Compromise Recovery Specialist

FULL_TIME On site
DohaQatar

Job Details

Follow
2

16 Aug 2026
Operations
15 Oct 2026
bachelor degree
10 years
QAR 0 - 0

Company Information


Techpace Technology & Software To be discussed

Job Description/Specification:


A Compromise Recovery Specialist plays a critical role in helping organizations recover safely from serious cybersecurity incidents. Based in Doha, this position focuses on containment, remediation, recovery planning, and the secure restoration of business-critical systems following incidents such as ransomware or destructive attacks.

This is a senior-level cybersecurity job in Qatar suited to professionals with extensive infrastructure administration experience and a strong background in incident recovery across on-premises and cloud environments.

Key Responsibilities

The Compromise Recovery Specialist will be responsible for:

  • Responding to cybersecurity incidents and coordinating compromise recovery activities.
  • Developing and implementing recovery strategies for affected systems and services.
  • Containing compromised environments and supporting secure remediation.
  • Restoring business-critical infrastructure, including Tier 0 and Tier 1 assets.
  • Applying proven recovery methodologies to ransomware and destructive cyber incidents.
  • Supporting recovery across on-premises and cloud environments.
  • Applying Zero Trust principles to strengthen security during and after recovery.
  • Identifying business and technical risks within security policies and operational procedures.
  • Recommending appropriate mitigations, solutions, and contingency measures.
  • Developing and improving documentation, procedures, and research related to compromise recovery.
  • Working with Microsoft security technologies and other enterprise cybersecurity solutions.

Requirements

Candidates should ideally have:

  • A bachelor's degree in Computer Science, Information Technology, Engineering, or a related discipline.
  • Previous experience working in compromise recovery or a closely related cybersecurity function.
  • At least 10 years of experience in system, network, storage, and backup administration.
  • At least 10 years of practical experience in cybersecurity containment, remediation, and recovery.
  • Experience handling incidents across on-premises and cloud environments.
  • Demonstrated experience recovering critical systems following ransomware or destructive cyber incidents.
  • Strong understanding of risk identification, mitigation, and contingency planning.
  • Experience developing security documentation and recovery procedures.
  • Deep knowledge of Microsoft security technologies, including Active Directory, Entra ID, and Microsoft Defender.
  • Familiarity with other established enterprise security solutions.

Why You'll Love This Opportunity

  • Work on high-impact cybersecurity recovery challenges.
  • Apply advanced infrastructure and security knowledge to business-critical environments.
  • Gain experience across both cloud and on-premises systems.
  • Work with modern Microsoft security technologies.
  • Contribute to strengthening an organization's resilience against major cyber incidents.

Who Should Apply?

This is not an entry-level cybersecurity position. It is designed for a highly experienced infrastructure and security professional who has dealt with complex systems and understands what is required to safely restore an organization after a serious compromise.

Candidates should be comfortable operating under pressure and making technically sound decisions when systems are unavailable and business continuity is at risk.

A background combining infrastructure administration, backup and recovery, cybersecurity incident response, and identity security would be particularly relevant.

Skills That Will Help You Succeed

The role requires a combination of deep technical knowledge and structured incident-recovery thinking.

Strong understanding of Active Directory, Entra ID, Microsoft Defender, backup infrastructure, storage, networking, and system administration will be valuable.

You should also understand how to separate compromised assets, establish trustworthy recovery points, validate systems before restoration, and reduce the possibility of reinfection.

Communication and documentation skills are equally important because recovery activities often involve infrastructure, security, management, and business continuity teams.

How to Stand Out

Your CV should demonstrate specific experience with major cybersecurity incidents and recovery projects rather than simply listing security technologies.

Highlight ransomware recovery, destructive attack response, restoration of critical services, cloud recovery, identity remediation, or large-scale infrastructure recovery projects.

Where possible, quantify the scale of your work—for example, the number of systems restored, size of the environment, critical services recovered, or recovery improvements achieved.

Clearly list your relevant Microsoft certifications, particularly SC-300, SC-100, AZ-104, and Azure Solutions Architect certifications where applicable.

Interview Preparation

Expect technical and scenario-based questions such as:

  • How would you approach recovery following a ransomware incident?
  • How would you determine which systems should be restored first?
  • What steps would you take before reconnecting recovered Active Directory infrastructure?
  • How can Zero Trust principles support compromise recovery?
  • How would you identify a trustworthy recovery point?
  • How would you handle recovery when backups may also have been compromised?

Prepare examples demonstrating your ability to contain, investigate, remediate, recover, and document complex incidents.

Career Growth

Experience in compromise recovery can lead toward senior positions such as Cybersecurity Incident Response Manager, Cyber Recovery Lead, Security Architect, Infrastructure Security Manager, Cyber Resilience Manager, or Cybersecurity Director.

Frequently Asked Questions

How much experience is required?
The role requires 10+ years of experience in infrastructure administration and 10+ years of applied cybersecurity containment, remediation, and recovery experience.

Is this an infrastructure or cybersecurity role?
It combines both. Strong infrastructure knowledge is essential because the role involves recovering systems, networks, storage, backups, and critical services after security incidents.

Are Microsoft skills important?
Yes. Strong knowledge of Active Directory, Entra ID, Microsoft Defender, and related Microsoft security technologies is specifically required.

Are certifications required?
The requirements call for at least three certifications from the listed Microsoft certification areas.

Is this suitable for junior cybersecurity professionals?
No. The extensive experience requirements make this a senior specialist position.

My Saved Jobs

Submit Application


Apply via Link

Share this job
Follow