Tech Stack
Tag name is followed by "@" symbol and proficiency level value.
About proficiency levels:
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
AWS @ 6
Azure @ 6
Communication @ 7
Compliance
Due Diligence @ 4
GCP @ 6
SRE @ 4
Security
- 1-2 — basic awareness. Minimal hands-on experience, and a rudimentary understanding of the technology's purpose;
- 3-6 — daily use. Comfortable and regular usage, capable of handling common tasks and challenges related to the technology;
- 7-9 — you are an expert, you can teach others, you know all the pitfalls and tricks;
- 10 — exceptional knowledge, comprehensive understanding, and adeptness in all aspects of the technology, including advanced problem-solving. Think twice before claiming or demanding such level.
Details
Bloomberg is seeking a seasoned professional to join its second line of defense (2LoD) Risk function, providing independent oversight, challenge, and governance of the firm's Resilience program, encompassing Business Continuity (BC), Disaster Recovery (DR), and Operational Resilience.
The role requires a technically grounded practitioner who can engage credibly with engineers, infrastructure teams, and product teams; translate technical recovery capabilities into meaningful risk judgments; influence senior stakeholders; and assess recovery capabilities beyond documentation. The role works closely with the Company's central Business Continuity Management (BCM) lead, Engineering leaders overseeing the DR program, and the Operational Resilience leadership team.
The successful candidate will apply a risk-based mindset, prioritizing scrutiny and escalation in proportion to actual risk exposure. They should communicate findings practically, distinguish material issues from noise, and help embed sustainable improvements.
Responsibilities
- Provide independent second-line oversight and challenge of Bloomberg's Business Continuity, Disaster Recovery, and broader resilience programs and practices operated by the first line of defense.
- Assess and challenge frameworks and strategies for Business Continuity, Disaster Recovery, and Operational Resilience.
- Assess the technical adequacy of the firm's recovery posture, including disaster recovery architecture, failover mechanisms, data replication strategies, backup integrity, and system recovery tiering.
- Evaluate alignment between business continuity plans, disaster recovery capabilities, and impact tolerance thresholds to ensure end-to-end recoverability of critical services under realistic failure scenarios.
- Identify gaps, weaknesses, and emerging risks across the resilience framework, and escalate findings with clear, evidence-based remediation recommendations.
- Own and maintain the 2LoD resilience policy and standards suite, ensuring alignment with industry best practices and Bloomberg's technology-intensive operating environment.
- Drive periodic framework reviews and updates in response to technology changes, infrastructure evolution, and lessons learned from incidents and exercises.
- Oversee 2LoD reviews of resilience testing programs, including business continuity exercises, disaster recovery failover tests, tabletop simulations, and scenario-based resilience stress tests.
- Ensure testing scenarios are technically realistic and cover cyber incidents, including ransomware and destructive attacks; infrastructure failures; data corruption events; third-party outages; and geographic disruptions.
- Verify that lessons learned from tests and live incidents result in tangible improvements to resilience capabilities.
- Evaluate third-party and vendor disaster recovery capabilities supporting critical Bloomberg services, with particular attention to concentration risk and recovery interdependencies.
- Report on the firm's recovery posture against defined impact tolerances and flag capability gaps that could prevent the firm from remaining within tolerance during a severe but plausible disruption.
- Contribute to operational risk appetite frameworks relating to resilience and recoverability risks.
- Build trusted relationships with first-line resilience teams, Technology Infrastructure, Site Reliability Engineering, Cyber/Information Security, Third Party Risk, and business leadership.
- Serve as a technically credible challenge partner to Engineering and Product teams on resilience architecture decisions, engaging substantively on design trade-offs rather than only governance processes.
- Promote a culture in which resilience is understood as an interconnected, technically grounded discipline rather than a siloed compliance activity.
Requirements
- 10+ years of experience spanning Business Continuity, Disaster Recovery, and enterprise resilience, with deep hands-on technical grounding in at least one associated discipline.
- Strong command of disaster recovery concepts, including RTO/RPO design and validation, recovery tiering, active/passive and active/active failover architectures, data replication technologies, backup and restoration methodologies, and dependency mapping.
- Experience assessing or governing disaster recovery capabilities in complex, technology-intensive environments, including on-premise data centers, hybrid infrastructure, and cloud-native or multi-cloud architectures.
- Proven second-line-of-defense experience providing credible independent oversight and challenge, including the technical depth to assess actual capabilities beyond policy review.
- Experience engaging constructively with engineering, SRE, and infrastructure teams.
- Strong analytical and communication skills, with the ability to translate highly technical findings into risk-based narratives for senior and Board-level audiences.
Preferred Qualifications
- Professional certifications such as CBCP, MBCI, CRISC, AWS, Azure, or GCP certifications, or equivalent technical credentials in infrastructure, cloud, or IT risk.
- Experience assessing cyber-informed disaster recovery strategies, including ransomware recovery planning, immutable backup architectures, and clean-room recovery environments.
- Exposure to financial market infrastructure, data platforms, or real-time systems with exceptionally tight recovery time requirements and critical data integrity needs.
- Experience evaluating third-party and vendor disaster recovery capabilities, including due diligence on critical technology suppliers.
Benefits
Benefits and total rewards may include merit increases, incentive compensation for exempt roles, paid holidays, paid time off, medical, dental, vision, short- and long-term disability benefits, 401(k) matching, life insurance, and wellness programs. Benefits are not provided directly to contingent workers, contractors, or interns.