
Location: Chicago, IL
Work Model: Hybrid (onsite 3 days per week)
Long Term Contract
The Cyber Recovery Engineer is a technical contributor role focused on supporting the design, operation, and testing of the organization s cyber recovery program within a regulated financial services environment. Working closely with senior engineers and program leads, you will gain hands-on experience in isolated recovery environments (IRE), clean room operations, enterprise backup platforms, and regulatory documentation.
This position is structured to cultivate the next generation of cyber recovery practitioners. Candidates should bring a strong foundation in infrastructure or security, prior exposure to regulated industries, and a genuine interest in resilience engineering and compliance. Within 12-18 months, you will be expected to independently manage recovery workstreams.
Experience Level: Senior
7-10 years of experience in infrastructure engineering, IT operations, or a security-related technical role.
Background in financial services or other regulated industries (e.g., healthcare, utilities, government).
Hands-on exposure to disaster recovery or backup operations, including DR testing, backup job management, or restore procedures.
Familiarity with at least one enterprise backup/replication platform (Cohesity, Rubrik, Veeam, Zerto, Commvault, NetBackup).
Basic scripting skills in Python, Bash, or PowerShell; ability to run and adapt existing scripts.
Understanding of networking fundamentals (VLANs, firewall rules, DNS, routing) relevant to isolated environments.
Strong documentation skills with the ability to produce clear technical procedures and test records.
Awareness of regulatory frameworks such as FFIEC, NIST CSF, or NYDFS.
Direct involvement in IRE or clean room recovery exercises.
Experience supporting regulatory examinations or audit walkthroughs.
Familiarity with Infrastructure-as-Code (IaC) tools such as Terraform or Ansible.
Coursework or self-study in cybersecurity, resilience engineering, or cloud infrastructure.
Certifications (completed or in progress): CompTIA Security+, CySA+, AWS/Azure fundamentals, or vendor-specific backup training.
Experience with ITSM workflows (ServiceNow or equivalent).
Exposure to ransomware response or cyber incident tabletop exercises.
Isolated & Clean Room Recovery
Support operation and maintenance of IRE and clean room infrastructure under senior guidance.
Execute recovery runbook steps during tabletop exercises, drills, and full recovery tests.
Document procedures, results, and anomalies; escalate issues for triage.
Assist with forensic validation tasks, including integrity checks and configuration reviews.
Apply clean room protocols such as network isolation and access control verification.
Backup Platform Operations
Perform daily operational tasks across enterprise backup platforms.
Monitor backup job health, investigate failures, and escalate recurring issues.
Assist with backup policy configuration, retention schedules, and replication targets.
Support restore testing for servers, databases, and applications; record RTO/RPO outcomes.
Regulatory Documentation & Audit Support
Prepare evidence packages, control narratives, and test documentation for audits and regulatory reviews.
Maintain organized recovery logs and remediation tracking aligned with FFIEC, NIST CSF, and NYDFS standards.
Participate in regulator and audit walkthroughs alongside senior engineers.
Support mapping of regulatory requirements to recovery engineering controls.
Recovery Engineering & Automation
Execute scripted recovery automation tasks and assist with IaC-driven configurations.
Contribute to updates of recovery runbooks and playbooks.
Participate in after-action reviews (AARs) and track findings to closure.
Collaborate with infrastructure, application, and database teams to understand dependencies in recovery sequencing.