Principal Remediation Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+45 more
Job description
The Principal Remediation Specialist is a senior level position with the scope to develop and grow the restoration capability within the AIR practice. The primary goal of each engagement is to recover our clients to an operating capacity post incident.
Key Attributes:
Business Support
- Support the development of bids / proposals associated with the opportunities identified usually from our Digital Forensics and Incident Response practice.
- Work clients and our sales teams with the generation of SOWs.
Data Collection / Set-up
- Deployment of client-side data and log collection solutions
- Assist with forensic collection requests
- Install Remote Monitoring and Management (“RMM”) utility and/or establish VPN credentials for remote access
- Deployment of Forensic tools e.g. (SentinelOne / Velociraptor)
- Develop shared inventory tracking document
Threat Actor Removal
- Technical engineering efforts to remove the threat actors
- Acquire third party products and services necessary to remove the threat actors and rebuild, recover, stabilize, and secure the Customer systems and environments
- Block IOCs within network firewalls as provided by forensics provider
- Perform impact assessment of servers to determine viability in cooperation with forensics provider
Environment Re-Build
- Rebuild, recover, stabilize, and secure systems
- Restoration/ rebuild/ decryption of servers
- AD Health review and rebuild
- Domain controller rebuilds and AD hardening
- Configure segregated networks
- Hypervisor configurations
- LAPS (Local Administrator Password Solution) configuration
- Troubleshooting, impact to and recovery options for Exchange
- Remote site Firewall Firmware update assistance
Legal / Comms
- Work with Company, Customer’s General Counsel, Customer’s insurance carrier, and any applicable third parties
Requirements
Due to the varied nature of client systems; as wide and diverse experience across multiple technologies and solutions is preferable. Typical technologies and solutions include:
Leadership
- More than 10 years in IT / Network / Cloud Engineering roles
- Leading enterprise recovery type projects
- Disaster Recovery planning
- VMware/Hyper-V, AWS/Azure/GCP recovery
- IaC - Infrastructure as Code (Terraform, Ansible)
Network Recovery SME
- Veeam, Commvault, Rubrik, Cohesity
Cloud Recovery SME
- Cloud/SaaS admin
- AWS/Azure Security Engineer
Infrastructure & Backup Tools
- VMware vSphere, Hyper-V, AWS Backup, Azure Site Recovery
- Veeam, Commvault, Rubrik, Cohesity, Zerto
- Immutable storage: S3 Object Lock, Wasabi Immutable, Dell Data Domain
Network Tools
- Firewalls: Palo Alto, Cisco ASA/FTD, SonicWall, Watchguard
- Monitoring: SolarWinds, NetFlow analyzers, Wireshark
- Segmentation: VLANs, Illumio, Guardicore
Endpoint Tools
- EDR/XDR: CrowdStrike, Defender ATP, SentinelOne
- RMM: Screen Connect, Kaseya, NinjaOne
- MDM: Intune, JAMF, Workspace ONE
- Imaging: MDT, Clonezilla, Acronis
Cloud & SaaS Recovery Tools
- AWS/Azure/GCP recovery playbooks
- SaaS backup: Spanning, Druva, AvePoint
- IAM monitoring: CloudTrail, Azure Sentinel
Communication & Coordination Tools
- Project Management: Connectwise, AutoTask, Atera
- Secure comms: Signal, MS Teams with eDiscovery
- Crisis platforms: xMatters, Everbridge
- Documentation: Confluence, SharePoint, ServiceNow
Testing & Validation Tools
- Red/Yellow/Green segmented environments
- Sandbox for malware testing: Cuckoo, AnyRun
- Cyber range and tabletop testing platforms, * Relevant academic degree
- CISM or CISSP (or a commitment to obtain within 12 months)
- GCWN, ITIL, DRII Certified
- CCNP Security, PCNSE, GCIA
- Microsoft 365 Certified, JAMF, Security+
- Veeam Certified, GEBR
- CCSP, CCSK
Education:
- A high school diploma or equivalent is required; a college or university degree is a plus., Amazon Simple Storage Service (S3), Amazon Web Services (AWS), Analysis Skills, Ansible, Artificial Intelligence (AI), Business Support, CCNP - Cisco Certified Network Professional, CCSP - Cisco Certified Security Professional, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cisco ASA (Adaptive Security Appliance), Cloud Computing, CompTIA Security+, Computer Firmware, Computer Forensics, Computer Security, Cryptography, Data Collection, Dell Computers, Dental Insurance, Disaster Recovery, Financial Control, Firewalls, Forensic Science, GCIA - GIAC Certified Intrusion Analyst, GCP (Good Clinical Practices), GCWN - GIAC Certified Windows Security Administrator, Human Intelligence (HUMINT), Hypervisors, Identify Issues, Incident Response, Insurance, Internet Security, Leadership, Malware, Manufacturing Data Management, Microsoft Exchange Server, Microsoft Hyper-V, Microsoft Product Family, Microsoft Windows Azure, Netflow, Network Configuration Management, Project/Program Management, Proposal Development, Protective Services, RMON, Remote Access, Sales, Security Monitoring, Software Engineering, Software as a Service (SaaS), SonicWALL, Statement of Work (SOW), Test Tools, Training/Teaching, VLAN (Virtual Local Area Network), VMWare, VMWare vSphere, VPN (Virtual Private Network), Validation Testing, Vision Plan, Wireshark (Ethereal)
Benefits & conditions
At LevelBlue, you’re not just an employee-you’re part of a team making a real difference in the world of cybersecurity. We foster a culture of innovation and creativity where your contributions are valued, and you’ll have the support and resources to grow and thrive.
Benefits and Perks:
- Comprehensive medical, dental, and vision insurance.
- 401(k) with employer matching.
- Generous paid time off and holidays.
- Flexible spending accounts and health savings accounts.
- Employee assistance programs.
- Training and development opportunities.
- Adoption assistance program.
About the company
LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services., This role is open to candidates legally authorized to work in the United States. At LevelBlue, we support flexible work and bring people together in person for key moments based on role, team, and business needs.
LevelBlue is committed to a culture of respect, inclusion, and equal opportunity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other status protected under applicable law.
To all agencies: Please do not contact LevelBlue employees outside of the Talent Acquisition team. LevelBlue’s policy is to only accept resumes from agencies through its approved agency process and with a valid agreement in place. Any resume submitted outside this process will be considered the property of LevelBlue, and no fee will be paid if a candidate is hired from such a submission.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
Dev Digest 134 - Where pixels sing?
Why Upskilling And Reskilling is Important For Developers
Best Coding Boot Camps in Germany