Sr. Operational Cybersecurity Manager

Posted today

3b staffingNew York (NY)

SENIORITY

Manager

Apply

About the role

Sr Operational Resilience Manager
Location: New York City, NY 10019 (Onsite 5 Days/Week)
Type: Contract-to-Hire Work Authorization: US Citizen or Green Card Holder (10+ Years) Only
Interview Process: Video + In-Person
Position Overview: We are seeking a highly experienced Sr. Operational Resilience Manager to lead enterprise-wide resilience initiatives for a major financial institution. This role will be responsible for developing and executing operational resilience, cyber resilience, business continuity, and disaster recovery strategies across the organization. The ideal candidate will have deep expertise in cybersecurity, operational risk management, regulatory compliance, incident response, and resilience governance within highly regulated banking or financial services environments.
Key Responsibilities: Enterprise Resilience Strategy Develop and implement enterprise operational and cyber resilience strategies aligned with regulatory frameworks and industry standards. Define and monitor KRIs, KPIs, KCIs, and resilience metrics. Partner with executive leadership to embed resilience across business and technology functions. Evaluate emerging threats, operational risks, and regulatory changes. Incident Management & Cyber Resilience Lead incident response and cyber resilience planning across enterprise systems. Conduct tabletop exercises, simulations, and resilience testing. Coordinate with regulators, auditors, law enforcement, and third-party vendors during incidents. Integrate cyber resilience into enterprise risk and IT security programs. Business Continuity & Disaster Recovery Develop and maintain enterprise-wide BC/DR strategies and recovery frameworks. Ensure critical systems meet RTO/RPO objectives. Conduct disaster recovery testing, audits, and continuity exercises. Build alternative operational processes for disruption scenarios. Governance, Risk & Compliance Ensure compliance with FFIEC, OCC, Basel, DORA, and other financial regulatory requirements. Develop governance policies, resilience standards, and operational procedures. Serve as key liaison for auditors and regulatory agencies. Promote resilience awareness and compliance culture enterprise-wide. Third-Party & Vendor Resilience Assess operational and cyber risks associated with vendors and suppliers. Establish due diligence and resilience requirements for third-party providers. Develop contingency and exit strategies for critical vendors. Partner with procurement and risk teams for vendor governance. Threat Intelligence & Risk Monitoring Lead operational risk monitoring and threat intelligence initiatives. Partner with cybersecurity and fraud prevention teams to mitigate emerging risks. Implement continuous improvement processes based on incidents and audit findings. Leadership & Stakeholder Management Lead cross-functional resilience and governance programs. Present resilience posture and risk updates to senior leadership. Drive enterprise-wide resilience awareness, training, and engagement. Advocate for resilience investments and strategic initiatives.
Required Qualifications: 15+ years of experience in Operational Resilience, Cybersecurity, IT Risk, Business Continuity, or Enterprise Risk Management within financial services. Strong experience in highly regulated banking environments. Deep knowledge of FFIEC, OCC, Basel, DORA, BC/DR, and cyber resilience frameworks. Experience leading enterprise incident response and resilience programs. Strong understanding of cloud resilience, third-party risk, and disaster recovery strategies. Excellent executive communication and stakeholder management skills.
Preferred Qualifications: TOGAF or enterprise architecture background preferred. Certifications such as CISSP, CISM, CISA, CBCP, or CRISC highly preferred. Experience presenting to regulators, auditors, and executive leadership.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this