Hiring.Camp

Operational Risk & Resilience Specialist

Sandia Laboratory Federal Credit Union

·

Today

Salary
$64k – $80k/yr
Location
Albuquerque, NM
Department
Operations
Experience
2+ years
Source
Paylocity

Description

Description

Summary

Responsible for administering and maturing Sunward’s business continuity, disaster recovery (BCP/DR), and incident response planning programs, and for administering enterprise member complaint intake, investigation, and regulatory reporting, as dedicated disciplines within the enterprise risk function. Reporting to the Manager, Enterprise Risk, this role manages the day-to-day execution of resilience activities — business impact analysis, plan development and maintenance, testing and exercises, and incident response readiness — ensuring the credit union can anticipate, withstand, and recover from operational disruption.

The role coordinates closely with IT and Information Security on disaster recovery and cyber-incident scenarios, and with Fraud, Compliance, and business unit leaders on continuity planning and incident response across the enterprise. It guides stakeholders on program requirements, ensures adherence to established procedures, documents results, and escalates gaps and concerns appropriately.

Operating with limited-to-moderate autonomy within established policy, the Operational Risk & Resilience Specialist makes tactical program decisions, prepares readiness and testing reporting, and refers strategic or cross-departmental exceptions to the Manager, Enterprise Risk.

Essential Functions:

Business Continuity & Disaster Recovery

  • Conducts and maintains the Business Impact Analysis (BIA), identifying critical processes, dependencies, recovery time objectives (RTO), and recovery point objectives (RPO).
  • Develops, refreshes, and maintains business continuity plans across departments, aligned to the BIA and current operations.
  • Maintains disaster recovery plans in coordination with IT / Information Security, covering systems recovery, data backup, and alternate processing arrangements.
  • Designs and executes a BCP/DR testing schedule — tabletop exercises, functional tests, and simulations — documenting results and tracking identified gaps to closure with accountable owners.
  • Administers and maintains the business continuity software / program (e.g., Tandem), ensuring data accuracy and supporting stakeholder adoption.

Incident Response Planning

  • Develops and maintains the enterprise incident response plan, including incident classification, severity levels, and activation criteria.
  • Maintains the roles, responsibilities, and escalation matrix spanning Fraud, Compliance, IT / Information Security, Legal, and executive leadership.
  • Establishes and documents incident communication protocols — internal notification, member communication, regulator notification (e.g., NCUA 72-hour), and law enforcement coordination.
  • Builds and maintains incident playbooks for priority scenarios (cyber event, vendor breach, fraud event, operational outage).
  • Coordinates and facilitates incident response tabletop exercises, captures lessons learned, and drives post-incident corrective actions to closure.

Reporting, Coordination & Support

  • Prepares resilience and continuity reporting — readiness status, test outcomes, and open gaps — feeding the Manager’s program reporting to the Risk Oversight Committee.
  • Integrates resilience considerations into new-product and change reviews, advising business units on continuity and incident implications.
  • Supports regulatory examinations (e.g., NCUA), audits, and insurance reviews by preparing documentation and helping execute management responses.
  • Develops strong working relationships with business units, IT / Information Security, and control partners to support consistent application of resilience standards.

Member Complaints

Intake and Resolution

  • Receives and researches member/customer complaints across channels (phone, mail, email, social media).
  • Investigates issues, including root-cause and customer-impact analysis.
  • Manages intake, prioritization, and routing of complaints to meet internal and regulatory timelines.

Documentation and Reporting

  • Tracks complaints and trends, and prepares reports for management identifying risk areas.
  • Drafts summary and response memos to management and regulators.
  • Maintains detailed records to support audits and exams.

Compliance and Escalation

  • Ensures complaint handling follows applicable regulations (e.g., Reg E, UDAAP, NCUA/CFPB requirements) and internal policy.
  • Escalates high-risk or regulator-directed complaints appropriately.
  • Collaborates with Compliance to meet regulatory deadlines and improve escalation processes.

Process Improvement

  • Identifies recurring root causes and recommends process, policy, or product fixes.
  • Supports front-line staff with guidance on payment/card- or account-related complaint matters.
  • Performs other duties and responsibilities as assigned in support of departmental and organizational objectives.

Qualifications

Experience

  • Minimum of 2–4 years of experience in business continuity, disaster recovery, operational risk, IT risk, or a related resilience discipline within a financial institution or comparable regulated environment.
  • Experience with complaints, compliance, or member/customer service within a bank or credit union, including investigation and root-cause work.
  • Demonstrated experience developing or maintaining continuity plans and conducting tabletop or functional exercises preferred.

Education

  • Bachelor’s degree in business administration, information systems, risk management, or a related field, or equivalent experience.
  • Relevant certification (e.g., CBCP, ABCP, or similar business continuity/resilience credential) preferred.

Knowledge

  • Practical knowledge of business continuity and disaster recovery methodology, including BIA, RTO/RPO, plan development, and exercise design.
  • Familiarity with incident response frameworks, severity classification, escalation, and post-incident review.
  • Applied understanding of NCUA examination practices and regulatory expectations for operational resilience and continuity.
  • Awareness of IT / Information Security concepts relevant to disaster recovery and cyber-incident coordination.
  • Proficiency in MS Office and experience administering BCP / resilience software (e.g., Tandem).

Skills/Abilities

  • Strong organizational and project-coordination skills; able to manage multiple plans, exercises, and deadlines simultaneously.
  • Clear written and verbal communication; able to document plans and present readiness status to stakeholders and leadership.
  • Facilitation skills to run effective tabletop exercises and cross-functional planning sessions.
  • Analytical and critical-thinking ability to identify dependencies, single points of failure, and gaps, and recommend practical mitigations.
  • Sound judgment within established policy; escalates strategic or cross-departmental exceptions to the Manager, Enterprise Risk.
  • Collaborative team contributor across Fraud, Compliance, IT / Information Security, and business units.
  • Self-starter with a high sense of urgency and a positive, adaptable mindset.

Physical Requirements/Work Environment

  • Primarily office-based work with frequent use of computers, phones, and other standard office equipment.
  • Ability to sit, stand, and work at a desk for extended periods throughout the workday.
  • Occasional lifting or moving of light materials (up to 15–20 pounds), such as files or office supplies.
  • May require participation in meetings, training sessions, exercises, or site visits within the organization.
  • Work environment includes deadlines, audits, exercises, or regulatory review periods requiring focused attention and multitasking.
  • Ability to communicate clearly in person, by phone, and electronically with internal stakeholders and external partners.

Requirements

  

Responsibilities & Duties

  • What is the problem      that this position solves?
  • What are the top 3      priorities for this role on a day-to-day basis? 
  • What goals, metrics,      or key outcomes are associated with this position? 
  • What experience or      qualifications are considered must-have versus nice-to-have? 
    • Business Continutiy       and disaster recovery - must have
  • What level of      ownership is expected in this role (execution vs. building/improving      processes)? 
    • Actively building -       may be coming in mid stream. There       is always room for enhancement or improvement. They may b bringing something. Responsibility that the plan is       up-to-date and scalable. There BC       stays on par. It's unique to       their. Where their specific       meeting point is. They'll be       responsible for annual testing of business continuity, and disaster       recovery. Needs to be 2
    • Recovery - RPO       (recovery point objection - system) and RTO (Recovery Time objection -       lights on)
  • What systems or      tools will this individual use regularly?
    • Tandem, Microsof       Office Suite - get them trained up. Using alert media. Alerts       that happen. Might want to expand       on services.
  • Are there any      systems/tools where prior experience is strongly preferred or required? 
  • Who will this      individual interact with most frequently (members, cross-functional      partners, leadership, vendors, etc.)? 
    • Member Complaints -       As getting member complaints in, farming them out. To compliance, Tyler will have eyes on       it if need to get legal involved
      • Tracking to        resolution (not sure if that's happening)
      • Current state:        Can't pull a report to see if done.
    • Business Continuity       and disaster recovery - Department heads
  • What does success      look like in: 
    • The first 60 days? 
    • The first 90 days? 
    • 6 months to 1 year?       Having full ownership of BCP, DR and IR plans, annual disaster recovery       is scheduled, member complaints with compliance and having a process in       place for tracking
  • What will training      look like once they get started?
  • Are there any      incentives outside of CSP? NO
    • If yes, what are       the earnings potential as well as the average bonus?

Logistics & Hiring Process

  • What are the      schedule expectations for this role? 
  • Is this position      on-site, or will it qualify for the flex work policy?
    • What are the       expectations and guidelines for your department as they align with the       flex work policy?
  • What would you like      the interview process to look like? 
    • Recommended       interview structure following TA screening: 

       

Role Level


Recommended Interviews

 

  

TA + Mary (in person) + David Garcia (live/virtual) + Tyler (call)

Skills

Risk ManagementComplianceCustomer Service

Similar Jobs

30

Operational Risk and Control Specialist, Quality Management Unit (QMU), Division for Management Services (DMS), Arab States Regional Office (ASRO), Cairo, Egypt, P-3

United Nations Development Programme (UNDP)·Cairo, Egypt

Today

Operational Risk and Control Specialist, Quality Management Unit (QMU), Division for Management Services (DMS), West and Central Africa Regional Office (WCARO), Dakar, Senegal, P-3

United Nations Development Programme (UNDP)·Dakar, SN

Today

Operational Risk and Control Specialist, Quality Management Unit (QMU), Division for Management Services (DMS), East and Southern Africa Regional Office (ESARO), Johannesburg, South Africa, P-3

United Nations Development Programme (UNDP)·Johannesburg, ZA

Today

Vice President, Operational Risk Management Framework

0101022-GIA PROD US LOS ANGELES·Pune, MH·Hybrid

Today

Operational Risk Specialist

JRI·Needham, MA

Today

Operational Risk & Wellness Manager

Ames Construction Careers·Federal - FL - Belle Glade, US

1d ago

Operational Risk & Wellness Manager

Ames Construction Careers·Federal - NM - Farmington, US

1d ago

Internship: Group Risk Management, Group Non-Financial Risk Management, Group Operational Risk Management (Implementation) [Jan to May 2027]

Ocbc·SGP-Head Office, Singapore·Hybrid

1d ago

Manager - Personal Financial Services (Compliance & Operational Risk)

Hlb·HLT-Hong Leong Tower, Malaysia

1d ago

Operational Risk Data Analyst

Coface·Warszawa, Województwo mazowieckie·Hybrid

3d ago

Operational Risk Analyst

FirstRand provides·2nd Floor, Wings East Tower

4d ago

Payments Operational Risk Management – Senior Associate – Argentina and Chile

JPMorgan Chase·Ciudad Autónoma de Buenos Aires, Argentina

4d ago

Payments Operational Risk Management – Senior Associate – Argentina and Chile

JP Morgan Chase·Ciudad Autónoma de Buenos Aires, Argentina

4d ago

Enterprise Compliance and Operational Risk Analyst - Risk Assessment

Regions·Birmingham, AL - Regions Center +2

5d ago

Compliance & Operational Risk Manager - Private Bank

Ghr·Charlotte, US +1·Onsite

5d ago

Operational Risk Manager

Familyoffice·New York +1

5d ago

Risk Analyst V - Operational Risk Management: Centralized Testing & Verification

Keybank·4900 Tiedeman Road, OH +3·Hybrid

6d ago

Superintendent, Operational Risk & Assurance

Riotinto·Salt Lake City, US

6d ago

Vice President, Country Compliance and Operational Risk Manager

Ghr·Jakarta, Indonesia·Onsite

6d ago

Team Member - ORM-SUPPORT SERVICES-Operational Risk

Kotak Bank·Mumbai, Maharashtra·Onsite

6d ago

Manager, Operational Risk

Sunlife·Sun Life Toronto One York, Canada +1·Hybrid

1w ago

Manager, Operational Risk

Sunlife·Sun Life Toronto One York, Canada +1·Hybrid

1w ago

Compliance & Operational Risk Program Manager - Reporting and Data Analyst

Ghr·Charlotte, US +3·Onsite

1w ago

Compliance and Operational Risk Manager

Ghr·Paris, France

1w ago

Operational Risk Advisor

Bpinternational·MY: Kuala Lumpur - Bangsar South Campus, Malaysia·Remote

1w ago

Vice President, Compliance and Operational Risk Manager, Taiwan

Ghr·Taipei, Taiwan·Onsite

1w ago

Compliance - Operational Risk Management Lead - Vice President

JPMorgan Chase·New York, NY

1w ago

Compliance - Operational Risk Management Lead - Vice President

JP Morgan Chase·New York, NY

1w ago

Vice President, Operational Risk Management

0101022-GIA PROD US LOS ANGELES·Pittsburgh, PA·Hybrid

1w ago

Compliance, Conduct & Operational Risk (CCOR) EMEA Quality Assurance

JPMorgan Chase·BOURNEMOUTH, GB

1w ago