Manager, Cyber Risk Operations

Wilton Re Ltd.

Norwalk, Northern (CT, KY)

Hybrid

USD 125,000 - 165,000

Full time

10 days ago
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Health insurance
Vision insurance
Dental insurance
Life insurance
401(k) with employer contribution
Profit sharing
Hybrid work environment
Employee engagement events

Job summary

Wilton Re Ltd. in Norwalk, CT, is seeking a Manager, Cyber Risk Operations to strengthen cybersecurity risk management, incident response readiness, and third-party risk oversight. This role reports to the CSO and leads incident command and governance through events.

Responsibilities include maintaining risk visibility, coordinating containment, and delivering executive updates while partnering with Legal, Compliance, Risk, IT, and vendors to ensure timely remediation and reporting.

Qualifications

  • Minimum 6 years of progressive cybersecurity-related experience.
  • Experience in insurance or financial services environments preferred.
  • Ability to coordinate cross-functional incident response and risk assessments.

Responsibilities

  • Serve as the designated lead for initial cybersecurity incident response.
  • Establish incident command structures and ensure clear accountability.
  • Coordinate containment discussions with stakeholders and executives.
  • Provide timely situation reports and executive updates.
  • Maintain the Cyber Risk Register and track remediation activities.
  • Collaborate with Security, IT, Legal, Compliance, Risk, and Audit.

Skills

Cyber risk mgmt
Incident response
Risk assessment
Regulatory knowledge
GRC tools
Vendor risk

Education

Bachelor’s degree
Advanced degree preferred

Job description

Manager, Cyber Risk Operations

We are searching for an experienced Manager, Cyber Risk Operations at our Connecticut office.

Full Time Norwalk, CT

About the Company:

Wilton Re is an industry leader in the life(re)insurance space, specializing in the acquisition of in force life insuranceand annuities. We are experienced industry specialists focused on the risk,capital and operational needs of our clients’ businesses. We provide our clients with theservices they need for in force transactions, capital optimization andoperational efficiencies. Wilton Re has the resources and expertise to pursueand successfully manage the largest life and annuity transactions in the market.

Position Summary:

The Manager, Cyber Risk Operations reports to the Chief InformationSecurity Officer and plays a central role in strengthening the organization’scybersecurity risk management, cyber incident response readiness, andthird-party cyber risk oversight. This role is responsible for maintainingvisibility into cyber risks, findings, exceptions, vulnerabilities, incidents,and remediation activities while helping leadership make informed, risk-baseddecisions. The role leads the organization through the initial stages ofcybersecurity events by establishing incident command and control, drivingevent categorization and severity determination, coordinating containmentdecisions, and managing executive, legal, governance, and operationalengagement through incident declaration and stabilization. The Cyber Risk Manager partners closely with Security, IT, Legal,Compliance, Risk Management, Internal Audit, business leaders, and third-partyservice providers to ensure cyber risks are identified, assessed, documented,owned, remediated, and reported through appropriate governance cha

Role Responsibilities:
Cybersecurity Incident Leadership and Coordination
  • Serve as the designated lead for the organization's initial response to cybersecurity incidents, ensuring timely, coordinated, and effective management of security events from identification through stabilization.
  • Establish and maintain initial incident command and control structures during cybersecurity events, ensuring clear accountability, decision‑making authority, and communication channels.
  • Lead the incident triage process, including validating incident details, coordinating investigations, and driving accurate classification, categorization, and severity determination.
  • Facilitate rapid assessment of business impact, regulatory implications, operational disruption, and cyber risk exposure to support executive decision‑making.
  • Coordinate containment strategy discussions with technical response teams, business stakeholders, legal counsel, and executive leadership to minimize organizational risk and disruption.
  • Manage executive, legal, compliance, privacy, and governance engagement throughout incident declaration, containment, and stabilization activities.
  • Provide timely and accurate situation reports, executive briefings, and incident status updates to senior leadership.
  • Maintain overall accountability for incident coordination and governance activities until the event has been stabilized and formally transitioned to recovery and remediation teams.
Cyber Risk Management
  • Own and maintain the Cyber Risk Register, ensuring cybersecurity risks, control deficiencies, audit findings, vulnerabilities, compensating controls, and approved risk exceptions are accurately documented and regularly reviewed.
  • Facilitate the identification, analysis, assessment, scoring, and prioritization of cybersecurity risks across the organization.
  • Partner with business, technology, and security stakeholders to develop and implement risk treatment plans, including mitigation, transfer, acceptance, and avoidance strategies.
  • Track risk mitigation activities, remediation efforts, and exception management processes to ensure timely execution and accountability.
  • Monitor cybersecurity trends, emerging threats, incidents, vulnerability data, control weaknesses, audit observations, and industry developments to identify evolving risk exposure.
  • Validate that cybersecurity findings, risk exceptions, and control deficiencies have clearly assigned owners, documented remediation plans, defined milestones, and target completion dates.
  • Conduct periodic reviews of risks, findings, and approved exceptions to validate continued business justification, effectiveness of compensating controls, and current risk ratings.
  • Challenge risk assumptions and facilitate informed risk acceptance decisions by ensuring leadership has sufficient visibility into residual risk and business impact.
Reporting,Metrics, and Governance
  • Develop and maintain cybersecurity risk reporting for executive management, risk committees, audit committees, and Board-level stakeholders.
  • Design and track cybersecurity key risk indicators (KRIs), key performance indicators (KPIs), and operational metrics to measure program effectiveness and risk trends.
  • Prepare executive dashboards and governance reports that communicate cybersecurity posture, emerging risks, remediation progress, and risk treatment status.
  • Provide data‑driven recommendations to leadership regarding risk priorities, investment decisions, and strategic cybersecurity initiatives.
Regulatory,Audit, and Compliance Support
  • Coordinate the collection, review, and presentation of cybersecurity risk documentation, evidence, and supporting materials during audit and regulatory activities.
  • Monitor regulatory and industry requirements to ensure risk management practices remain aligned with applicable standards, frameworks, and obligations.
  • Assist in the development and maintenance of policies, standards, procedures, and risk management documentation supporting the cybersecurity program.
Third Party Cyber Risk Management
  • Ensure third‑party cybersecurity risks, vendor findings, control deficiencies, and risk exceptions are appropriately documented and tracked within enterprise risk management processes and the IT Risk Register.
  • Partner with procurement, legal, technology, and business stakeholders to evaluate cybersecurity risks associated with vendors, service providers, and strategic partners.
  • Support vendor onboarding and due diligence activities, including cybersecurity assessments, security reviews, evidence evaluations, and risk recommendations.
  • Participate in contract reviews to ensure cybersecurity, privacy, incident notification, audit, business continuity, and security control requirements are incorporated as appropriate.
Business Impact Analysis and Resilience
  • Lead the development of a Business Impact Analysis (BIA) framework for critical business processes and services.
  • Facilitate identification of critical business functions, dependencies, recovery objectives, and operational impacts associated with cyber and technology disruptions.
  • Partner with business leaders to assess and document third‑party dependencies that could materially impact business operations.
  • Ensure BIA outputs are incorporated into cybersecurity risk assessments, third‑party risk evaluations, incident response planning, and business continuity strategies.
  • Support cross‑functional resilience initiatives by helping business units understand and manage risks associated with critical systems, processes, and external service providers.
Basic Qualifications:
  • Minimum 6 years of progressive experience in cybersecurity, cyber risk management, incident response, technology risk, IT risk, audit, or related disciplines.
  • Experience supporting cybersecurity risk management or incident response in insurance, reinsurance, financial services, or another highly regulated environment preferred.
  • Demonstrated ability to coordinate cross‑functional incident response activities, facilitate risk assessments, maintain risk registers, and communicate risk decisions to leadership.
  • Strong understanding of cybersecurity risk management, incident response practices, vulnerability management, third‑party risk, NIST Cybersecurity Framework, NYDFS cybersecurity requirements, and audit or regulatory expectations.
  • Proven ability to work effectively across security, IT, legal, compliance, risk, audit, business, and vendor teams during both steady‑state risk management and active incident response.
  • Strong knowledge of cyber risk assessment, risk scoring, risk treatment, incident response coordination, control deficiencies, exception management, and remediation tracking.
  • Excellent communication, stakeholder management, executive briefing, and governance reporting skills.
  • Experience with GRC platforms, incident response tools, vulnerability management tools, dashboards, and workflow management solutions preferred.
  • Ability to translate technical findings, incident details, and cyber risk information into practical business decisions and clear leadership reporting.
Required Education /Certifications:
  • Bachelor’s degree required; advanceddegree preferred
  • Professional certifications such asCISSP, CISM, CRISC, CISA, GIAC, or similar cybersecurity, risk, or incidentresponse certifications are desirable
Pay/Location
  • Norwalk, CT
  • Hybrid Structure
  • Minimal to no travel required
  • Basesalary/hourly rate range for this position in Connecticut is between $125,000and $ 165,000 Please note that specific compensation decisions are based upon avariety of job‑related factors as permitted by law, including geographiclocation, credentials, skills, education, training, and experience.
  • Base salary is just one component of Wilton Re’s totalcompensation package for employees. Additional compensation includes annualperformance‑based bonus, 401K with employer contribution, and profit‑sharingprogram. Employee may also be eligible for long‑term incentives. All incentivesand benefits are subject to the applicable plan terms.
What We Offer:
  • Competitive vacation and sick time, including company-paid holidays, floating holidays and early closing days
  • 401(k) plan with employer contribution - US Employees Only
  • Profit Sharing Program
  • Competitive parental leave
  • Health, vision, dental, and life insurance, including access to health and wellness programs
  • Actuarial Development Program (ADP) for Actuarial employees taking exams
  • Employee Assistance Program (EAP)
  • Current hybrid working environment
  • Employee Engagement Events and various committees on site to join

WiltonRe strives to attract, develop, and retain a diverse workforce. We arecommitted to providing an inclusive and accessible work environment where allassociates feel valued, respected, and supported. Our commitment to inclusivityis reflected in the safeguards, policies, and commitments we have in place toremove barriers and provide equal opportunities to prospective and currentassociates, without discrimination. A Human Resources representative isavailable to consult with applicants who require accommodation in theapplication or recruitment process. Any information shared by the applicantabout an accommodation will be treated as confidential.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Manager, Cyber Risk Operations
Manager, Cyber Risk Operations

Wilton Re • Norwalk (CT)

Hybrid
USD 125,000 - 165,000
Hybrid structure
Health insurance
401(k) matching
VP, IT Governance Risk and Compliance
VP, IT Governance Risk and Compliance

Wilton Re Ltd. • Norwalk (CT), Northern (KY)

Hybrid
USD 170,000 - 210,000
Hybrid work environment
Profit sharing program
401(k) plan with employer contribution
+1
VP, IT Governance Risk and Compliance
VP, IT Governance Risk and Compliance

Wilton Re • Norwalk (CT)

Hybrid
USD 170,000 - 210,000
Vacation & holidays
401(k) plan
Profit sharing
+5
Manager, Investments
Manager, Investments

Wilton Re Ltd. • Norwalk (CT)

Hybrid
USD 130,000 - 160,000
Competitive vacation and sick time
401(k) with employer contribution
Profit Sharing Program
+1
Regulatory and Compliance Specialist
Regulatory and Compliance Specialist

Wilton Re • Norwalk (CT)

Hybrid
USD 70,000 - 90,000
Health, vision, dental, and life保险
401(k) plan with employer contribution
Profit Sharing Program
+2
Manager, Investment Operations
Manager, Investment Operations

Wilton Re Ltd. • Norwalk (CT)

Hybrid
USD 130,000 - 150,000
Competitive vacation and sick time
401(k) plan with employer contribution
Profit Sharing Program
+2
AVP, IT Operations
AVP, IT Operations

Wilton Re Ltd. • Norwalk (CT), Northern (KY)

Hybrid
USD 140,000 - 175,000
Health insurance
Dental insurance
Vision insurance
+2
IT Business Analyst
IT Business Analyst

Wilton Re Ltd. • Norwalk (CT)

Hybrid
USD 80,000 - 95,000
401(k) plan with employer contribution
Profit Sharing Program
Health, vision, dental, and life insurance
+1
AVP or VP, Finance & Investments Counsel
AVP or VP, Finance & Investments Counsel

Wilton Re • Norwalk (CT)

Hybrid
USD 150,000 - 215,000
Health, vision, dental, and life ins.
401(k) plan with employer contribution
Profit sharing program
+1
IT Business Analyst
IT Business Analyst

Wilton Re • Norwalk (CT)

Hybrid
USD 80,000 - 95,000
401(k) plan with employer contribution
Profit Sharing Program
Health, vision, dental, and life insurance
+1