Senior Recovery and Restoration Engineer - Remote; U.S
Tampa, Hillsborough County, Florida, 33646, USA
Listed on 2026-02-28
-
IT/Tech
Cybersecurity, Systems Engineer
Senior Recovery and Restoration Engineer - Remote (Anywhere in the U.S.)
Join GuidePoint Security as a Senior Recovery and Restoration Engineer. GuidePoint Security provides trusted cybersecurity expertise, solutions and services that help organizations make better decisions and minimize risk.
Role SummaryAs a key member of the Incident Management & Recovery team, you will rebuild and secure infrastructure after ransomware or other destructive cyber incidents. Your role blends deep on‑premises infrastructure expertise (Active Directory, VMware/Hyper‑V, storage, backups, etc.) with advanced Microsoft 365 and Azure tenant recovery experience.
Core Responsibilities- Lead IT recovery projects involving on‑premises endpoint and network infrastructure, Entra , and Microsoft 365.
- Develop and manage technical remediation and restoration plans tailored to the impact of a client’s environment.
- Implement network containment using common firewall platforms.
- Rebuild Active Directory domains, DNS/DHCP, and GPO structures to a clean baseline.
- Restore and validate virtualized workloads (VMware, Hyper‑V) and critical file/application servers.
- Recover and secure Entra , Conditional Access, and synchronization with on‑prem AD.
- Rebuild Exchange Online, SharePoint, One Drive, and Teams configurations.
- Validate and restore data from backups (Veeam, Rubrik, Datto, etc.) ensuring integrity and cleanliness.
- Use common remote management tools to assist impacted clients.
- Apply industry‑standard Microsoft hardening guidelines.
- Implement compliance controls such as MFA, Defender for Office 365, Purview, etc.
- Develop and maintain automation scripts (Power Shell/Python) for recurring recovery workflows.
- Document rebuilt configurations and assist client recommendations for hardening and post‑incident validation.
- Participate in after‑hours response rotations.
- Travel to client sites as required (up to 50% travel).
- Advanced knowledge of Windows Server, Active Directory, Entra , and Microsoft 365 administration.
- Strong experience with VMware or Hyper‑V virtualization platforms.
- Proficiency in Power Shell. Prefer experience with Entra , Exchange Online, and Graph API modules.
- Familiarity with backup restoration workflows and immutable storage systems.
- Solid understanding of identity security, Conditional Access, Defender for Cloud Apps, and Exchange Online Protection.
- Demonstrated success in recovery or rebuild scenarios post‑incident.
- Ability to identify persistence mechanisms and rebuild clean environments under tight timelines.
- Working knowledge of NIST CSF, CIS benchmarks, and insurance‑driven recovery requirements.
- Excellent communication and documentation skills across technical and non‑technical stakeholders.
- Proven ability to work alongside IR firms, legal counsel, and insurers during live recovery engagements.
- Capable of mentoring junior engineers and improving structured rebuild approaches.
- Calm and decisive under pressure and able to prioritize critical‑path recovery items.
- Highly organized with a disciplined approach to communicating recovery milestones, task tracking, and reporting.
- Willingness to travel up to 50% to client environments as needed for hands‑on rebuilds and validation.
- 5–8 years of experience in infrastructure engineering roles, preferably within consulting, MSP, or IR/recovery efforts.
- Microsoft certifications (e.g., AZ‑104, MS‑100, MS‑500, SC‑300) or equivalent enterprise experience.
- Experience with one or more EDR or security platforms (Crowd Strike, Sentinel One, Defender).
- Strong scripting or automation experience, demonstrating process acceleration in rebuilds.
- Remote workforce primarily (U.S. based only; some travel may be required).
- Group Medical Insurance (Zero‑Deductible PPO plan etc.).
- Group Dental Insurance.
- 12 corporate holidays and a Flexible Time Off (FTO) program.
- Healthy mobile phone and home internet allowance.
- Eligibility for retirement plan after 2 months at open enrollment.
- Pet Benefit Option.
Mid‑Senior level
Employment typeFull‑time
Job functionOther
IndustriesIT Services and IT Consulting
Referrals increase your chances of interviewing at GuidePoint Security by 2x
#J-18808-Ljbffr(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).