×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Cyber Resiliency Manager

Job in North Bothell Area, Snohomish County, Washington, 98021, USA
Listing for: Bristol Myers Squibb
Full Time position
Listed on 2026-07-20
Job specializations:
  • IT/Tech
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 125480 - 152049 USD Yearly USD 125480.00 152049.00 YEAR
Job Description & How to Apply Below

The Cyber Resiliency Manager for the manufacturing site is responsible for protecting and strengthening the resilience of site‑specific IT and OT systems that support pharmaceutical production. This role ensures that the site can anticipate, withstand, respond to, and recover quickly from cyber incidents without compromising product quality, patient safety, or regulatory compliance. The manager acts as the site focal point for cyber risk management, incident response, and recovery planning, working closely with both site IT leadership and cybersecurity functions.

This role is critical to ensuring uninterrupted pharmaceutical production and protecting patient safety in an increasingly complex threat environment.

Major Responsibilities and Accountabilities Cyber Risk Resiliency Strategy & Governance
  • Develop and execute a site-level cyber resiliency program, aligned with BMS policies and standards.
  • Identify and assess cyber risks across IT, OT, automation, and manufacturing execution systems (MES, SCADA, PLCs, laboratory instruments).
  • Define and validate site‑specific recovery time objectives (RTOs) and recovery point objectives (RPOs) for critical digital systems.
  • Maintain and report site cyber resiliency KPIs and KRIs to site leadership and the enterprise cybersecurity function on a regular cadence.
  • Align with the Site General Manager, Quality, and EHS functions on resiliency priorities and risk tolerance.
Incident Response & Recovery
  • Lead or co‑lead the site cyber incident response process, coordinating with the CFC, IT, and OT teams.
  • Oversee and test disaster recovery (DR) and backup strategies for site systems (e.g., MES, LIMS, ERP, automation).
  • Support cyber crisis simulations, ransomware drills, and tabletop exercises with site leadership and operators.
  • Ensure lessons learned from incidents are embedded into site resiliency practices.
Operational Technology (OT) & Manufacturing Systems Resilience
  • Partner with Engineering and Automation to secure ICs/OT environments, including patching, network segmentation, and secure remote access.
  • Ensure redundancy and contingency measures for critical control systems and data flows.
  • Collaborate with vendors and system integrators to strengthen the resilience of third‑party technology supporting production.
Compliance & Regulatory Readiness
  • Ensure cybersecurity controls comply with GxP requirements and 21 CFR Part 11 as applicable to digital manufacturing systems.
  • Support FDA, EMA, and other regulatory audit readiness, providing evidence of cyber resiliency controls and incident response capability.
  • Collaborate with Quality and Validation teams on computer system validation (CSV/CSA) activities that intersect with cybersecurity.
  • Maintain documentation and records to support regulatory inspections and internal audits.
Awareness & Training
  • Deliver cyber resiliency awareness training for site employees, with tailored sessions for operators, engineers, and leadership.
  • Act as the resilience advocate at the site, embedding cyber recovery readiness into daily operations.
Qualifications

Minimum Requirements

  • Minimum education of a bachelor’s degree in Cybersecurity, Computer Science, Engineering, or a related field.
  • Minimum of five (5) years of experience in cybersecurity, OT security, or cyber resiliency, with at least three (3) years in a manufacturing or critical infrastructure setting.
  • Strong understanding of OT/ICS environments, pharmaceutical manufacturing systems, and automation technologies.
  • Demonstrated experience operating within a GxP‑regulated environment (required).
  • Familiarity with regulatory frameworks and expectations for cybersecurity in pharma (FDA, EMA).
  • Familiarity with NIST CSF, IEC 62443 frameworks.
  • Understanding of the Purdue Model or ISA/IEC OT network architecture.
  • Hands‑on experience with pharma manufacturing systems such as MES, LIMS, and ERP platforms (e.g., SAP).
  • Strong stakeholder management and communication skills; ability to influence site leadership and cross‑functional teams without direct authority.
  • Experience developing and presenting risk reports, KPIs, and executive summaries.

Preferred Qualifications

  • GICSP (Global Industrial Cyber Security Professional) –…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary