The Team:
Upstart Bank is an evolution of Upstart's AI lending platform, focused on simplifying the regulatory infrastructure behind our marketplace while expanding access to credit nationwide. By moving from a fragmented, state-based system to a unified federal framework, Upstart Bank enables more consistent borrower experiences, reduces structural costs, and unlocks opportunities to improve pricing, compliance, and access to credit at scale.
We're looking for a Principal Program Manager, Business Continuity & Disaster Recovery to join our growing Information Security team. In this role, you will lead Upstart's business continuity and disaster recovery program, inheriting and maturing existing foundations including business continuity policy, disaster recovery planning, and business impact analysis processes. You will help build the program toward bank-grade operational resilience standards while ensuring critical business operations and technology services can effectively respond to and recover from disruptive events.
This role sits in the first line of defense and partners closely with Enterprise Risk Management, Compliance, Engineering, Security, Operations, Vendor Management, and business owners to execute and mature Upstart's resiliency program.
How you'll make an impact
- Lead the enterprise business continuity and disaster recovery program strategy, execution, governance, and ongoing maturity efforts.
- Own and mature the business impact analysis process, including critical business process identification, dependency mapping, ownership assignment, risk-rating methodology, and recovery strategy development.
- Develop and maintain business continuity plans, disaster recovery plans, crisis management processes, and supporting documentation for critical business and technology functions.
- Drive cross-functional execution across Technology, Security, Office Operations, Vendor Management, Enterprise Risk Management, Compliance, and business process owners to ensure continuity and recovery plans are actionable, tested, and maintained.
- Coordinate disaster recovery exercises, tabletop tests, remediation tracking, and evidence collection to improve organizational preparedness and support audit or regulatory expectations.
- Maintain and improve program repositories, workflows, and reporting, including business impact analysis records, recovery plans, testing evidence, program metrics, and remediation status.
Minimum Qualifications
- Bachelor's degree in Information Security, Computer Science, Business, Risk Management, or a related field, or equivalent practical experience, plus 8 years of experience in business continuity, disaster recovery, operational resilience, information security, risk management, or program management.
- 8+ years of experience leading or materially maturing business continuity, disaster recovery, or operational resilience programs.
- Experience designing or maturing business continuity, disaster recovery, or operational resilience programs in a bank, fintech, lending, or other regulated financial services environment.
- Experience conducting business impact analyses, recovery planning, dependency mapping, resilience testing, and remediation tracking.
- Experience implementing or operating against business continuity, disaster recovery, or operational resilience frameworks or standards such as ISO 22301, NIST, FFIEC, or equivalent regulatory guidance.
Preferred Qualifications
- Knowledge of technology resilience concepts, including cloud infrastructure resilience, service outages, incident response coordination, system dependencies, and vendor recovery planning.
- Experience supporting audits, regulatory reviews, or compliance initiatives related to business continuity, disaster recovery, or operational resilience.
- Skilled in developing scalable operational processes, program governance models, documentation repositories, and executive-level reporting.
- Ability to communicate resilience risks, recovery strategies, and program priorities to technical and non-technical stakeholders.
- Professional certifications such as CBCP, CISSP, CISM, CRISC, or related business continuity, security, or risk certifications
Position location: This role is available in the following locations: Remote
Travel requirements: As a digital first company, the majority of your work can be accomplished remotely. The majority of our employees can live and work anywhere in the U.S but are encouraged to to still spend high quality time in-person collaborating via regular onsites. The in-person sessions' cadence varies depending on the team and role; most teams meet once or twice per quarter for 2-4 consecutive days at a time.
#LI-REMOTE
#LI-MidSenior