Director, Cybersecurity Recovery & Resiliency
Indexed description
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.
Pay And Benefits
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
- Immutable backup recovery: immutable, air-gapped backup storage, malware and ransomware analysis on backup data, and digital forensics support to enable clean, trusted recovery decisions.
- Full-stack and bare-metal recovery: the capability to rebuild and restore infrastructure and applications from the ground up following a significant cyber-induced disruption.
Your Primary Responsibilities
Cyber Resiliency Strategy & Program Leadership
- Own the enterprise cyber resiliency strategy and roadmap for recovering from extreme cyber events (ransomware, destructive malware, data corruption), tracking key recovery metrics and reporting to senior leadership and risk committees.
- Lead immutable/air-gapped backup infrastructure, including malware and integrity scanning of backup data and forensic support for incident investigations, in partnership with the IR/Forensics team.
- Own recovery readiness (runbooks, automation, and regular testing) for critical infrastructure and applications across mainframe, Linux/VMware, storage, and cloud, in partnership with Infrastructure and Cloud teams.
- Serve as the key liaison to Business Continuity, Risk, and Audit on resiliency posture and regulatory readiness, and represent cyber resiliency in incident response and crisis management planning.
- Hire, develop, and lead the resiliency engineering team, and manage vendor/managed-service relationships supporting recovery tooling.
Qualifications
- Min 10+ years of relevant experience
- Bachelor’s Degree and/or equivalent experience
- 10+ years of progressive experience in infrastructure, disaster recovery, business continuity, or security roles, with at least 4-5 years in a leadership capacity.
- Demonstrated experience designing or operating cyber recovery capabilities (isolated recovery environments, immutable backups, bare-metal recovery) — not just traditional DR/BCP.
- Strong working knowledge of enterprise infrastructure, ideally spanning mainframe systems, distributed databases, Linux/VMware server environments, and enterprise storage platforms.
- Hands-on familiarity with public cloud infrastructure (AWS preferred) and recovery patterns (backup, snapshotting, cross-region/account recovery, access considerations for isolated recovery).
- Experience with ransomware/malware forensics concepts and backup integrity validation, or close partnership with forensics/IR teams.
- Experience leading enterprise-scale recovery exercises (tabletop through full-scale) and reporting outcomes to senior stakeholders.
- Strong understanding of regulatory/operational resilience expectations relevant to the industry.
- Excellent stakeholder management and executive communication skills; ability to translate technical recovery posture into business risk terms.
- Isolated backup and full-stack recovery capabilities are documented, tested, and validated against defined RTO/RPO targets for the organization's most critical services.
- A recurring cyber recovery exercise program is in place with executive-level reporting.
- Clear, auditable evidence of immutable backup coverage and recovery runbooks across on-premise and cloud environments.
- Strong working relationships established with Security, Infrastructure, Business Continuity, and Risk stakeholders.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search