All remote jobs

Tabletop Exercise (TTX) Specialist – Cybersecurity Focus

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

Remote from
USA
Salary
USD 100k–135k / yr
Department
Cybersecurity
Employment
Full Time
Experience
Director
Published
Apply before
10 Nov 2026
Listing views
147
Application actions
9
Application toolkit

Make your next move.

Prepare your resume, explore your fit, and draft a cover letter for this opportunity.

AI Summary

The role, at a glance.

This client-facing cybersecurity role designs, tailors, and facilitates tabletop exercises that evaluate enterprise incident response, disaster recovery, and business continuity readiness. The specialist will guide executive and cross-functional stakeholders through crisis scenarios such as ransomware attacks, data breaches, and systemic security incidents. Key deliverables include exercise materials, facilitator scripts, evaluation metrics, debriefs, and actionable After-Action Reports. The position requires knowledge of US and European cyber/privacy regulations, strong project coordination, and up to 25% travel across the US and Europe. It is a high-visibility role requiring confident executive communication and ownership across multiple client engagements.

Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

Job Complexity

4/5
EasyHard

Pace & Pressure

4/5
RelaxedFast-paced

Autonomy Level

5/5
GuidedFull ownership

Communication Load

5/5
IndependentCollaborative
AI insightThe role combines technical cybersecurity and regulatory knowledge with independent scenario design and executive-level facilitation under simulated crisis conditions. Success depends on translating complex risk issues into practical decisions for diverse, non-technical stakeholders while managing multiple engagements.

Salary analysis

Estimated compensation compared with the broader US market for similar roles.

Estimated job medianMarket rate
$117,500
US market range$95k–$145k
AI insightThe disclosed compensation range is $100,000 to $135,000 USD, with a midpoint of $117,500 per year. This is broadly competitive for a mid-level US cybersecurity tabletop exercise and incident-response consulting specialist; estimated US market pay is approximately $95,000 to $145,000 annually depending on location, client-facing experience, certifications, and depth of incident-response expertise.

Core skills

Skills and capabilities most closely associated with this opportunity.

Sample interview questions
How do you design a tabletop exercise that is relevant to a specific client?

I begin by reviewing the client's incident response, disaster recovery, and business continuity plans, along with their industry, threat profile, critical systems, and regulatory obligations. I identify decision points and gaps, then build an escalating scenario with clear injects, roles, success criteria, and evaluation metrics tied to the client's priorities.

How would you facilitate a ransomware exercise with a non-technical executive team?

I would use plain business language and structure the discussion around decisions executives actually own, such as operational shutdowns, legal notification, customer communications, ransom considerations, and recovery prioritization. I would keep the scenario time-bound, clarify assumptions, and ensure each function understands its responsibilities without overwhelming participants with unnecessary technical detail.

What should an effective After-Action Report include?

An effective AAR should summarize the exercise scope and scenario, document key decisions and observations, identify strengths and gaps, assess process and communication effectiveness, and prioritize recommendations. Each recommendation should have a clear owner, rationale, urgency, and practical next step so the report becomes an improvement roadmap rather than only a record of discussion.

How do GDPR, NIS2, CCPA, and SEC disclosure requirements affect incident-response exercises?

They shape the scenario's notification, evidence preservation, governance, and escalation decisions. I would incorporate realistic prompts about breach assessment, materiality, regulator and customer notification timelines, cross-border data considerations, and coordination among security, legal, privacy, communications, and executive leadership.

How do you manage several client exercises with competing deadlines?

I establish a delivery plan for each engagement with milestones for discovery, scenario development, stakeholder scheduling, facilitation, and reporting. I maintain a central tracker, communicate risks early, use reusable but adaptable templates, and protect review time so quality is not compromised when schedules change.

This analysis is generated from the job description. Salary estimates, role characteristics and sample answers are guidance, not employer-provided facts.
Opportunity details

About this role.

About Us

At Resilience, we’re creating a new category that integrates cybersecurity, cyber insurance, and cyber risk management. Founded in 2016 by experts from across the highest tiers of the US military and intelligence communities – and built by prominent leaders and innovators from the insurance, technology, and cybersecurity industries – Resilience is rewriting the rules of how cyber risk is assessed, measured, and managed.

Our integrated cyber risk solutions connect risk quantification software, cybersecurity experts, and A+ rated cyber insurance, all purpose-built for middle and large organizations. We are a cybersecurity company, a Cyber and Tech E&O-focused MGA, a fintech startup, and a data science powerhouse, all purposefully built into one.

Resilience is proud to be backed by leading technology investment firms, including General Catalyst, Lightspeed Venture Partners, Intact Ventures, Founders Fund, CRV, and Shield Capital.

The Hook: Why this role matters now

Step into a high-visibility, client-facing role to drive real-world cyber resilience for middle to large enterprises with annual revenues ranging from $100M to $10B. Reporting to the Director of Security and Risk Services, as a Tabletop Exercise (TTX) Specialist, you won’t just run routine drills; you will take complete ownership of designing, building, and facilitating immersive, crisis-level cyber incident simulations. You will serve as the trusted advisor who tests client Incident Response Plans (IRPs), Disaster Recovery Plans (DRPs), and Business Continuity Plans (BCPs), ensuring executive teams are battle-tested before a real threat strikes.

The Mission: What you will achieve in the first 6 months

In your first six months, you will take full accountability for building, tailoring, and facilitating realistic TTX scenarios that test our clients’ operational and strategic cyber readiness:

  • Scenario Design & Engineering: Partner with Resilience Customer Engagement teams to audit client Incident Response Plans, identify critical coverage gaps, and author tailored exercise guides, facilitator scripts, and evaluation metrics mapped to each client’s industry and regulatory requirements.
  • Executive & C-Suite Facilitation: Confidently lead virtual and in-person TTX sessions, guiding cross-functional stakeholders—including non-technical executive leadership (C-Suite, Legal, PR, and HR)—through complex decisions during simulated ransomware attacks, data breaches, and systemic security events.
  • Post-TTX Analysis & Actionable Guidance: Conduct debriefing sessions and deliver comprehensive After-Action Reports (AARs) summarizing lessons learned, regulatory decision-making nuances, and actionable security recommendations.
  • Methodology Scaling: Contribute to refining Resilience’s proprietary TTX frameworks, methodologies, and best practices as our client portfolio grows globally.

The Toolkit: Technical skills vs. “nice-to-haves”

  • Core Requirements:
    • 3–5 years of proven experience designing and facilitating cybersecurity incident response TTXs, IRPs, DRPs, and BCPs for enterprise clients.
    • Demonstrated mastery in facilitating crisis simulations for cross-functional enterprise stakeholders, specifically non-technical C-Suite executives, Legal, PR, and HR leaders.
    • Bachelor’s degree in Cybersecurity, Computer Science, Information Technology, or a related field (or equivalent practical experience).
    • Strong working knowledge of major US and European cybersecurity and privacy regulations (GDPR, NIS2, CCPA, SEC cyber disclosure rules) and their impact on incident response governance.
    • Strong project management skills to handle multiple client engagements, coordinate enterprise schedules, and meet strict deadlines
    • Willingness to travel up to 25% across the US and Europe
  • Nice-to-Haves:
    • Relevant industry certifications (e.g., CISSP, CISM
    • Hands-on proficiency with specialized TTX simulation platforms and software.

The Culture: How we work

We move fast, operate with zero ego, and embrace a bias to action. We are guided strongly by our four core values: transparency, excellence, grit, and humility. You will thrive in an exciting, collaborative startup culture alongside top-tier cybersecurity experts, maintaining a constructive learning environment for clients under pressure.

The Benefits: Standardized perks

You will work alongside prominent leaders and innovators from the insurance, technology, and cybersecurity industries, as well as experts from the highest tiers of the US military and intelligence communities.

Compensation range

$100,000—$135,000 USD

What Resilience Offers You

Innovative company culture

Flexible work schedules

Family paid leave

Paid healthcare for employees

401k/Pension

Professional development & career advancements

Flexible paid time off

Employee referral bonus

Accommodations and Accessibility

We want to ensure you’re able to perform as well as possible in your interview. As part of that, if you have any accessibility-related needs to ensure a comfortable visit, please let us know. We’ll do our best to provide reasonable accommodations to suit your working style during your interview and if you join our team.

If you require a reasonable accommodation in completing this application, interviewing, completing any pre-employment testing, or otherwise participating in the employee selection process, please let your recruiter contact know.

Beware of Job Scams

Resilience is excited to welcome talented individuals to explore career opportunities with us. However, we urge you to stay vigilant against recruitment scams where fraudsters may impersonate our company. We will never ask for payments, conduct interviews via chat rooms, or contact candidates from personal email accounts. All job applications must be submitted through our official platform at greenhouse.io , and interviews will only take place via approved Resilience accounts. If you receive suspicious outreach or have concerns, please let your recruiter contact know. Thank you for helping us maintain a safe and secure recruitment process.

Apply now >

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Did you apply?Let us know, and we’ll help you track your application.

Continue on the employer website

Protect your personal information and never pay to secure an interview or job offer. .

Log in to save
One quick step before you apply

Sign in to continue.

Sign in or create a free account to continue to the employer's application.

Applying is free. After signing in, return to this job and select Apply Now.
Add alert
Jobs Talent AI Tools Salaries
Menu