Operational Risk & Resilience Specialist

Sunward Federal Credit UnionAlbuquerque, NM
$24 - $30Onsite

About The Position

Responsible for administering and maturing Sunward’s business continuity, disaster recovery (BCP/DR), and incident response planning programs, and for administering enterprise member complaint intake, investigation, and regulatory reporting, as dedicated disciplines within the enterprise risk function. Reporting to the Manager, Enterprise Risk, this role manages the day-to-day execution of resilience activities — business impact analysis, plan development and maintenance, testing and exercises, and incident response readiness — ensuring the credit union can anticipate, withstand, and recover from operational disruption. The role coordinates closely with IT and Information Security on disaster recovery and cyber-incident scenarios, and with Fraud, Compliance, and business unit leaders on continuity planning and incident response across the enterprise. It guides stakeholders on program requirements, ensures adherence to established procedures, documents results, and escalates gaps and concerns appropriately. Operating with limited-to-moderate autonomy within established policy, the Operational Risk & Resilience Specialist makes tactical program decisions, prepares readiness and testing reporting, and refers strategic or cross-departmental exceptions to the Manager, Enterprise Risk.

Requirements

  • Minimum of 2–4 years of experience in business continuity, disaster recovery, operational risk, IT risk, or a related resilience discipline within a financial institution or comparable regulated environment.
  • Experience with complaints, compliance, or member/customer service within a bank or credit union, including investigation and root-cause work.
  • Bachelor’s degree in business administration, information systems, risk management, or a related field, or equivalent experience.
  • Practical knowledge of business continuity and disaster recovery methodology, including BIA, RTO/RPO, plan development, and exercise design.
  • Familiarity with incident response frameworks, severity classification, escalation, and post-incident review.
  • Applied understanding of NCUA examination practices and regulatory expectations for operational resilience and continuity.
  • Awareness of IT / Information Security concepts relevant to disaster recovery and cyber-incident coordination.
  • Proficiency in MS Office and experience administering BCP / resilience software (e.g., Tandem).
  • Strong organizational and project-coordination skills; able to manage multiple plans, exercises, and deadlines simultaneously.
  • Clear written and verbal communication; able to document plans and present readiness status to stakeholders and leadership.
  • Facilitation skills to run effective tabletop exercises and cross-functional planning sessions.
  • Analytical and critical-thinking ability to identify dependencies, single points of failure, and gaps, and recommend practical mitigations.
  • Sound judgment within established policy; escalates strategic or cross-departmental exceptions to the Manager, Enterprise Risk.
  • Collaborative team contributor across Fraud, Compliance, IT / Information Security, and business units.
  • Self-starter with a high sense of urgency and a positive, adaptable mindset.

Nice To Haves

  • Demonstrated experience developing or maintaining continuity plans and conducting tabletop or functional exercises preferred.
  • Relevant certification (e.g., CBCP, ABCP, or similar business continuity/resilience credential) preferred.

Responsibilities

  • Conducts and maintains the Business Impact Analysis (BIA), identifying critical processes, dependencies, recovery time objectives (RTO), and recovery point objectives (RPO).
  • Develops, refreshes, and maintains business continuity plans across departments, aligned to the BIA and current operations.
  • Maintains disaster recovery plans in coordination with IT / Information Security, covering systems recovery, data backup, and alternate processing arrangements.
  • Designs and executes a BCP/DR testing schedule — tabletop exercises, functional tests, and simulations — documenting results and tracking identified gaps to closure with accountable owners.
  • Administers and maintains the business continuity software / program (e.g., Tandem), ensuring data accuracy and supporting stakeholder adoption.
  • Develops and maintains the enterprise incident response plan, including incident classification, severity levels, and activation criteria.
  • Maintains the roles, responsibilities, and escalation matrix spanning Fraud, Compliance, IT / Information Security, Legal, and executive leadership.
  • Establishes and documents incident communication protocols — internal notification, member communication, regulator notification (e.g., NCUA 72-hour), and law enforcement coordination.
  • Builds and maintains incident playbooks for priority scenarios (cyber event, vendor breach, fraud event, operational outage).
  • Coordinates and facilitates incident response tabletop exercises, captures lessons learned, and drives post-incident corrective actions to closure.
  • Prepares resilience and continuity reporting — readiness status, test outcomes, and open gaps — feeding the Manager’s program reporting to the Risk Oversight Committee.
  • Integrates resilience considerations into new-product and change reviews, advising business units on continuity and incident implications.
  • Supports regulatory examinations (e.g., NCUA), audits, and insurance reviews by preparing documentation and helping execute management responses.
  • Develops strong working relationships with business units, IT / Information Security, and control partners to support consistent application of resilience standards.
  • Receives and researches member/customer complaints across channels (phone, mail, email, social media).
  • Investigates issues, including root-cause and customer-impact analysis.
  • Manages intake, prioritization, and routing of complaints to meet internal and regulatory timelines.
  • Tracks complaints and trends, and prepares reports for management identifying risk areas.
  • Drafts summary and response memos to management and regulators.
  • Maintains detailed records to support audits and exams.
  • Ensures complaint handling follows applicable regulations (e.g., Reg E, UDAAP, NCUA/CFPB requirements) and internal policy.
  • Escalates high-risk or regulator-directed complaints appropriately.
  • Collaborates with Compliance to meet regulatory deadlines and improve escalation processes.
  • Identifies recurring root causes and recommends process, policy, or product fixes.
  • Supports front-line staff with guidance on payment/card- or account-related complaint matters.
  • Performs other duties and responsibilities as assigned in support of departmental and organizational objectives.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service