CFGI
Business Continuity and Disaster Recovery - Senior Manager
- Location
- US
- Arrangement
- Hybrid
- Employment type
- Full-time
- Level
- Senior
- Posted
- 28 September 2026 (3 days ago)
Checked 2 days agoApplications go to the employer, never to RoleSprint
About this role
Cybersecurity: Business Continuity & Disaster Recovery (BCDR) - Senior Manager
CFGI is a leading advisory firm that partners with private equity sponsors, portfolio companies, and public companies to solve complex challenges across finance, technology, compliance, and business transformation. Our Cybersecurity practice supports clients through operational resilience, business continuity, disaster recovery, cyber resilience, and technology risk management programs.
Role Overview CFGI is seeking a Business Continuity & Disaster Recovery (BCDR) Subject Matter Expert to lead strategic advisory engagements that strengthen clients’ operational resilience, crisis management, business continuity, and technology recovery capabilities. This role combines hands-on delivery, executive communication, and practice leadership.
The successful candidate will work with CISOs, CIOs, COOs, Risk Leaders, Infrastructure Leaders, and private equity deal teams to assess resilience maturity, develop recovery strategies, lead testing programs, and implement pragmatic solutions that improve organizational preparedness and recoverability.
Key Responsibilities
Client Advisory & Resilience Delivery Lead Business Continuity, Disaster Recovery, Operational Resilience, and Crisis Management engagements from scoping through executive reporting. Conduct Business Impact Analyses (BIA), dependency mapping, critical process assessments, and recovery objective (RTO/RPO) reviews. Design and implement BCM governance programs, policies, standards, recovery plans, crisis management frameworks, and multi-year resilience roadmaps. Assess third-party and vendor resilience capabilities and integrate continuity requirements into risk management programs.
Disaster Recovery & Technical Resilience Assess recovery capabilities across cloud, infrastructure, networks, applications, data platforms, and cybersecurity environments. Evaluate backup, replication, high availability, failover, and recovery architectures against business requirements. Review technical recovery documentation, runbooks, architecture diagrams, testing results, and recovery evidence. Assess cyber recovery capabilities, including ransomware recovery strategies, immutable backups, recovery vaults, and segregated recovery environments. Support M&A, carve-outs, integrations, and portfolio company resilience transformation initiatives.
Testing, Exercises & Crisis Management Design and facilitate tabletop exercises, crisis simulations, and disaster recovery tests involving executive and technical stakeholders. Develop exercise scenarios, after-action reports, lessons learned analyses, and prioritized remediation plans. Define and report resilience KPIs, recovery performance, testing effectiveness, and material risks.
Practice Development & Leadership Support business development through proposal writing, SOW development, client presentations, solution design, and effort estimation. Mentor and develop team members while providing engagement leadership, quality oversight, and delivery rigor. Contribute to resilience methodologies, accelerators, templates, and thought leadership.
What You Must Have 8+ years of relevant experience in Business Continuity, Disaster Recovery, Operational Resilience, Technology Risk, Cyber Resilience, or consulting. Demonstrated experience designing and implementing enterprise Business Continuity Management (BCM) and disaster recovery programs. Deep experience with Business Impact Analysis (BIA), recovery planning, crisis management, dependency mapping, resilience governance, and validating disaster recovery capabilities through testing and evidence review.
What Sets You Apart Working knowledge of cloud platforms, enterprise infrastructure, networks, applications, backup technologies, and cybersecurity operations. Familiarity with ISO 22301, NIST SP 800-34, FFIEC, and other relevant continuity and resilience frameworks. Experience leading cyber recovery, ransomware preparedness, regulatory readiness, or operational resilience initiatives. Experience supporting private equity portfolio companies, highly regulated industries, or complex global organizations. Exceptional written and verbal communication skills, including experience producing and presenting executive-level deliverables. Proven ability to lead teams, manage multiple workstreams, and deliver effectively in a client-facing consulting environment.
Nice to Have Certifications such as CBCP, MBCI, CDRE, CISSP, CISM, CRISC, PMP, or related credentials. Experience with Azure Site Recovery, AWS Elastic Disaster Recovery, Rubrik, Cohesity, Veeam, Commvault, Zerto, or comparable technologies.
Why CFGI High-impact work with sophisticated clients and private equity portfolio companies. Opportunity to help shape and scale a growing Operational Resilience and Cybersecurity practice. Exposure to executive leadership teams, boards of directors, and private equity sponsors. Collaborative culture with autonomy, flexibility, and strong leadership support. Competitive compensation, benefits, and career growth opportunities.
Work location
- US
Ready to make a decision?
This role is either worth your time or it isn’t.
Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.
Nothing is submitted automatically. You choose what happens next.
About this listing
Advertised by Cfgi and published on Lever, the applicant tracking system they use.
RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.
Published 28 September 2026, last checked 2 days ago. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.