Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
WR
Wilton Re
Manager, Cyber Risk Operations
Career Insights for Operations Manager (General)
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Connecticut data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
An Operations Manager manages operations for a specific area within a company or organization. Supervises staff, oversees quality control, process improvement, and budget management for daily work activities. Has significant authority within their area of responsibility such as hiring, training, and managing staff.
$121,815 / year median in Connecticut
+4% projected growth
Job Description
Manager, Cyber Risk Operations We are searching for an experienced Manager, Cyber Risk Operations at our Connecticut office. Manager, Cyber Risk Operations Full Time Norwalk, CT About the
Company:
Wilton Re is an industry leader in the life (re)insurance space, specializing in the acquisition of in force life insurance and annuities. We are experienced industry specialists focused on the risk, capital and operational needs of our clients' businesses. We provide our clients with the services they need for in force transactions, capital optimization and operational efficiencies. Wilton Re has the resources and expertise to pursue and successfully manage the largest life and annuity transactions in the market.Position Summary:
The Manager, Cyber Risk Operations reports to the Chief Information Security Officer and plays a central role in strengthening the organization's cybersecurity risk management, cyber incident response readiness, and third-party cyber risk oversight. This role is responsible for maintaining visibility into cyber risks, findings, exceptions, vulnerabilities, incidents, and remediation activities while helping leadership make informed, risk-based decisions. The role leads the organization through the initial stages of cybersecurity events by establishing incident command and control, driving event categorization and severity determination, coordinating containment decisions, and managing executive, legal, governance, and operational engagement through incident declaration and stabilization. The Cyber Risk Manager partners closely with Security, IT, Legal, Compliance, Risk Management, Internal Audit, business leaders, and third-party service providers to ensure cyber risks are identified, assessed, documented, owned, remediated, and reported through appropriate governance chaRole Responsibilities:
Cybersecurity Incident Leadership and Coordination Serve as the designated lead for the organization's initial response to cybersecurity incidents, ensuring timely, coordinated, and effective management of security events from identification through stabilization. Establish and maintain initial incident command and control structures during cybersecurity events, ensuring clear accountability, decision-making authority, and communication channels. Lead the incident triage process, including validating incident details, coordinating investigations, and driving accurate classification, categorization, and severity determination. Facilitate rapid assessment of business impact, regulatory implications, operational disruption, and cyber risk exposure to support executive decision-making. Coordinate containment strategy discussions with technical response teams, business stakeholders, legal counsel, and executive leadership to minimize organizational risk and disruption. Manage executive, legal, compliance, privacy, and governance engagement throughout incident declaration, containment, and stabilization activities. Provide timely and accurate situation reports, executive briefings, and incident status updates to senior leadership. Maintain overall accountability for incident coordination and governance activities until the event has been stabilized and formally transitioned to recovery and remediation teams. Cyber Risk Management Own and maintain the Cyber Risk Register, ensuring cybersecurity risks, control deficiencies, audit findings, vulnerabilities, compensating controls, and approved risk exceptions are accurately documented and regularly reviewed. Facilitate the identification, analysis, assessment, scoring, and prioritization of cybersecurity risks across the organization. Partner with business, technology, and security stakeholders to develop and implement risk treatment plans, including mitigation, transfer, acceptance, and avoidance strategies. Track risk mitigation activities, remediation efforts, and exception management processes to ensure timely execution and accountability. Monitor cybersecurity trends, emerging threats, incidents, vulnerability data, control weaknesses, audit observations, and industry developments to identify evolving risk exposure. Validate that cybersecurity findings, risk exceptions, and control deficiencies have clearly assigned owners, documented remediation plans, defined milestones, and target completion dates. Conduct periodic reviews of risks, findings, and approved exceptions to validate continued business justification, effectiveness of compensating controls, and current risk ratings. Challenge risk assumptions and facilitate informed risk acceptance decisions by ensuring leadership has sufficient visibility into residual risk and business impact. Reporting, Metrics, and Governance Develop and maintain cybersecurity risk reporting for executive management, risk committees, audit committees, and Board-level stakeholders. Design and track cybersecurity key risk indicators (KRIs), key performance indicators (KPIs), and operational metrics to measure program effectiveness and risk trends. Prepare executive dashboards and governance reports that communicate cybersecurity posture, emerging risks, remediation progress, and risk treatment status. Provide data-driven recommendations to leadership regarding risk priorities, investment decisions, and strategic cybersecurity initiatives. Regulatory, Audit, and Compliance Support Coordinate the collection, review, and presentation of cybersecurity risk documentation, evidence, and supporting materials during audit and regulatory activities. Monitor regulatory and industry requirements to ensure risk management practices remain aligned with applicable standards, frameworks, and obligations. Assist in the development and maintenance of policies, standards, procedures, and risk management documentation supporting the cybersecurity program. Third Party Cyber Risk Management Ensure third-party cybersecurity risks, vendor findings, control deficiencies, and risk exceptions are appropriately documented and tracked within enterprise risk management processes and the IT Risk Register. Partner with procurement, legal, technology, and business stakeholders to evaluate cybersecurity risks associated with vendors, service providers, and strategic partners. Support vendor onboarding and due diligence activities, including cybersecurity assessments, security reviews, evidence evaluations, and risk recommendations. Participate in contract reviews to ensure cybersecurity, privacy, incident notification, audit, business continuity, and security control requirements are incorporated as appropriate. Business Impact Analysis and Resilience Lead the development of a Business Impact Analysis (BIA) framework for critical business processes and services. Facilitate identification of critical business functions, dependencies, recovery objectives, and operational impacts associated with cyber and technology disruptions. Partner with business leaders to assess and document third-party dependencies that could materially impact business operations. Ensure BIA outputs are incorporated into cybersecurity risk assessments, third-party risk evaluations, incident response planning, and business continuity strategies. Support cross-functional resilience initiatives by helping business units understand and manage risks associated with critical systems, processes, and external service providers.Basic Qualifications:
Minimum 6 years of progressive experience in cybersecurity, cyber risk management, incident response, technology risk, IT risk, audit, or related disciplines. Experience supporting cybersecurity risk management or incident response in insurance, reinsurance, financial services, or another highly regulated environment preferred. Demonstrated ability to coordinate cross-functional incident response activities, facilitate risk assessments, maintain risk registers, and communicate risk decisions to leadership. Strong understanding of cybersecurity risk management, incident response practices, vulnerability management, third-party risk, NIST Cybersecurity Framework, NYDFS cybersecurity requirements, and audit or regulatory expectations. Proven ability to work effectively across security, IT, legal, compliance, risk, audit, business, and vendor teams during both steady-state risk management and active incident response. Strong knowledge of cyber risk assessment, risk scoring, risk treatment, incident response coordination, control deficiencies, exception management, and remediation tracking. Excellent communication, stakeholder management, executive briefing, and governance reporting skills. Experience with GRC platforms, incident response tools, vulnerability management tools, dashboards, and workflow management solutions preferred. Ability to translate technical findings, incident details, and cyber risk information into practical business decisions and clear leadership reporting. Required Education /Certifications:
Bachelor's degree required; advanced degree preferred Professional certifications such as CISSP, CISM, CRISC, CISA, GIAC, or similar cybersecurity, risk, or incident response certifications are desirable Pay/Location Norwalk, CT Hybrid Structure Minimal to no travel required Base salary/hourly rate range for this position in Connecticut is between $125,000 and $ 165,000 Please note that specific compensation decisions are based upon a variety of job-related factors as permitted by law, including geographic location, credentials, skills, education, training, and experience. Base salary is just one component of Wilton Re's total compensation package for employees. Additional compensation includes annual performance-based bonus, 401K with employer contribution, and profit-sharing program. Employee may also be eligible for long-term incentives. All incentives and benefits are subject to the applicable plan terms.What We Offer:
Competitive vacation and sick time, including company-paid holidays, floating holidays and early closing days 401(k) plan with employer contribution - US Employees Only Profit Sharing Program Competitive parental leave Health, vision, dental, and life insurance, including access to health and wellness programs Actuarial Development Program (ADP) for Actuarial employees taking exams Employee Assistance Program (EAP) Current hybrid working environment Employee Engagement Events and various committees on site to join Wilton Re strives to attract, develop, and retain a diverse workforce. We are committed to providing an inclusive and accessible work environment where all associates feel valued, respected, and supported. Our commitment to inclusivity is reflected in the safeguards, policies, and commitments we have in place to remove barriers and provide equal opportunities to prospective and current associates, without discrimination. A Human Resources representative is available to consult with applicants who require accommodation in the application or recruitment process. Any information shared by the applicant about an accommodation will be treated as confidential.To All Recruitment Agencies:
Please do not send any resumes or solicitations regarding open positions to Wilton Re employees unless you have been requested to work on this position or other positions with Wilton Re; please reach out to your main point of contact. Wilton Re is not responsible for any fees related to unsolicited resumes. Terms & Conditions Sitemap Privacy Policy Contact US © Copyright 2025 Wilton ReBenefits
- Paid Time Off (PTO)
- Sick Leave
- Floating Holidays
- 401(k) Plans