
Staff Security Risk and Compliance Program Manager – Business Resilience
Confluent
full-time
Posted on:
Location Type: Remote
Location: Remote • 🇺🇸 United States
Visit company websiteSalary
💰 $213,200 - $250,500 per year
Job Level
Lead
Tech Stack
AWSAzureGoogle Cloud PlatformRTOS
About the role
- Own the strategic direction and roadmap for the integrated Business Continuity, Disaster Recovery, and Resilience program across the enterprise. Drive the evolution of the program maturity model.
- Lead the execution of comprehensive, regular Business Impact Analysis (BIA) sessions with business unit leaders to identify and document critical functions, interdependencies, Recovery Time Objectives (RTOs), and Recovery Point Objectives (RPOs). Partner with Risk Management to integrate resilience findings into the corporate risk register.
- Oversee the development, review, and continuous improvement of all BCM plans, including departmental plans, crisis management playbooks, communication strategies, and technology recovery plans (DR). Ensure plans meet industry standards and regulatory expectations.
- Design, coordinate, and lead complex, full-scale resilience testing and validation exercises (e.g., tabletop exercises, simulation drills, functional tests) across technology and business teams. Develop clear objectives, conduct post-test analysis, and manage the remediation of identified gaps.
- Establish and maintain the program governance framework. Develop key performance indicators (KPIs) and metrics to regularly report on the state of organizational resilience to executive leadership, the Board, and regulatory bodies.
- Ensure the BCM program is tightly integrated with other GRC domains, particularly Third-Party Risk Management (TPRM), including vetting third-party resilience capabilities.
- Stay current on relevant industry best practices (e.g., ISO 22301, NIST) and regulatory requirements (e.g., financial sector resilience rules) to ensure program compliance.
Requirements
- 8+ years of experience in Business Continuity, Disaster Recovery, or Organizational Resilience roles, with at least 3 years managing an enterprise-level program in a tech company.
- Experience in helping company achieve ISO 22301
- Deep expertise in conducting and analyzing Business Impact Analyses (BIA) and developing detailed recovery strategies.
- Proven ability to design and execute complex, cross-functional continuity and disaster recovery test scenarios.
- Strong knowledge of and experience in all facets of integrated security governance, risk, and compliance management.
- Strong security engineering fundamentals background in infrastructure security controls in GCP, AWS, Azure, and/or web application security.
- Experience with integrating BCM processes or findings into the GRC platform.
- Strong project management and organizational skills.
- Exceptional analytical and problem-solving skills, with a data-driven approach to decision-making.
- Experience in running long-term, complex security programs that deliver iterative improvements and risk reduction.
- Excellent written and verbal communication skills. The ability to influence and lead without direct authority. Detail-oriented with a strong analytical mindset.
- Excellent ability to articulate complex technical concepts and program statuses to executive-level audiences and technical teams.
Benefits
- Offers Equity 📊 Resume Score Upload your resume to see if it passes auto-rejection tools used by recruiters Check Resume Score
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard skills
Business ContinuityDisaster RecoveryBusiness Impact AnalysisRecovery Time ObjectivesRecovery Point ObjectivesISO 22301GRCsecurity governancerisk managementinfrastructure security
Soft skills
project managementorganizational skillsanalytical skillsproblem-solving skillscommunication skillsinfluencing skillsdetail-orienteddata-driven decision-makingleadershipcross-functional collaboration