Cyber Resiliency Manager

Bristol Myers SquibbBothell, WA
$125,480 - $152,049Hybrid

About The Position

The Cyber Resiliency Manager for the manufacturing site is responsible for protecting and strengthening the resilience of site-specific IT and OT systems that support pharmaceutical production. This role ensures that the site can anticipate, withstand, respond to, and recover quickly from cyber incidents without compromising product quality, patient safety, or regulatory compliance. The manager acts as the site focal point for cyber risk management, incident response, and recovery planning, working closely with both site IT leadership and cybersecurity functions. This role is critical to ensuring uninterrupted pharmaceutical production and protecting patient safety in an increasingly complex threat environment.

Requirements

  • Minimum education of a bachelor’s degree in Cybersecurity, Computer Science, Engineering, or a related field is required.
  • Minimum of five (5) years of experience in cybersecurity, OT security, or cyber resiliency, with at least three (3) years in a manufacturing or critical infrastructure setting is required.
  • Strong understanding of OT/ICS environments, pharmaceutical manufacturing systems, and automation technologies.
  • Demonstrated experience operating within a GxP-regulated environment (required).
  • Familiarity with regulatory frameworks and expectations for cybersecurity in pharma (FDA, EMA).
  • Familiarity with NIST CSF, IEC 62443 frameworks.
  • Understanding of the Purdue Model or ISA/IEC OT network architecture.
  • Hands-on experience with pharma manufacturing systems such as MES, LIMS, and ERP platforms (e.g., SAP).
  • Strong stakeholder management and communication skills; ability to influence site leadership and cross-functional teams without direct authority.
  • Experience developing and presenting risk reports, KPIs, and executive summaries.

Nice To Haves

  • GICSP (Global Industrial Cyber Security Professional) – highly relevant to OT/ICS context
  • CISSP, CISM, or CRISC
  • ISA/IEC 62443 certifications or ICS-CERT training

Responsibilities

  • Develop and execute a site-level cyber resiliency program, aligned with BMS policies and standards.
  • Identify and assess cyber risks across IT, OT, automation, and manufacturing execution systems (MES, SCADA, PLCs, Laboratory Instruments).
  • Define and validate site-specific recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical digital systems.
  • Maintain and report site cyber resiliency KPIs and KRIs to site leadership and the enterprise cybersecurity function on a regular cadence.
  • Align with the Site General Manager, Quality, and EHS functions on resiliency priorities and risk tolerance.
  • Lead or co-lead the site cyber incident response process, coordinating with the CFC, IT, and OT teams.
  • Oversee and test disaster recovery (DR) and backup strategies for site systems (e.g., MES, LIMS, ERP, automation).
  • Support cyber crisis simulations, ransomware drills, and tabletop exercises with site leadership and operators.
  • Ensure lessons learned from incidents are embedded into site resiliency practices.
  • Partner with Engineering and Automation to secure ICS/OT environments, including patching, network segmentation, and secure remote access.
  • Ensure redundancy and contingency measures for critical control systems and data flows.
  • Collaborate with vendors and system integrators to strengthen the resilience of third-party technology supporting production.
  • Ensure cybersecurity controls comply with GxP requirements and 21 CFR Part 11 as applicable to digital manufacturing systems.
  • Support FDA, EMA, and other regulatory audit readiness, providing evidence of cyber resiliency controls and incident response capability.
  • Collaborate with Quality and Validation teams on computer system validation (CSV/CSA) activities that intersect with cybersecurity.
  • Maintain documentation and records to support regulatory inspections and internal audits.
  • Deliver cyber resiliency awareness training for site employees, with tailored sessions for operators, engineers, and leadership.
  • Act as the resilience advocate at the site, embedding cyber recovery readiness into daily operations.

Benefits

  • Health Coverage: Medical, pharmacy, dental, and vision care.
  • Wellbeing Support: Programs such as BMS Well-Being Account, BMS Living Life Better, and Employee Assistance Programs (EAP).
  • Financial Well-being and Protection: 401(k) plan, short- and long-term disability, life insurance, accident insurance, supplemental health insurance, business travel protection, personal liability protection, identity theft benefit, legal support, and survivor support.
  • Work-life benefits include: Paid Time Off US Exempt Employees: flexible time off (unlimited, with manager approval, 11 paid national holidays (not applicable to employees in Phoenix, AZ, Puerto Rico or Rayzebio employees) Phoenix, AZ, Puerto Rico and Rayzebio Exempt, Non-Exempt, Hourly Employees: 160 hours annual paid vacation for new hires with manager approval, 11 national holidays, and 3 optional holidays
  • Based on eligibility, additional time off for employees may include unlimited paid sick time, up to 2 paid volunteer days per year, summer hours flexibility, leaves of absence for medical, personal, parental, caregiver, bereavement, and military needs and an annual Global Shutdown between Christmas and New Years Day.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service