Skip to content
← Back to job listings

Disaster Recovery and Resilience Engineer

001 Brown & Brown, Inc · Daytona Beach, United States

CybersecurityExternal listingfull-timeabout 2 hours ago

About The Role

Built on meritocracy, our unique company culture rewards self-starters and those who are committed to doing what is best for our customers.

Brown & Brown is seeking a Disaster Recovery and Resilience Engineer to join our growing team in Daytona Beach, FL or Plano, TX.

The DR and Resilience Analyst owns the operation and governance of Brown & Brown's enterprise disaster recovery program end to end, from application intake and Business Impact Analysis through tiering, recovery plan currency, test scheduling, annual recertification, evidence, and executive reporting.

The core work is driving completion across an organization that does not report to this role. Success is measured in coverage, currency, and closure, not in activity.

During a declared event, this role serves as a Scribe within the incident command structure, owning the contemporaneous decision log that supports post-incident review, regulatory notification, insurance claim, and any subsequent dispute.

How You Will Contribute

  1. Program lifecycle ownership

Own the seven-phase recovery program lifecycle end to end: Discovery, Identification, Assessment, Planning, Implementation, Training & Test, and Maintenance for the full application of estate.

Operate the application intake path: ensure every operational application entering the estate is registered, risk-reviewed, and assigned an owner, and that no application reaches production without a defined recovery posture or a documented, approved exception.

Drive Business Impact Analysis through completion with Application and Business Owners and maintain BIA currency across the estate.

Manage tier assignments against RTO/RPO criteria and manage the DCIO review and risk-acceptance path for applications where no recovery plan will be built.

Ensure Application Recovery Plans exist, are complete against the ARP standard, and are currently including the required Security-Event Recovery Playbook for Tier 1–2 applications.

Operate the annual recertification cadence across the estate and drive it to on-time completion.

  1. Divisional and stakeholder engagement

Serve as the primary point of contact for Application Owners, Business Owners, and divisional IT leadership on all recovery program obligations.

Build and sustain working relationships across divisions that are not organizationally obligated to participate and convert program requirements into commitments with named owners and dates.

Integrate newly acquired entities into the recovery program as part of the standard integration path, working with acquisition integration teams to establish recovery posture rather than inheriting an exception.

Deliver program education so that owners understand their obligations, what a BIA asks of them, and what a recovery test will require from their team.

Escalate non-participation. Where an owner or division does not engage after defined outreach, report it through Service Management governance to the DCIO as a control failure with a named accountable individual. Non-participation is not absorbed as a scheduling problem.

  1. Test program orchestration

Build and own the enterprise recovery test calendar across applications, regions, and divisions, sequenced around business cycles, change freezes, and platform events including the ServiceNow consolidation.

Coordinate all logistics for recovery tests: participants, scheduling, scope, entry and exit criteria, communications, and business-side representation.

Coordinate annual destructive-cyber tabletop exercises with Security Operations, Legal, Corporate Communications, and Crisis Management — including scenario development, facilitation logistics , and findings capture.

Capture, publish, and track test outcomes against declared RTO and RPO. A test that does not meet its declared targets is recorded as failed, and re-test is scheduled.

Maintain the findings register and drive every finding to closure against a committed date with the owner.

  1. Evidence, audit, and regulatory readiness

Maintain the authoritative, audit-ready evidence set for enterprise recovery capability: plan currency, test execution, results against target, findings, and remediation.

Serve as the primary interface for internal audit, external audit, and client due-diligence requests relating to disaster recovery and IT resilience.

Maintain sufficient evidence to satisfy applicable regulatory obligations, including DORA-driven requirements for in-scope EU entities and HITRUST requirements for the segregated pharmacy environment.

Maintain the recovery risk register, including all documented risk acceptances with named accepting executives and review dates.

  1. Reporting and governance

Produce the recurring recovery posture reporting set for Service Management governance, the DCIO, and executive leadership: coverage, currency, test pass rate, RTO/RPO achievement, findings backlog age, and divisional participation.

Prepare recovery content for the Steering Committee and executive briefings.

Coverage and currency reporting must reflect actual state, including applications that are non-compliant, untested, or owned by non-participating divisions. Reporting that only shows progress is a failure of this role.

Own the program's operating documentation: policy, standards, procedures, RACI, and the incident command structure documentation, keeping them current and available.

Skills & Experience to be Successful

Required

  • 6+ years in IT program management, IT governance, business continuity, or technology risk, including direct ownership of an enterprise program driven to completion across business units that were not organizationally obligated to participate.
  • Demonstrated experience operating a disaster recovery, business continuity, or comparable compliance program at enterprise scale hundreds of applications or equivalent breadth.
  • Working knowledge of Business Impact Analysis methodology , RTO/RPO tiering, and recovery plan structure sufficient to assess whether a submitted plan is credible rather than merely complete.
  • Track record producing audit-ready evidence and interfacing directly with internal audit, external audit, or regulators.
  • Experience building and operating governance workflow in ServiceNow or a comparable platform — configuring process, not only consuming it.
  • Executive reporting experience, including presenting unfavorable results to senior leadership.
  • Demonstrated ability to escalate constructively and hold a position under pressure from senior stakeholders.

Preferred

  • Insurance, financial services, or another regulated industry; familiarity with DORA, HITRUST, SOC 2, or comparable resilience regulation.
  • Experience in a decentralized or acquisitive enterprise where governance has to work across federated divisions.
  • Prior participation in a real declared incident or crisis response in a coordination or scribe capacity.
  • Certifications: CBCP, MBCI, CISA, ITIL, PMP, or equivalent demonstrated capability.
  • Technical background sufficient to hold a substantive conversation with infrastructure and application engineers without an interpreter.

Teammate Benefits & Total Well-Being

We go beyond standard benefits, focusing on the total well-being of our teammates, including

  • Health Benefits : Medical/Rx, Dental, Vision, Life Insurance, Disability Insurance
  • Financial Benefits : ESPP; 401k; Student Loan Assistance; Tuition Reimbursement
  • Mental Health & Wellness : Free Mental Health & Enhanced Advocacy Services
  • Beyond Benefits : Paid Time Off, Holidays, Preferred Partner Discounts and more.

Not reflective of all benefits. Enrollment waiting periods or eligibility criteria may apply to certain benefits. Benefit details and offerings may vary for subsidiary entities or in specific geographic locations.

Recruiting Vendor Disclosure Statement

Brown & Brown does not accept unsolicited resumes from external recruiters, recruitment vendors or employment agencies ("Recruiting Vendors"). Recruiting Vendors must have a valid written agreement and received prior written authorization from an authorized Brown & Brown representative before submitting candidates for any publicly posted role. Any unsolicited resumes submitted to Brown & Brown or its employees become the property of Brown & Brown, and no fees will be paid for such submissions. Additional information regarding this policy can be found on our careers page.

The Power To Be Yourself

As an Equal Opportunity Employer, we are committed to fostering an inclusive environment comprised of people from all backgrounds, with a variety of experiences and perspectives, guided by our Diversity, Inclusion & Belonging (DIB) motto, “The Power to Be Yourself”.

This is an external listing. JobSpring does not represent or verify the employer. Report this listing