Operational Risk & Resilience Specialist
Albuquerque, NM Risk
Job Type
Full-time
Description

Summary

Responsible for administering and maturing Sunward’s business continuity, disaster recovery (BCP/DR), and incident response planning programs, and for administering enterprise member complaint intake, investigation, and regulatory reporting, as dedicated disciplines within the enterprise risk function. Reporting to the Manager, Enterprise Risk, this role manages the day-to-day execution of resilience activities — business impact analysis, plan development and maintenance, testing and exercises, and incident response readiness — ensuring the credit union can anticipate, withstand, and recover from operational disruption.

The role coordinates closely with IT and Information Security on disaster recovery and cyber-incident scenarios, and with Fraud, Compliance, and business unit leaders on continuity planning and incident response across the enterprise. It guides stakeholders on program requirements, ensures adherence to established procedures, documents results, and escalates gaps and concerns appropriately.

Operating with limited-to-moderate autonomy within established policy, the Operational Risk & Resilience Specialist makes tactical program decisions, prepares readiness and testing reporting, and refers strategic or cross-departmental exceptions to the Manager, Enterprise Risk.

Essential Functions:

Business Continuity & Disaster Recovery

  • Conducts and maintains the Business Impact Analysis (BIA), identifying critical processes, dependencies, recovery time objectives (RTO), and recovery point objectives (RPO).
  • Develops, refreshes, and maintains business continuity plans across departments, aligned to the BIA and current operations.
  • Maintains disaster recovery plans in coordination with IT / Information Security, covering systems recovery, data backup, and alternate processing arrangements.
  • Designs and executes a BCP/DR testing schedule — tabletop exercises, functional tests, and simulations — documenting results and tracking identified gaps to closure with accountable owners.
  • Administers and maintains the business continuity software / program (e.g., Tandem), ensuring data accuracy and supporting stakeholder adoption.

Incident Response Planning

  • Develops and maintains the enterprise incident response plan, including incident classification, severity levels, and activation criteria.
  • Maintains the roles, responsibilities, and escalation matrix spanning Fraud, Compliance, IT / Information Security, Legal, and executive leadership.
  • Establishes and documents incident communication protocols — internal notification, member communication, regulator notification (e.g., NCUA 72-hour), and law enforcement coordination.
  • Builds and maintains incident playbooks for priority scenarios (cyber event, vendor breach, fraud event, operational outage).
  • Coordinates and facilitates incident response tabletop exercises, captures lessons learned, and drives post-incident corrective actions to closure.

Reporting, Coordination & Support

  • Prepares resilience and continuity reporting — readiness status, test outcomes, and open gaps — feeding the Manager’s program reporting to the Risk Oversight Committee.
  • Integrates resilience considerations into new-product and change reviews, advising business units on continuity and incident implications.
  • Supports regulatory examinations (e.g., NCUA), audits, and insurance reviews by preparing documentation and helping execute management responses.
  • Develops strong working relationships with business units, IT / Information Security, and control partners to support consistent application of resilience standards.

Member Complaints

Intake and Resolution

  • Receives and researches member/customer complaints across channels (phone, mail, email, social media).
  • Investigates issues, including root-cause and customer-impact analysis.
  • Manages intake, prioritization, and routing of complaints to meet internal and regulatory timelines.

Documentation and Reporting

  • Tracks complaints and trends, and prepares reports for management identifying risk areas.
  • Drafts summary and response memos to management and regulators.
  • Maintains detailed records to support audits and exams.

Compliance and Escalation

  • Ensures complaint handling follows applicable regulations (e.g., Reg E, UDAAP, NCUA/CFPB requirements) and internal policy.
  • Escalates high-risk or regulator-directed complaints appropriately.
  • Collaborates with Compliance to meet regulatory deadlines and improve escalation processes.

Process Improvement

  • Identifies recurring root causes and recommends process, policy, or product fixes.
  • Supports front-line staff with guidance on payment/card- or account-related complaint matters.
  • Performs other duties and responsibilities as assigned in support of departmental and organizational objectives.

Qualifications

Experience

  • Minimum of 2–4 years of experience in business continuity, disaster recovery, operational risk, IT risk, or a related resilience discipline within a financial institution or comparable regulated environment.
  • Experience with complaints, compliance, or member/customer service within a bank or credit union, including investigation and root-cause work.
  • Demonstrated experience developing or maintaining continuity plans and conducting tabletop or functional exercises preferred.

Education

  • Bachelor’s degree in business administration, information systems, risk management, or a related field, or equivalent experience.
  • Relevant certification (e.g., CBCP, ABCP, or similar business continuity/resilience credential) preferred.

Knowledge

  • Practical knowledge of business continuity and disaster recovery methodology, including BIA, RTO/RPO, plan development, and exercise design.
  • Familiarity with incident response frameworks, severity classification, escalation, and post-incident review.
  • Applied understanding of NCUA examination practices and regulatory expectations for operational resilience and continuity.
  • Awareness of IT / Information Security concepts relevant to disaster recovery and cyber-incident coordination.
  • Proficiency in MS Office and experience administering BCP / resilience software (e.g., Tandem).

Skills/Abilities

  • Strong organizational and project-coordination skills; able to manage multiple plans, exercises, and deadlines simultaneously.
  • Clear written and verbal communication; able to document plans and present readiness status to stakeholders and leadership.
  • Facilitation skills to run effective tabletop exercises and cross-functional planning sessions.
  • Analytical and critical-thinking ability to identify dependencies, single points of failure, and gaps, and recommend practical mitigations.
  • Sound judgment within established policy; escalates strategic or cross-departmental exceptions to the Manager, Enterprise Risk.
  • Collaborative team contributor across Fraud, Compliance, IT / Information Security, and business units.
  • Self-starter with a high sense of urgency and a positive, adaptable mindset.

Physical Requirements/Work Environment

  • Primarily office-based work with frequent use of computers, phones, and other standard office equipment.
  • Ability to sit, stand, and work at a desk for extended periods throughout the workday.
  • Occasional lifting or moving of light materials (up to 15–20 pounds), such as files or office supplies.
  • May require participation in meetings, training sessions, exercises, or site visits within the organization.
  • Work environment includes deadlines, audits, exercises, or regulatory review periods requiring focused attention and multitasking.
  • Ability to communicate clearly in person, by phone, and electronically with internal stakeholders and external partners.
Requirements

  

Responsibilities & Duties

  • What is the problem      that this position solves?
  • What are the top 3      priorities for this role on a day-to-day basis? 
  • What goals, metrics,      or key outcomes are associated with this position? 
  • What experience or      qualifications are considered must-have versus nice-to-have? 
    • Business Continutiy       and disaster recovery - must have
  • What level of      ownership is expected in this role (execution vs. building/improving      processes)? 
    • Actively building -       may be coming in mid stream. There       is always room for enhancement or improvement. They may b bringing something. Responsibility that the plan is       up-to-date and scalable. There BC       stays on par. It's unique to       their. Where their specific       meeting point is. They'll be       responsible for annual testing of business continuity, and disaster       recovery. Needs to be 2
    • Recovery - RPO       (recovery point objection - system) and RTO (Recovery Time objection -       lights on)
  • What systems or      tools will this individual use regularly?
    • Tandem, Microsof       Office Suite - get them trained up. Using alert media. Alerts       that happen. Might want to expand       on services.
  • Are there any      systems/tools where prior experience is strongly preferred or required? 
  • Who will this      individual interact with most frequently (members, cross-functional      partners, leadership, vendors, etc.)? 
    • Member Complaints -       As getting member complaints in, farming them out. To compliance, Tyler will have eyes on       it if need to get legal involved
      • Tracking to        resolution (not sure if that's happening)
      • Current state:        Can't pull a report to see if done.
    • Business Continuity       and disaster recovery - Department heads
  • What does success      look like in: 
    • The first 60 days? 
    • The first 90 days? 
    • 6 months to 1 year?       Having full ownership of BCP, DR and IR plans, annual disaster recovery       is scheduled, member complaints with compliance and having a process in       place for tracking
  • What will training      look like once they get started?
  • Are there any      incentives outside of CSP? NO
    • If yes, what are       the earnings potential as well as the average bonus?

Logistics & Hiring Process

  • What are the      schedule expectations for this role? 
  • Is this position      on-site, or will it qualify for the flex work policy?
    • What are the       expectations and guidelines for your department as they align with the       flex work policy?
  • What would you like      the interview process to look like? 
    • Recommended       interview structure following TA screening: 

       

Role Level


Recommended Interviews

 

  

TA + Mary (in person) + David Garcia (live/virtual) + Tyler (call)

Salary Description
$64,275.20 - $80,344.00 annually (DOE)