Responsibilities
- Provide support for IT recovery initiatives involving on-premises endpoints, network systems, Entra ID (Azure AD), and Microsoft 365 environments under the supervision of senior technical staff.
- Help design technical strategies for remediation and system restoration based on the specific impact observed in client environments.
- Deploy network containment and isolation configurations on widely used firewall platforms prior to recovery operations.
- Support the reconstruction of Active Directory domains, DNS/DHCP services, and Group Policy settings to a secure, known-good state.
- Assist in restoring and verifying virtualized systems running on VMware ESXi or Hyper-V platforms, along with critical file and application servers.
- Help recover and secure Entra ID user identities, Conditional Access rules, and directory synchronization using Entra Connect linked to on-premises Active Directory.
- Support the reconfiguration and recovery of Exchange Online, SharePoint, OneDrive, and Microsoft Teams services.
- Validate and restore data from backup solutions such as Veeam, Rubrik, and Datto, ensuring data integrity and understanding distinctions between snapshots and isolated backups.
- Use standard remote access tools and secure VPN connections to deliver remote assistance during incident recovery.
- Apply recognized Microsoft security baselines and hardening practices throughout recovery workflows.
- Support the deployment of compliance-related security controls including multi-factor authentication, Defender for Office 365, and Purview.
- Create and maintain PowerShell automation scripts to streamline repetitive recovery tasks.
- Document all rebuilt system configurations, recovery timelines, and actions performed to support auditability for legal and insurance purposes.
- Maintain awareness of chain-of-custody protocols when managing forensic evidence, disk images, and system logs.
Work Arrangement
Remote (Worldwide)
Responsibilities (14)
- Support IT recovery projects involving on-premises endpoint and network infrastructure, Entra ID (Azure AD), and Microsoft 365 under the guidance of senior engineers
- Assist in developing technical remediation and restoration plans tailored to the impact on a client's environment
- Implement network containment and isolation measures on common firewall platforms in preparation for recovery efforts
- Assist in rebuilding Active Directory domains, DNS/DHCP, and Group Policy structures to a clean baseline
- Support restoration and validation of virtualized workloads (VMware ESXi, Hyper-V) and critical file/application servers
- Assist in recovering and securing Entra ID identities, Conditional Access policies, and synchronization with on-prem AD via Entra Connect
- Support rebuilds of Exchange Online, SharePoint, OneDrive, and Teams configurations
- Validate and restore data from backups (Veeam, Rubrik, Datto, etc.), ensuring integrity and cleanliness — understanding the critical difference between snapshots and proper isolated backups
- Utilize common remote management tools and VPN connections to assist impacted clients remotely
- Apply industry-standard Microsoft hardening guidelines throughout recovery processes
- Assist in implementing compliance controls such as MFA, Defender for Office 365, and Purview
- Develop and maintain PowerShell scripts for recurring recovery workflows
- Maintain thorough documentation of rebuilt configurations, recovery timelines, and actions taken — supporting defensible, auditable records for insurance carriers and legal counsel
- Maintain chain of custody awareness when handling evidence, disk images, or log files
Work Arrangement
Remote (Worldwide)
Team
Reports to: senior engineers and the R&R Engineering Manager
Other (5)
- Travel up to 50% may be required to client sites as required to perform recovery activities and on-site validation.
- Participate in after-hours response rotations.
- Sedentary work
- Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day
- Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day