Disaster Recovery and Resilience Engineer
Program Lifecycle Ownership
Own the seven-phase recovery program lifecycle end to end: Discovery, Identification, Assessment, Planning, Implementation, Training & Test, and Maintenance for the full application of estate.
Operate the application intake path: ensure every operational application entering the estate is registered, risk-reviewed, and assigned an owner, and that no application reaches production without a defined recovery posture or a documented, approved exception.
Drive Business Impact Analysis through completion with Application and Business Owners and maintain BIA currency across the estate.
Manage tier assignments against RTO/RPO criteria and manage the DCIO review and risk-acceptance path for applications where no recovery plan will be built.
Ensure Application Recovery Plans exist, are complete against the ARP standard, and are currently including the required Security-Event Recovery Playbook for Tier 1–2 applications.
Operate the annual recertification cadence across the estate and drive it to on-time completion.
Serve as the Primary Point of Contact
Serve as the primary point of contact for Application Owners, Business Owners, and divisional IT leadership on all recovery program obligations.
Build and sustain working relationships across divisions that are not organizationally obligated to participate and convert program requirements into commitments with named owners and dates.
Integrate newly acquired entities into the recovery program as part of the standard integration path, working with acquisition integration teams to establish recovery posture rather than inheriting an exception.
Deliver program education so that owners understand their obligations, what a BIA asks of them, and what a recovery test will require from their team.
Escalate non-participation. Where an owner or division does not engage after defined outreach, report it through Service Management governance to the DCIO as a control failure with a named accountable individual.
Test Program Orchestration
Build and own the enterprise recovery test calendar across applications, regions, and divisions, sequenced around business cycles, change freezes, and platform events including the ServiceNow consolidation.
Capture, publish, and track test outcomes against declared RTO and RPO.
A test that does not meet its declared targets is recorded as failed, and re-test is scheduled.
Maintain the findings register and drive every finding to closure against a committed date with the owner.
Evidence, Audit, and Regulatory Readiness
Maintain the authoritative, audit-ready evidence set for enterprise recovery capability: plan currency, test execution, results against target, findings, and remediation.
Serve as the primary interface for internal audit, external audit, and client due-diligence requests relating to disaster recovery and IT resilience.
Maintain sufficient evidence to satisfy applicable regulatory obligations, including DORA-driven requirements for in-scope EU entities and HITRUST requirements for the segregated pharmacy environment.
Maintain the recovery risk register, including all documented risk acceptances with named accepting executives and review dates.
Reporting and Governance
Produce the recurring recovery posture reporting set for Service Management governance, the DCIO, and executive leadership: coverage, currency, test pass rate, RTO/RPO achievement, findings backlog age, and divisional participation.
Prepare recovery content for the Steering Committee and executive briefings.
Coverage and currency reporting must reflect actual state, including applications that are non-compliant, untested, or owned by non-participating divisions.
Reporting that only shows progress is a failure of this role.
Own the program's operating documentation: policy, standards, procedures, RACI, and the incident command structure documentation, keeping them current and available.