Job Description
Job Description
American Heritage Credit Union, a $5+ billion credit union, has an immediate opening for a Incident Response and Business Continuity Lead.
This position is responsible for developing, implementing, and maintaining comprehensive business continuity plans and incident response program to ensure the resilience of American Heritage Credit Union's operations while safeguarding the organization's assets and reputation. Act as point of contact and central coordinator during security incidents, ensuring that the organization can effectively respond, mitigate damage, and recover from these events. Execute the incident response program as defined with internal staff and external vendors in support of the approved organizational mission while maintaining consistency with industry best practices and regulatory standards.
RESPONSIBILITIES INCLUDE :
- Develop and maintain a comprehensive business continuity program, including policies, procedures, and plans aligned with the industry's best practices and regulatory requirements.
- Ensure that critical business functions are maintained or quickly restored during and after incidents.
- Conduct thorough risk assessments to identify potential threats and vulnerabilities to the credit union's operations, systems, and infrastructure.
- Collaborate with cross-functional teams to develop and test business continuity and disaster recovery plans for critical business functions and systems.
- Collaborate with IT staff to develop and implement best practices to protect and restore data and systems in the event of natural disasters, viruses, and hackers.
- Plan, conduct, and debrief on scenario-based tests and exercises consistent with the Business Impact Analysis (BIA) and capture outcomes and resulting action items necessary to close any identified gaps and / or process improvements to strengthen the credit union's overall readiness and responsiveness.
- Coordinate and facilitate regular training and awareness programs to enhance the credit union's preparedness and response capabilities.
- Work closely with Vendor Management to identify major functions including potential third-party service providers to ensure continuity readiness. Review vendor contracts and service level agreements (SLA) to ensure conformance with BIA expectations and communicate identified gaps or risks to Vendor Management.
- Work with the organization's Change Management process to immediately identify any changes that may have an impact on the BIA and organizational readiness or response.
- Establish and maintain effective communication channels and protocols to ensure timely and accurate dissemination of information during a crisis or disruption.
- Lead response and recovery efforts and the incident response team during incidents, making decisions under pressure and managing resources effectively while ensuring appropriate actions are taken to minimize the impact on the credit union's operations and reputation.
- Lead investigations into security incidents, fraud cases, and cyber threats affecting the credit union.
- Develop and implement strategies for threat identification, mitigation, and resolution.
- Coordinate with internal teams and external agencies including law enforcement, regulatory bodies, and legal counsel as necessary.
- Oversee the collection and preservation of digital and physical evidence in compliance with legal standards.
- Review incident responses to identify areas for improvement and refine incident response plans.
- Support all activities related to incidents reported in the Incident Log including real-time incident response, after action report meetings, and tracking / closure of approved action items to address any gaps or process improvements.
- Assess and enhance the credit union's security measures including physical security controls, cybersecurity protocols, and fraud prevention programs.
QUALIFICATIONS :
Three to five years of IT / security audit and vendor due diligence experience in the financial services industry.Equivalent to a college degree (BS or BA) in business administration or risk-related field.Certified Business Continuity Professional (CBCP) certification required.Certified Information Security Manager (CISM) or Certified Information Systems Security Professional (CISSP) a plus.Working knowledge of or the ability to learn and understand the credit union movement, credit union products and services, and laws and regulations relevant to the credit union industry.Strong working knowledge of financial fraud schemes, cybersecurity threats and concepts, security technologies (e.g., firewalls, intrusion detection systems), risk mitigation strategies, and incident response methodologies.Strong working knowledge of business continuity management principles, methodologies, and best practices.Exceptional project management skills.Must possess and exhibit excellent analytical and organizational skills needed for problem solving, critical thinking, decision making, crisis management, and handling multiple priorities in a deadline-oriented environment.Highly developed negotiation, consensus building and influencing skills, facilitation, and the adaptability to respond to change quickly.Our commitment to your success is enhanced by our competitive salary commensurate with experience and an extensive benefits package including paid time off, health benefits, 401(k) with a generous company match, and future growth opportunities within the company. We work to maintain the best possible professional and environmentally friendly atmosphere for our employees.
EOE M / F / D / V