Business Resilience Manager
Date: 23 Sept 2026
Location: Leeds, GB Manchester, GB London, GB
Company: Eversheds Sutherland
We are Eversheds Sutherland, a global law firm, with more than 5,000 people across over 30 countries. We’re full-service with deep niche and sector experience. Whatever challenge, wherever in the world, we’re equipped and ready to meet it. We live our values, we’re purposeful and purpose-led. So although the world is fast-moving and rapidly changing, we see it as a place where everyone can thrive. We’re ambitious for our clients, our communities – and for you. Whether you’re starting out on your career or well established, whether you’re a lawyer or in business services. If you’re looking for what’s next, we are too.
Our team
The General Counsel’s Office supports Eversheds Sutherland’s international business by providing trusted leadership across legal, regulatory, risk and governance matters. The Business Resilience function works across practice groups, Business Services teams and international offices to strengthen preparedness, protect critical services and enable an effective response to disruption. This role reports to the Head of Risk Management and partners closely with IT, Information Security and senior business leaders.
About the role
We are seeking an experienced and influential Business Resilience manager to lead the continuous improvement of Eversheds Sutherland’s business resilience management capability across its international network.
Reporting to the Head of Risk Management, you will ensure that business resilience arrangements remain practical, current and aligned to the firm’s most critical services, client commitments, enterprise risks and Minimum Viable Firm priorities. You will maintain the controlled documentation required for relevant ICO certification and lead the associated audit.
You will translate policy, business impact analysis and recovery priorities into a clear improvement programme for plans, runbooks, recovery strategies and supporting information. Working directly with senior leaders, you will challenge assumptions, clarify accountabilities and ensure arrangements reflect changes in services, people, locations, technology, suppliers and the external threat environment.
A central feature of the role is close partnership with IT as technology incident response, cyber response and disaster recovery capabilities mature. You will align business and technology recovery assumptions, design a structured operational and executive exercising programme, and convert lessons from exercises and live incidents into measurable improvements and clear management information.
Key Responsibilities
You will:
- Business Resilience leadership and governance: lead and continually improve the firm’s business resilience management programme, standards, governance, lifecycle and delivery roadmap.
- Translate enterprise risk priorities, Minimum Viable Firm requirements, likely crisis triggers and client commitments into a clear, risk-based resilience improvement plan.
- Develop and maintain clear roles, decision rights and escalation arrangements across the Gold, Silver and Bronze incident command structure, promoting effective ownership across practice groups, Business Services teams, international offices and critical support functions.
- Establishing and chairing a cross-firm Business Resilience governance forum.
- Plan maturity and continuous improvement: establish a proportionate review cycle for business impact assessments, business resilience plans, runbooks, contact information and critical business information.
- Engage senior leaders to validate critical activities, recovery priorities, recovery time objectives, resources, dependencies and workable recovery strategies.
- Set concise, action-oriented standards, templates and quality criteria; use findings from analysis, incidents, exercises, audits, client reviews and operating-model changes to identify gaps and prioritise improvements.
- Track improvements to completion, validate that remediation addresses underlying weaknesses and escalate material or overdue actions.
- Maintain controlled, accurate and audit-ready policies, procedures, plans, records and evidence for relevant ICO certification; lead the associated audit and ensure findings are resolved promptly and sustainably.
- Developing a risk-based resilience roadmap aligned to critical services and regulatory expectations.
- IT resilience and incident response integration: build an effective partnership with IT, IT Risk Management, Information Security and incident response teams.
- Ensure business-defined critical processes, systems, data, alternative technology requirements and recovery priorities inform disaster recovery and incident response planning.
- Align business recovery time objectives with technology recovery assumptions, highlighting unsupported dependencies, conflicts and single points of failure.
- Integrate business resilience, crisis management, cyber response, major incident management and disaster recovery into coherent end-to-end scenarios and escalation paths.
- Support resilient plan repositories, alternative communications, clean-device or virtual-desktop solutions and other recovery capabilities.
- Maintaining critical service dependencies across people, processes, technology, data, third parties and locations.
- Aligning business resilience with IT disaster recovery.
- Testing, exercising and validation: design and deliver an annual, risk-based programme covering operational teams, senior leaders, the incident command structure and critical third parties.
- Facilitate plan walkthroughs, communication tests, tabletop exercises, simulations and integrated business and IT recovery exercises using credible scenarios.
- Prepare executive participants while preserving sufficient challenge; lead structured debriefs, agree owners and deadlines, and retest where required.
- Embedding an assumed-breach mindset across planning and exercises.
- Readiness, reporting and incident learning: develop decision-useful management information on plan coverage, review status, exercise performance, recovery capability, gaps, overdue actions and recurring themes.
- Advise the Head of Risk Management, relevant committees and senior leadership on readiness, material gaps, investment priorities and emerging resilience concerns.
- Support live incidents as required and lead post-incident reviews, translating lessons into changes to plans, technology, controls, training and governance.
- Stakeholder engagement and capability: act as the principal operational contact for resilience planning, exercising, readiness reporting and improvement.
- Build trusted relationships with executive and international leaders, practice group leaders, Business Services chiefs, office leaders and plan owners.
- Collaborate across technology, information security, data governance, legal, compliance, communications, finance, people, procurement, workplace, insurance and operations.
- Build organisational capability through targeted training, briefings, guidance and exercise support, using constructive challenge to secure ownership and sustained action.
- Developing a Board-aligned Business Resilience strategy.
Skills and experience
We are looking for someone who can demonstrate:
- Significant experience leading business-wide change, operational improvement, risk, resilience or other complex cross-functional programmes in a professional services or regulated environment; a business resilience background is desirable but not essential.
- The ability to acquire and apply sound working knowledge of business resilience management, business impact analysis, recovery strategies, plan development, exercising and post-incident review; existing expertise would be advantageous.
- Exceptional relationship-building and facilitation skills, with the confidence to challenge assumptions constructively and secure ownership from senior managers.
- Experience partnering with IT and Information Security teams, with sufficient technical understanding to connect business requirements to incident response and disaster recovery capability.
- Experience designing and facilitating operational and executive exercises, producing clear evaluations and driving remediation through to closure.
- Strong analytical, programme-management, reporting and presentation skills, together with a pragmatic, calm and risk-based approach.
- Experience maintaining controlled certification or assurance documentation and leading or coordinating external audits, reviews or assessments.
What we are looking for
The successful candidate will:
- Demonstrate strong personal integrity and professional judgement
- Be an experienced leader with a relevant professional qualification or equivalent experience in business resilience, operational resilience, risk, technology or complex business change
- Bring a strong record of delivering cross-functional improvement in a regulated or professional services environment, influencing senior stakeholders and working effectively with IT and Information Security
- Be strategic yet practical, exercise sound judgement under pressure, communicate clearly and turn plans, exercises, incidents and audit findings into measurable improvements
- Knowledge of ISO 22301 and/or relevant professional accreditation are desirable.
- Success will be evidenced by current and tested plans, aligned business and technology recovery priorities, clear readiness reporting, timely closure of material actions, confident leaders and audit-ready ICO certification documentation.
What’s in it for you?
At Eversheds Sutherland, we provide benefits focused on looking after you: your development, your performance, your financial future and your health, as well as providing the opportunity to make a contribution to the world.
- We’re fair, transparent and equitable
- We share in the success of the firm, reward alignment to our values, going above and beyond and your individual performance
- We support flexible ways of working through our remote working policy and commitment to flexible, agile and hybrid ways of working
- We support your health and performance through our dental, healthcare and wellness support
- We support everything you are and all you bring through our powerful commitment to diversity and inclusion
- We provide a platform for your career, whatever your ambitions through our structured professional and personal training, mentoring and development programs
- We provide experience and opportunity through international and cross-function exposure
- We provide an opportunity to give back through our pro bono work and community engagement
- We help you plan ahead through retirement planning, insurance and assurance
Diversity & Inclusion
At Eversheds Sutherland, “Inclusive” is a core business value. We bring together different skillsets, global mindsets and approaches. We foster diversity of thought and the freedom to put ideas into action. We have an inherent respect for the individual. We have a strong belief in collaboration and teamwork. Sharing ideas, asking questions, solving challenges and meeting our clients’ goals: together.
We want all our people to thrive at work and reach their full potential and we work hard to continue to build a diverse and inclusive culture, monitor and report on our progress and impact, and develop our approach. This is reflected in our policies, systems and processes, and in our work with diversity membership organisations.
Many of our people work flexibly in some way and we are open to considering how we can accommodate flexible working arrangements alongside role requirements. If this is important to you, please talk to us about it during the recruitment process.
We want you to perform at your best during our recruitment process. If there is any adjustment or support you need, please contact us so we can discuss how we can best assist you.
For you,
For your success.
And what's next.
#LI-NC1