Job Summary
The Senior Cyber Recovery Engineer will serve as a hands-on technical leader responsible for designing, implementing, and continuously validating the organization's ability to recover critical systems and data following a cyber event. The role sits at the intersection of infrastructure engineering, cybersecurity, and regulatory compliance within a highly regulated financial services environment. The successful candidate will have direct experience operating within financial institution recovery programs, engaging with banking regulators, and executing recovery exercises within Isolated Recovery Environments (IRE) and clean room configurations. This is a hands-on role requiring experience running recovery drills, developing recovery runbooks, and validating recovery assumptions.
Key Responsibilities
• Design, build, and maintain Isolated Recovery Environment (IRE) and clean room infrastructure used for cyber recovery exercises and declared events.
• Execute end-to-end recovery testing cycles to validate RTOs and RPOs for Tier-1 and Tier-2 critical applications.
• Develop and maintain recovery runbooks, playbooks, and automation scripts for clean room restoration of core banking systems, trading platforms, and data stores.
• Lead technical forensic validation procedures within the IRE to confirm system integrity before production re-entry.
• Design and implement cyber recovery capabilities for critical systems and data.
• Continuously test and validate recovery processes, assumptions, and technical controls.
• Apply network segmentation, identity isolation, and zero-trust concepts within isolated recovery and clean room environments.
• Support recovery activities involving ransomware, destructive malware, and related cyber incidents.
• Collaborate across infrastructure, cybersecurity, resilience, and compliance teams to execute recovery exercises and declared events.
Required Qualifications
• 10+ years of infrastructure, platform, or resilience engineering experience.
• At least 4 years of experience working within a financial institution, such as a bank, broker-dealer, asset manager, or equivalent regulated entity.
• Demonstrated hands-on experience implementing and testing cyber recovery within an Isolated Recovery Environment (IRE) or clean room; traditional DR/BC planning experience alone is not sufficient.
• Direct experience engaging with financial regulators such as OCC, FDIC, Federal Reserve, NYDFS, SEC, or FINRA in technology examinations or regulatory responses.
• Proficiency with enterprise backup and replication platforms such as Cohesity, Rubrik, Zerto, Veeam, Commvault, or NetBackup.
• Working knowledge of Infrastructure as Code (IaC) tools including Terraform and Ansible.
• Strong scripting experience with Python, Bash, and/or PowerShell for recovery automation.
• Strong understanding of network segmentation, identity isolation, and zero-trust concepts as applied to clean room environments.
• Familiarity with ransomware TTPs, destructive malware incident response, and forensic triage in a recovery context.
• Experience applying FFIEC guidance, NIST CSF, and/or DORA requirements to operational resilience and recovery.