Resilience & Incident Operations Manager
Be the calm command behind our fintech’s reliability. Drive major incident response, live DR drills, and DORA/FCA standards - protecting millions in customer funds when it matters most.
About Pockit and Monese
Pockit and Monese are all-in-one money apps that make it easier for people to access and manage the financial tools they need to take control of their money.
We provide vital financial services, from accounts and cards to income advance solutions. In October 2024, Pockit acquired Monese, bringing together two complementary businesses and creating a leading fintech company focused on serving people who are underserved by traditional banks.
Together, we serve more than three million customers across the UK and Europe.
We're a diverse, international and energetic team, with colleagues based across London, Newcastle, Tallinn and remote teams across Central Europe. We value curiosity, ambition, accountability and resilience, and we want everyone to feel at home, have a voice and know that their contribution matters. We give people the trust and space to take ownership, share ideas, influence decisions, and make a real impact on our customers and our business.
The role
As a regulated fintech, operational resilience is central to keeping customer funds safe and our services running. We are looking for a Resilience & Incident Operations Manager to strengthen how we detect, manage, learn from, and prepare for disruption. This is a hands-on, cross-functional role. You'll drive two critical areas for the business: incident management and business continuity & disaster recovery (BC/DR). Additionally, you will be expected to play a key role in the third-party risk management (TPRM), ensuring our operational resilience posture is up to the regulatory standards (FCA, DORA).
What you will do
1. Major Incident Leadership & Regulatory Reporting
End-to-End Major Incident Coordination: Coordinate major incidents end to end across platform/apps, safeguarding, and security/data-breach categories-triaging and assigning severity, coordinating technical responders, managing stakeholder and regulatory communications, and driving issues to complete resolution.
Regulatory Reporting Timelines: Own and meet strict regulatory reporting timelines, including DORA major-incident reporting, FCA notifications, and ICO data breach assessment and notification.
Post-Incident Reviews (PIRs): Run thorough post-incident reviews and track all identified remediation actions to closure.
2. Governance, Policy & Audit Readiness
Policy & Framework Maintenance: Maintain the incident management policy, procedures, severity matrix, and escalation paths, keeping them audit-ready against FCA’s PS21/3 (Operational Resilience), DORA, and ISO 27001:2022 requirements.
BCP & DR Playbooks: Maintain BCP & DR policy, procedures, and playbooks, ensuring they continuously stay up to date.
Forensic Readiness & Evidence Chain: Ensure forensic readiness for security incidents by preserving digital evidence and maintaining a chain of custody so it is admissible in legal, regulatory, or law-enforcement proceedings.
3. Resilience Execution & Testing
Tabletop & Live DR Exercises: Plan and facilitate tabletop exercises, incident drills, and live DR exercises for the platform and critical ICT services - aligning Engineering, Customer Service, FinOps, and CRM teams.
Third-Party Risk (TPRM) Integration: Contribute to the TPRM (Third Party Risk Management) programme, working with vendor owners to monitor third-party service providers and reflecting third-party dependencies directly in incident and DR plans.
4. Tooling Operations & On-Call Governance
Incident Workflow & Metrics: Own the incident workflow in Jira Service Management (templates, runbooks, on-call routing) and report core incident metrics (MTTA, MTTR, recurrence, and SLA adherence).
On-Call Management:Coordinate and occasionally participate in the 24x7 on-call ROTA across Operations and Tech- ensuring members are properly trained and have the runbooks, contacts, and system access they need.
What you will bring
4+ years of proven experience leading major incident management, disaster recovery, and operational resilience within a heavily regulated financial institution or Fintech/EMI environment.
Hands-on BCP/DR Execution: Proven experience writing end-to-end BCP/DR playbooks, setting RTO/RPO targets, and facilitating both cross-functional tabletop exercises and live failover tests.
Regulatory Expertise: Working knowledge and practical application of European and UK resilience frameworks, including DORA, FCA PS21/3, critical third-party outsourcing rules, and GDPR/ICO breach notification requirements.
Modern Technical Familiarity: Direct experience navigating complex Fintech architecture, including payment gateways, core banking engines, ledgers, and KYB/AML integrations.
Tooling Mastery: Hands-on experience configuring and operating incident/service management platforms (Jira Service Management, OpsGenie, PagerDuty, or Statuspage) to drive MTTA/MTTR reduction and SLA tracking.
Analytical Problem Solver: Ability to leverage post-mortem data and metric trends to address root causes, improve systems/procedures, and secure stakeholder buy-in.
What we consider as a plus
Familiarity with ISO 27001: 2022 and the security incident / data-breach lifecycle, including UK GDPR breach assessment.
Why Join Us?
Make a real difference: Work at the intersection of technology and financial inclusion, helping people take greater control of their money.
Have a voice: Your ideas and perspective matter. You'll have the opportunity to influence decisions, take ownership and shape how we work.
Make an impact: Work on initiatives that reach millions of customers across the UK and Europe.
Work with great people: Join a diverse, international and ambitious team where collaboration and curiosity are encouraged.
Grow with us: Be part of a fast-moving fintech where you'll have plenty of opportunities to learn, develop and make your mark.
What benefits we offer
We want you to feel supported, valued and able to do your best work - both in and outside the office.
25 days annual leave + public holidays, with an extra day for every year worked
Healthcare: Private medical with Confido, sports compensation with Stebby or discount from a gym.
10 paid sick days per year
Hybrid working + up to 30 days working abroad each year
L&D budget + 10 paid learning days per year
Annual eyecare allowance
Enhanced maternity, paternity and shared parental leave
VIP Pockit & Monese accounts
Extra paid days off for your birthday and wedding
Regular social events and team activities
Monthly recognition awards and Team of the Quarter
Share options, depending on role and level
Employee referral bonus
Free office parking
- Department
- Operations
- Location
- Estonia
- Remote status
- Hybrid