Jobs and Careers
BR

Senior Counsel, Data Governance, Law & Compliance

Bristol Myers Squibb
United Statesfull_timeVerifiedPosted 30 Jun 2026
💰 $268,212/yr($221,340/yr$268,212/yr)

About the role

Working with Us
Challenging. Meaningful. Life-changing. Those aren’t words that are usually associated with a job. But working at Bristol Myers Squibb is anything but usual. Here, uniquely interesting work happens every day, in every department. From optimizing a production line to the latest breakthroughs in cell therapy, this is work that transforms the lives of patients, and the careers of those who do it. You’ll get the chance to grow and thrive through opportunities uncommon in scale and scope, alongside high-achieving teams. Take your career farther than you thought possible.

Bristol Myers Squibb recognizes the importance of balance and flexibility in our work environment. We offer a wide variety of competitive benefits, services and programs that provide our employees with the resources to pursue their goals, both at work and in their personal lives. Read more: careers.bms.com/working-with-us.

Position Summary

The Senior Counsel, Data Governance, Law & Compliance provides legal and compliance leadership for enterprise data governance initiatives at Bristol Myers Squibb. Sitting within the AI, Data and Privacy Law and Compliance department and reporting to the Head of AI & Data Governance, Law and Compliance, this role partners closely with Business Insights and Technology (BI&T) to advance the company's data governance framework across R&D, Commercial, Medical, Manufacturing, and enabling functions. The Senior Counsel translates evolving global data and AI requirements into practical policies, controls, and guardrails that support responsible data use and AI adoption in a highly regulated life sciences environment, while relying on Privacy Law & Compliance as the enterprise owner of personal data and privacy compliance matters.

Key Responsibilities

  • Provide legal counsel on enterprise data governance initiatives across the data lifecycle, including classification, access, use, sharing, retention, and disposition.

  • Partner with cross-functional stakeholders to advance the data governance operating model, accountability framework, and supporting governance forums.

  • Draft foundational data governance policies and standards, including Data Classification, Acceptable Use & Handling, Records & Retention, Data Residency & Cross-Border Transfer, Third-Party Data Handling, Privilege Handling, Trade Secret Protection, and crown jewel data protection.

  • Collaborate with AI Governance counsel colleagues on responsible AI standards, and secondary use and reuse frameworks so that data flowing into AI pipelines is lawful, and contractually permitted.

  • Partner with Privacy Law & Compliance on personal data and privacy matters, ensuring data governance policies, classification taxonomy, and controls align with and support the enterprise privacy program rather than duplicate it; coordinate with Privacy on intersecting topics such as personal data classification and linkage, cross-border transfers, automated decision-making, and data subject rights.

  • Advise on non-privacy domain-specific obligations across clinical and real world data, GxP data integrity, commercial data, financial data (including MNPI and SOX), and HR and employee data, partnering with Privacy Law & Compliance where personal data is implicated.

  • Track and interpret global data and AI laws and standards (e.g., EU AI Act, ISO/IEC 27001, 27701, 42001, SOC 2) and translate them into actionable policies, playbooks, and training materials, drawing on Privacy Law & Compliance for privacy-specific regulatory interpretation.

  • Partner with external advisors as needed on policy design, taxonomy, and operating model rollout, and review deliverables for legal soundness and fit to BMS.

  • Work with BI&T Information Security so that data controls, including classification tags, linkage rules, and AI access controls, are enforceable in enterprise systems and produce defensible evidence.

  • Review and negotiate data-related contractual provisions with vendors, partners, and third-party data providers, including data use, residency, downstream restrictions, and audit rights, coordinating with Privacy Law & Compliance on personal data terms and working with technology contracting team on relevant contract templates.

  • Help design and deliver data governance training for legal, compliance, and business audiences.

  • Maintain clear documentation to support audit readiness, regulatory inquiries, and governance maturity assessments.

Qualifications

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Bristol Myers Squibb

View company profile →