About the job
At GuidePoint Security, we deliver unparalleled cybersecurity expertise, solutions, and services that empower organizations to make informed decisions and mitigate risks. Our comprehensive, three-tiered approach to assessing security posture and ecosystems enables leading entities, including Fortune 500 companies and U.S. government agencies, to effectively identify threats, optimize resources, and implement tailored solutions that reduce vulnerabilities.
Role Overview
The Senior Recovery and Restoration Engineer plays a pivotal role within our Incident Management & Recovery team. This position involves the meticulous rebuilding and fortification of infrastructure environments following ransomware attacks or other significant cyber incidents. The ideal candidate will possess extensive on-premises infrastructure knowledge (Active Directory, VMware/Hyper-V, storage, backups, etc.) combined with advanced recovery skills in Microsoft 365 and Azure. You will spearhead hands-on recovery efforts encompassing identity, compute, storage, and cloud layers, collaborating closely with clients, the GuidePoint Security Incident Response team, and internal engineers to restore business functions swiftly and securely.
Key Responsibilities
- Lead IT recovery initiatives involving on-premises endpoint and network infrastructure, Entra ID, and Microsoft 365.
- Design and oversee technical remediation and restoration strategies customized to the specific impacts on client environments.
- Apply knowledge of common firewall platforms to execute network containment in preparation for recovery operations.
- Reconstruct Active Directory domains, DNS/DHCP configurations, and Group Policy structures to a pristine baseline.
- Recover and verify virtualized workloads (VMware, Hyper-V) and critical file/application servers.
- Restore and secure Entra ID identities, Conditional Access, and synchronization with on-premises Active Directory.
- Rebuild configurations for Exchange Online, SharePoint, OneDrive, and Teams.
- Validate and restore data from backups (Veeam, Rubrik, Datto, etc.) ensuring integrity and accuracy.
- Utilize common remote management tools to assist impacted clients effectively.
- Understand and apply industry-standard Microsoft hardening guidelines.
- Implement essential compliance controls, including MFA, Defender for Office 365, Purview, etc.
- Create and maintain automation scripts (PowerShell/Python) for recurring recovery workflows.
- Document rebuilt configurations and offer client recommendations for security hardening and post-incident validation.
- Participate in after-hours response rotations as needed.
- Travel to client sites when required to execute critical recovery tasks.

