Manager, Cyber Risk Operations
Listed on 2026-09-16
-
IT/Tech
Cybersecurity, Information Security & Data Protection
We are searching for an experienced Manager, Cyber Risk Operations at our Connecticut office.
Manager, Cyber Risk OperationsFull Time
Norwalk, CT
About The CompanyWilton Re is an industry leader in the life (re) insurance space, specializing in the acquisition of in force life insurance and annuities. We are experienced industry specialists focused on the risk, capital and operational needs of our clients’ businesses. We provide our clients with the services they need for in force transactions, capital optimization and operational efficiencies.
Wilton Re has the resources and expertise to pursue and successfully manage the largest life and annuity transactions in the market.
Position SummaryThe Manager, Cyber Risk Operations reports to the Chief Information Security Officer and plays a central role in strengthening the organization’s cybersecurity risk management, cyber incident response readiness, and third-party cyber risk oversight. This role is responsible for maintaining visibility into cyber risks, findings, exceptions, vulnerabilities, incidents, and remediation activities while helping leadership make informed, risk-based decisions. The role leads the organization through the initial stages of cybersecurity events by establishing incident command and control, driving event categorization and severity determination, coordinating containment decisions, and managing executive, legal, governance, and operational engagement through incident declaration and stabilization.
The Cyber Risk Manager partners closely with Security, IT, Legal, Compliance, Risk Management, Internal Audit, business leaders, and third-party service providers to ensure cyber risks are identified, assessed, documented, owned, remediated, and reported through appropriate governance cha
Serve as the designated lead for the organization’s initial response to cybersecurity incidents, ensuring timely, coordinated, and effective management of security events from identification through stabilization.
Establish and maintain initial incident command and control structures during cybersecurity events, ensuring clear accountability, decision-making authority, and communication channels.
Lead the incident triage process, including validating incident details, coordinating investigations, and driving accurate classification, categorization, and severity determination.
Facilitate rapid assessment of business impact, regulatory implications, operational disruption, and cyber risk exposure to support executive decision-making.
Coordinate containment strategy discussions with technical response teams, business stakeholders, legal counsel, and executive leadership to minimize organizational risk and disruption.
Manage executive, legal, compliance, privacy, and governance engagement throughout incident declaration, containment, and stabilization activities.
Provide timely and accurate situation reports, executive briefings, and incident status updates to senior leadership.
Maintain overall accountability for incident coordination and governance activities until the event has been stabilized and formally transitioned to recovery and remediation teams.
Cyber Risk ManagementOwn and maintain the Cyber Risk Register, ensuring cybersecurity risks, control deficiencies, audit findings, vulnerabilities, compensating controls, and approved risk exceptions are accurately documented and regularly reviewed.
Facilitate the identification, analysis, assessment, scoring, and prioritization of cybersecurity risks across the organization.
Partner with business, technology, and security stakeholders to develop and implement risk treatment plans, including mitigation, transfer, acceptance, and avoidance strategies.
Track risk mitigation activities, remediation efforts, and exception management processes to ensure timely execution and accountability.
Monitor cybersecurity trends, emerging threats, incidents, vulnerability data, control weaknesses, audit observations, and industry developments to identify evolving risk exposure.
Validate that cybersecurity findings, risk exceptions, and control deficiencies have clearly assigned owners, documented remediation plans, defined milestones, and target completion dates.
Conduct periodic reviews of risks, findings, and approved exceptions to validate continued business justification, effectiveness of compensating controls, and current risk ratings.
Challenge risk assumptions and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).