Director, Cybersecurity Recovery & Resiliency
The Depository Trust & Clearing Corporation (DTCC)
Salary not disclosed
Need a reasonable accommodation to apply or interview? Contact us.
JobMinglr uses automated technology to recommend jobs based on profile information and job preferences. Match Score does not determine eligibility for a position, prevent a user from viewing or applying to a job, or make hiring decisions on behalf of an employer.
Description
Are you ready to make an impact at DTCC?
Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC, we are at the forefront of innovation in the financial markets. We are committed to helping our employees grow and succeed. We believe that you have the skills and drive to make a real impact. We foster a thriving internal community and are committed to creating a workplace that looks like the world that we serve.
The Information Technology group delivers secure, reliable technology solutions that enable DTCC to be the trusted infrastructure of the global capital markets. The team delivers high-quality information through activities that include development of essential, building infrastructure capabilities to meet client needs and implementing data standards and governance.
Pay and Benefits:
- Competitive compensation, including base pay and annual incentive
- Comprehensive health and life insurance and well-being benefits, based on location
- Pension / Retirement benefits
- Paid Time Off and Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
- DTCC offers a flexible/hybrid model of 3 days onsite and 2 days remote (onsite Tuesdays, Wednesdays and a third day unique to each team or employee).
The Impact you will have in this role:
Being a member of IT Cybersecurity & Platform Strategy team, the Director, Cyber Resiliency will build, lead, and mature our capability focusing on recovery from destructive events that may impact core business operations. This is a hands-on leadership role accountable for two core capability areas:
- Immutable backup recovery: immutable, air-gapped backup storage, malware and ransomware analysis on backup data, and digital forensics support to enable clean, trusted recovery decisions.
- Full-stack and bare-metal recovery: the capability to rebuild and restore infrastructure and applications from the ground up following a significant cyber-induced disruption.
The environment spans on-premise data center infrastructure (mainframe, distributed databases, application servers on Linux/VMware, and enterprise storage) as well as public cloud. The successful candidate will bridge traditional infrastructure resiliency with modern cloud recovery patterns and will be a key partner to Security, Infrastructure, Business Continuity, Risk, and Technology leadership.
Your Primary Responsibilities:
Cyber Resiliency Strategy & Program Leadership
- Own the enterprise cyber resiliency strategy and roadmap for recovering from extreme cyber events (ransomware, destructive malware, data corruption), tracking key recovery metrics and reporting to senior leadership and risk committees.
Isolated & Immutable Backup Recovery
- Lead immutable/air-gapped backup infrastructure, including malware and integrity scanning of backup data and forensic support for incident investigations, in partnership with the IR/Forensics team.
Full-Stack & Bare-Metal Recovery
- Own recovery readiness (runbooks, automation, and regular testing) for critical infrastructure and applications across mainframe, Linux/VMware, storage, and cloud, in partnership with Infrastructure and Cloud teams.
Cross-Functional Partnership & Governance
- Serve as the key liaison to Business Continuity, Risk, and Audit on resiliency posture and regulatory readiness, and represent cyber resiliency in incident response and crisis management planning.
Team Leadership
- Hire, develop, and lead the resiliency engineering team, and manage vendor/managed-service relationships supporting recovery tooling.
**NOTE: The Primary Responsibilities of this role are not limited to the details above. **
Qualifications:
- Min 10+ years of relevant experience
- Bachelor’s Degree and/or equivalent experience
Talents Needed for Success:
- 10+ years of progressive experience in infrastructure, disaster recovery, business continuity, or security roles, with at least 4-5 years in a leadership capacity.
- Demonstrated experience designing or operating cyber recovery capabilities (isolated recovery environments, immutable backups, bare-metal recovery) — not just traditional DR/BCP.
- Strong working knowledge of enterprise infrastructure, ideally spanning mainframe systems, distributed databases, Linux/VMware server environments, and enterprise storage platforms.
- Hands-on familiarity with public cloud infrastructure (AWS preferred) and recovery patterns (backup, snapshotting, cross-region/account recovery, access considerations for isolated recovery).
- Experience with ransomware/malware forensics concepts and backup integrity validation, or close partnership with forensics/IR teams.
- Experience leading enterprise-scale recovery exercises (tabletop through full-scale) and reporting outcomes to senior stakeholders.
- Strong understanding of regulatory/operational resilience expectations relevant to the industry.
- Excellent stakeholder management and executive communication skills; ability to translate technical recovery posture into business risk terms.
- Isolated backup and full-stack recovery capabilities are documented, tested, and validated against defined RTO/RPO targets for the organization's most critical services.
- A recurring cyber recovery exercise program is in place with executive-level reporting.
- Clear, auditable evidence of immutable backup coverage and recovery runbooks across on-premise and cloud environments.
- Strong working relationships established with Security, Infrastructure, Business Continuity, and Risk stakeholders.
The salary range is indicative for roles at the same level within DTCC across all US locations. Actual salary is determined based on the role, location, individual experience, skills, and other considerations. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, sex, gender, gender expression, sexual orientation, age, marital status, veteran status, or disability status. We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
Benefits
- paid time off
- life insurance
- professional development
About this role
DTCC's IT Cybersecurity & Platform Strategy team is building out a specialized capability to recover from destructive cyber events, and this director role leads that charge. You would own the enterprise cyber resiliency strategy and program—from immutable, air-gapped backup infrastructure and malware forensics through full-stack and bare-metal recovery across mainframe, distributed systems, Linux/VMware, storage, and public cloud environments. This is hands-on leadership: you'll design recovery readiness, run recovery exercises, report to senior leadership and risk committees, and partner closely with Security, Infrastructure, Business Continuity, and Risk teams to ensure DTCC can rebuild from a significant ransomware or destructive malware event.
The role demands 10+ years in infrastructure, disaster recovery, business continuity, or security—with at least 4–5 years leading teams. You'll need real experience designing or operating cyber recovery capabilities (not traditional DR alone), working knowledge of enterprise infrastructure spanning mainframe through cloud, and hands-on familiarity with AWS and recovery patterns. Ransomware and malware forensics concepts, backup integrity validation, and experience running enterprise-scale recovery exercises are essential. Strong stakeholder management and the ability to translate technical recovery posture into business risk language matter equally.
You'll hire and develop the resiliency engineering team, manage vendor relationships, and establish documented, tested recovery capabilities with defined RTO/RPO targets for critical services. The role is hybrid—three days onsite in Jersey City, two remote—with competitive base pay, annual incentive, comprehensive health and life insurance, pension, and flexible paid time off.
This role's local market on JobMinglr
Pay for this role
The employer didn't post a pay range for this role. That usually means pay is set in negotiation, which favors whoever arrives with numbers. Check ranges on comparable Director, Cybersecurity Recovery & Resiliency postings in Jersey City, and analyze any offer before you accept it.
Before you apply, worth reading
How JobMinglr reads this job
Every listing here is scored against your profile before you apply: skills overlap, experience level, location and work arrangement, each weighted and explained. You see the score and the reasons, not just a list. How the matching works.