Information Security Engineer, Principal
- Lead the development, maintenance, and continuous improvement of the enterprise BCDR program within the Information Security function.
- Establish governance processes, reporting structures, and key performance indicators aligned to organizational risk appetite and compliance requirements.
- Ensure BCDR practices align with NIST CSF, NIST 800-34, ISO 22301, CMMC, and internal ISMS controls.
- Facilitate cross-functional collaboration among IT, Security, Operations, Manufacturing, HR, Facilities, Legal, and Business Owners.
- Plan and conduct structured interviews, workshops, and data-gathering sessions with business leaders and process owners.
- Document critical business processes, dependencies, system interrelationships, and recovery time objectives (RTOs/RPOs).
- Analyze operational, financial, regulatory, and reputational impacts to determine organizational priorities for continuity.
- Maintain an enterprise BIA repository and ensure periodic review and updates.
- Identify vulnerabilities, single points of failure, and resilience gaps revealed through BIAs and risk assessments.
- Recommend and document mitigation strategies, compensating controls, and resilience enhancements.
- Work with IT Architecture, Infrastructure, and Security teams to ensure alignment with redundancy, high-availability, and site-failover strategies.
- Develop, document, and maintain Disaster Recovery plans, including system-specific runbooks, recovery steps, communication flows, and escalation procedures.
- Coordinate with IT Operations, Cloud/Infrastructure, Application Owners, and Security to ensure DR procedures are complete, testable, and auditable.
- Ensure DR documentation aligns with RTO/RPO requirements, and compliance frameworks.
- Lead tabletop exercises, functional tests, and full-scale DR simulations.
- Document test results, track remediation activities, and report on program maturity to leadership and audit stakeholders.
- Validate that DR plans remain current with system changes, architectural decisions, and change management activities.
- Coordinate BCDR procedures with the Cyber Incident Response Plan and Crisis Management Team.
- Ensure seamless integration between recovery plans and security response workflows.
- Participate in major incident response activities when continuity or recovery actions are required.
- Develop and maintain BCDR documentation repositories, templates, and standards.
- Provide status updates, dashboards, and executive-level reports detailing program readiness and risk exposure.
- Prepare program evidence for internal audits, customer assessments, and compliance reviews (CMMC, ISO, DFARS, etc.).
- Bachelor’s degree in information security, Information Technology, Business Continuity, or related field (or equivalent experience).
- 5–7+ years of experience in Business Continuity, Disaster Recovery, Information Security, or related resilience disciplines.
- Demonstrated experience conducting BIAs, developing DR plans, and running continuity exercises.
- Strong understanding of frameworks such as NIST CSF, NIST SP 800-34, ISO 22301, and CMMC.
- Excellent interviewing, facilitation, documentation, and analytical skills.
- Ability to communicate effectively with technical and non-technical stakeholders, including senior leadership.
- Professional certifications (e.g., CBCP, MBCI, ISO 22301 Lead Implementer/Auditor, CISSP, CISM).
- Experience developing or maturing BCDR governance programs in manufacturing, engineering, defense contracting, or other critical industries.
- Familiarity with IT architecture, high-availability infrastructure, cloud resiliency, and cybersecurity incident response.
- Strong analytical and critical-thinking skills
- Detail-oriented documentation and organizational skills
- Excellent communication, interviewing, and facilitation abilities
- Ability to lead cross-functional initiatives and influence without authority
- Comfort operating in highly regulated security/compliance environments
- Problem-solving and process improvement mindset
- Health, dental, and vision insurance.
- Employer-sponsored 401(k) plan.
- Paid time off.
- Professional development opportunities.
Recommended Jobs
Family Medicine/Internal Medicine Physician
Tufts Medical Center Community Care is seeking a Family Medicine or Internal Medicine Physician to join our team of collaborative providers in Reading, MA . Why join our team: Our well-est…
Senior Quality Engineer
Emerging from MIT, Poly6 is an exciting, innovative manufacturing company that specializes in the development and production of advanced additive manufacturing and ceramic components for aerospace tur…
Senior Product Manager
Sr. Product Manager Hybrid in Towson, MD or East Longmeadow, MA Come build your career. It takes great people to achieve greatness. People with a sense of purpose and integrity. Peopl…
Physical Therapist - PT - Per Diem (Marlborough)
Description: Physical Therapist (PT) – Marlborough | $55–$65 per visit | Make Your Own Hours |**Must have 1 year clinical experience** USA Today Top Workplaces Winner 2024 & 2025 — s till no bribe…
Dietary Cook
Are you passionate about creating delicious and nutritious meals? Do you want to make a difference in the lives of others while working in a supportive and welcoming environment? Join us as a Dietary…
Consultant, Employee Benefits
Are you an Employee Benefits professional that likes to manage your own book and your own process but still be part of a great team? Are you passionate about helping small businesses thrive while en…
Senior Data Engineer, Platform Infrastructure
About Gather Health Gather Health is a Series B healthcare company reimagining primary care for older adults. Backed by Khosla, Maverick, and HC9, we’ve raised over $50M to build a new model of …
CREW MEMBER
We are looking for a Crew Member to help us deliver our mission statement – “turning moments into memories for our guests, while providing opportunities to our employees, and giving back to the com…
Pharma Partnerships Manager
Empatica Empatica is a full-stack, digital healthcare company, forever changing the way health is monitored and new treatments are developed through our AI platform , digital biomarkers , and …
Leasing Officer - NE (HENFP Equipment Finance)
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our …