Enterprise Architect - Cybersecurity
Listed on 2026-06-26
-
IT/Tech
Cybersecurity, Disaster Recovery IT
Enterprise Architect/ Senior Cyber Recovery Engineer Project Overview / Contractor's Role:
The Senior Cyber Recovery Engineer is a hands‑on technical leader responsible for designing, implementing, and continuously validating the organization’s ability to recover critical systems and data in the wake of a cyber event. This role sits at the intersection of infrastructure engineering, cybersecurity, and regulatory compliance within a highly regulated financial services environment.
The successful candidate has direct experience operating within financial institution recovery programs, engaging with banking regulators (OCC, FDIC, Client, or equivalent), and executing recovery exercises within isolated recovery environments (IRE) and clean room configurations.
Required Qualifications (Must Have):- 10+ years of infrastructure, platform, or resilience engineering experience, with at least 4 years in a financial institution (bank, broker‑dealer, asset manager, or equivalent regulated entity).
- Demonstrated hands‑on experience implementing and testing cyber recovery in an Isolated Recovery Environment (IRE) or clean room
— not just DR/BC planning. - Direct experience engaging with financial regulators (OCC, FDIC, Client, NYDFS, SEC, or Client) in the context of technology examinations or regulatory responses.
- Proficiency with enterprise backup and replication platforms:
Cohesity, Rubrik, Zerto, Veeam, Commvault, or Net Backup. - Working knowledge of IaC tooling (Terraform, Ansible) and scripting (Python, Bash, Power Shell) for recovery automation.
- Strong understanding of network segmentation, identity isolation, and zero‑trust concepts as applied to clean room environments.
- Familiarity with ransomware TTPs, destructive malware incident response, and forensic triage in a recovery context.
- Experience with FFIEC guidance, NIST CSF, and/or DORA requirements as they pertain to operational resilience and recovery.
- Experience in a GSIB, SIFI, or Category I–III bank with heightened regulatory scrutiny.
- Certifications:
CISSP, CISA, AWS/Azure Disaster Recovery specialty, or vendor‑specific backup platform certifications. - Exposure to DORA (Digital Operational Resilience Act) implementation for EU‑facing operations.
- Familiarity with SWIFT, Fed Wire, or CHIPS recovery considerations for payment system continuity.
- Experience with cyber recovery in hybrid cloud environments (AWS, Azure, or GCP) including cloud‑based IRE architectures.
- Background in incident response or cyber threat intelligence with a recovery engineering lens.
Isolated & Clean Room Recovery
- Design, build, and maintain the Isolated Recovery Environment (IRE) and clean room infrastructure used for cyber recovery exercises and declared events.
- Execute end‑to‑end recovery testing cycles, validating RTOs and RPOs for Tier‑1 and Tier‑2 critical applications.
- Develop and maintain recovery runbooks, playbooks, and automation scripts for clean room restoration of core banking systems, trading platforms, and data stores.
- Lead technical forensic validation procedures within the IRE to confirm system integrity prior to production re‑entry.
- Serve as a subject matter expert during regulatory examinations, audits, and inquiry responses related to cyber recovery posture (e.g., OCC, FDIC, FFIEC, Client, NYDFS).
- Translate regulatory guidance (FFIEC Cybersecurity Assessment Tool, NIST CSF, SR 20‑24, DORA where applicable) into actionable recovery engineering requirements.
- Prepare evidence packages, technical narratives, and examination artifacts that demonstrate recovery capability maturity.
- Maintain continuous documentation of control effectiveness, test results, and remediation tracking aligned to regulatory expectations.
- Architect and operate air‑gapped or logically isolated backup and replication pipelines using immutable storage technologies (e.g., Zerto, Cohesity, Rubrik, Net Backup, Veeam).
- Engineer network segmentation and identity isolation controls within the IRE to prevent lateral movement and re‑infection risk during recovery.
- Integrate recovery…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).