilities and Accountabilities:
Cyber Risk Resiliency Strategy & Governance
-
Develop and execute a site-level cyber resiliency program, aligned with BMS policies and standards.
-
Identify and assess cyber risks across IT, OT, automation, and manufacturing execution systems (MES, SCADA, PLCs, Laboratory Instruments).
-
Define and validate site-specific recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical digital systems.
-
Maintain and report site cyber resiliency KPIs and KRIs to site leadership and the enterprise cybersecurity function on a regular cadence.
-
Align with the Site General Manager, Quality, and EHS functions on resiliency priorities and risk tolerance.
Incident Response & Recovery
-
Lead or co-lead the site cyber incident response process, coordinating with the CFC, IT, and OT teams.
-
Oversee and test disaster recovery (DR) and backup strategies for site systems (e.g., MES, LIMS, ERP, automation).
-
Support cyber crisis simulations, ransomware drills, and tabletop exercises with site leadership and operators.
-
Ensure lessons learned from incidents are embedded into site resiliency practices.
Operational Technology (OT) & Manufacturing Systems Resilience
-
Partner with Engineering and Automation to secure ICS/OT environments, including patching, network segmentation, and secure remote access.
-
Ensure redundancy and contingency measures for critical control systems and data flows.
-
Collaborate with vendors and system integrators to strengthen the resilience of third-party technology supporting production.
Compliance & Regulatory Readiness
-
Ensure cybersecurity controls comply with GxP requirements and 21 CFR Part 11 as applicable to digital manufacturing systems.
-
Support FDA, EMA, and other regulatory audit readiness, providing evidence of cyber resiliency controls and incident response capability.
-
Collaborate with Quality and Validation teams on computer system validation (CSV/CSA) activities that intersect with cybersecurity.
-
Maintain documentation and records to support regulatory inspections and internal audits.
Awareness & Training
-
Deliver cyber resiliency awareness training for site employees, with tailored sessions for operators, engineers, and leadership.
-
Act as the resilience advocate at the site, embedding cyber recovery readiness into daily operations.
Qualifications
Minimum Requirements
-
Minimum education of a bachelor’s degree in Cybersecurity, Computer Science, Engineering, or a related field is required.
-
Minimum of five (5) years of experience in cybersecurity, OT security, or cyber resiliency, with at least three (3) years in a manufacturing or critical infrastructure setting is required.
-
Strong understanding of OT/ICS environments, pharmaceutical manufacturing systems, and automation technologies.
-
Demonstrated experience operating within a GxP-regulated environment (required).
-
Familiarity with regulatory frameworks and expectations for cybersecurity in pharma (FDA, EMA).
-
Familiarity with NIST CSF, IEC 62443 frameworks.
-
Understanding of the Purdue Model or ISA/IEC OT network architecture.
-
Hands-on experience with pharma manufacturing systems such as MES, LIMS, and ERP platforms (e.g., SAP).
-
Strong stakeholder management and communication skills; ability to influence site leadership and cross-functional teams without direct authority.
-
Experience developing and presenting risk reports, KPIs, and executive summaries.
Preferred Qualifications
-
GICSP (Global Industrial Cyber Security Professional) – highly relevant to OT/ICS context
-
CISSP, CISM, or CRISC
-
ISA/IEC 62443 certifications or ICS-CERT training
#LI-Hybrid
We hire for skills and capabilities, not just credentials – if this role excites you, but doesn’t perfectly match your resume, we encourage you to apply anyway.
Compensation Overview:
Bothell - WA - US: $125,480 - $152,049

The starting pay range(s) listed above is for full-time employees (FTE). You may also be eligible for additional discretionary incentive cash and stock opportunities. We determine starting pay thoughtfully – carefully considering the nature of the role, required skills, work location, schedule and the knowledge and experience you bring. Final compensation is guided by pay equity principles and applicable employment laws. Compensation programs are reviewed on an ongoing basis and may be adjusted over time to reflect evolving market factors, and individual, team or Company performance.
Benefits:
Subject to the terms and conditions of the applicable plans then in effect, you may be eligible to participate in our comprehensive benefit plans – including wellbeing support, retirement and financial protection benefits, and insurance offerings (medical, dental, vision, life and disability).
U.S.-based exempt employees are eligible for Flexible Time Off (FTO), which provides paid time off without a set accrual limit, subject to manager approval, along with 11 paid company holidays each year.
Non-exempt employees, RayzeBio employees, and employees located in Puerto Rico receive 160 hours of paid vacation annually for new hires (subject to manager approval), 11 paid company holidays, and 3 optional holidays.
Depending on eligibility, employees may also have access to additional time-off benefits, including paid sick leave, up to two paid volunteer days per year, summer hours flexibility, and leaves of absence for medical, personal, parental, caregiver, bereavement, or military needs. Eligible employees also enjoy an annual Global Shutdown between Christmas Day and New Year's Day.
U.S.-based job seekers can explore full benefit offerings at https://careers.bms.com/benefits
How We Work
Where you work matters – because collaboration, innovation and patient impact happen in many settings. Our roles are structured across four work models: site-essential, site-by-design, field-based and remote-by-design. The model assigned to this role is based on its core responsibilities. Learn more at https://careers.bms.com/ways-of-working.
Supporting People with Disabilities
BMS is dedicated to ensuring that people with disabilities can excel through a transparent recruitment process, reasonable workplace accommodations/adjustments and ongoing support in their roles. Applicants can request a reasonable workplace accommodation/adjustment prior to accepting a job offer. If you require reasonable accommodations/adjustments in completing this application, or in any part of the recruitment process, direct your inquiries to [email protected] . Visit careers.bms.com/eeo-accessibility to access our complete Equal Employment Opportunity statement.
Candidate Rights
BMS will consider qualified applicants with arrest and conviction records, pursuant to applicable laws in your area.
For roles based in Los Angeles County only: If you live in or expect to work from Los Angeles County if hired for this position, please visit this page for important additional information: https://careers.bms.com/california-residents/
Data Protection
We will never request payments, financial information, or social security numbers during our application or recruitment process. Learn more about protecting yourself at https://careers.bms.com/fraud-protection .
Any data processed in connection with role applications will be treated in accordance with applicable data privacy policies and regulations.
If this posting is missing required information required by local law or incorrect, contact BMS at [email protected] with the Job Title and Requisition number. Do not send application-related inquiries to this email. To check your application status, please login to your Candidate Home Account.
R1606192 : Manager, Cybersecurity - Manufacturing