Primary Responsibilities:
**•**Managing and maintaining the resilience policies and procedures, such as:
•
Operational Resilience policy
•
Operational Resilience self-assessment document
•
Digital Resilience strategy
•
ICT Risk Management Framework
•Enhancing the operational resilience programme in line with global regulations, which includes the collection of key risk indicators and reporting to the Board.
•Undertake the annual refresh of the important business services, resource mapping, and the impact tolerance statements.
•Conducting scenario testing for the operational resilience important business services.
•Investigating BCP and Technology related operational risk events, ensuring root cause analysis and control assessments, including ‘deep dive’ reviews on significant and complex events.
•Identifying vulnerabilities from the important business services mapping and scenario testing, and raise issues and associated actions, where required. This will involve notifying responsible owners and providing sufficient oversight to ensure the issue is managed to completion.
•Maintenance and development of the BCP and Resilience system, Fusion.
•Acting as subject matter expert for all resilience matters, including upcoming regulatory changes.
•Undertake the review of FCA resilience regulatory changes.
•Run global Resilience projects across all Neuberger entities.
•Provide resilience reporting to the EMEA Risk and Compliance Committee, and relevant Boards.
•Managing and maintaining the business continuity policy and procedures (including the Business Continuity plans), such as:
•
Business Continuity policy
•
Business Continuity Executive Group Response Plan
•Implementing a Business Impact Analysis (BIA) programme that meets all necessary regulatory requirements.
•Creation and maintenance of Business Continuity plans across locations and functions.
•Undertaking and developing the Business Continuity testing programme and, where appropriate, the Neuberger Group.
•Coordinate and run the global and regional Business Continuity tabletop exercises, in conjunction with Technology teams.
•Management of Business Continuity incidents, ensuring the appropriate response and communications are taken.
•Ensuring all key stakeholders, including Business Continuity Coordinators, are trained on their business continuity responsibilities.
•Coordinating and overseeing the third-party due diligence processes undertaken by the Senior Relationship Managers, including the creation of bespoke questionnaires.
•Oversight of the ICT Risk Framework, partnering with the first line IT Risk function, including annual refresh of the Critical and Important Functions (DORA).
•Chair of the ICT Risk Governance Committee, providing input and challenge.
•Input into the DORA incident reporting and Register of Information process.
•Partnering with the Information Security team to ensure effective cyber-security resilience.