Principal Remediation Specialist

Levelblue, LLC
United States
16 days ago
Apply on www.careerbuilder.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Microsoft Windows Domain Controllers Artificial Intelligence Amazon Web Services Amazon S3 Confluence Microsoft Azure Cisco PIX Software as a Service Cloud Computing Cloud Engineering CompTIA Security+
+45 more
Cyber Security Computer Networks Computer Forensics Data Recovery Desktop Computing Digital Forensics Disaster Recovery Microsoft Exchange Server Firmware Hyper-V Hypervisor Identity and Access Management Internet Security Virtual Private Networks (VPN) Information Systems Security Architecture Professional Microsoft Software Network Configuration and Change Management NetFlow Remote Access Technology Cloud Services Ansible Microsoft SharePoint Software Engineering Technical Data Management Systems Trusted Systems Wireshark Virtual Local Area Networks VMware VSphere Forensic Toolkit Workspace ONE Sonicwall Malware Firewalls (Computer Science) Microsoft InTune Ethereal SolarWinds (Software) Windows Security Casper Suite Veeam Terraform SentinelOne Expertise Commvault Cisco Servicenow Vmware

Job description

The Principal Remediation Specialist is a senior level position with the scope to develop and grow the restoration capability within the AIR practice. The primary goal of each engagement is to recover our clients to an operating capacity post incident.

Key Attributes:

Business Support

  • Support the development of bids / proposals associated with the opportunities identified usually from our Digital Forensics and Incident Response practice.
  • Work clients and our sales teams with the generation of SOWs.

Data Collection / Set-up

  • Deployment of client-side data and log collection solutions
  • Assist with forensic collection requests
  • Install Remote Monitoring and Management (“RMM”) utility and/or establish VPN credentials for remote access
  • Deployment of Forensic tools e.g. (SentinelOne / Velociraptor)
  • Develop shared inventory tracking document

Threat Actor Removal

  • Technical engineering efforts to remove the threat actors
  • Acquire third party products and services necessary to remove the threat actors and rebuild, recover, stabilize, and secure the Customer systems and environments
  • Block IOCs within network firewalls as provided by forensics provider
  • Perform impact assessment of servers to determine viability in cooperation with forensics provider

Environment Re-Build

  • Rebuild, recover, stabilize, and secure systems
  • Restoration/ rebuild/ decryption of servers
  • AD Health review and rebuild
  • Domain controller rebuilds and AD hardening
  • Configure segregated networks
  • Hypervisor configurations
  • LAPS (Local Administrator Password Solution) configuration
  • Troubleshooting, impact to and recovery options for Exchange
  • Remote site Firewall Firmware update assistance

Legal / Comms

  • Work with Company, Customer’s General Counsel, Customer’s insurance carrier, and any applicable third parties

Requirements

Due to the varied nature of client systems; as wide and diverse experience across multiple technologies and solutions is preferable. Typical technologies and solutions include:

Leadership

  • More than 10 years in IT / Network / Cloud Engineering roles
  • Leading enterprise recovery type projects
  • Disaster Recovery planning
  • VMware/Hyper-V, AWS/Azure/GCP recovery
  • IaC - Infrastructure as Code (Terraform, Ansible)

Network Recovery SME

  • Veeam, Commvault, Rubrik, Cohesity

Cloud Recovery SME

  • Cloud/SaaS admin
  • AWS/Azure Security Engineer

Infrastructure & Backup Tools

  • VMware vSphere, Hyper-V, AWS Backup, Azure Site Recovery
  • Veeam, Commvault, Rubrik, Cohesity, Zerto
  • Immutable storage: S3 Object Lock, Wasabi Immutable, Dell Data Domain

Network Tools

  • Firewalls: Palo Alto, Cisco ASA/FTD, SonicWall, Watchguard
  • Monitoring: SolarWinds, NetFlow analyzers, Wireshark
  • Segmentation: VLANs, Illumio, Guardicore

Endpoint Tools

  • EDR/XDR: CrowdStrike, Defender ATP, SentinelOne
  • RMM: Screen Connect, Kaseya, NinjaOne
  • MDM: Intune, JAMF, Workspace ONE
  • Imaging: MDT, Clonezilla, Acronis

Cloud & SaaS Recovery Tools

  • AWS/Azure/GCP recovery playbooks
  • SaaS backup: Spanning, Druva, AvePoint
  • IAM monitoring: CloudTrail, Azure Sentinel

Communication & Coordination Tools

  • Project Management: Connectwise, AutoTask, Atera
  • Secure comms: Signal, MS Teams with eDiscovery
  • Crisis platforms: xMatters, Everbridge
  • Documentation: Confluence, SharePoint, ServiceNow

Testing & Validation Tools

  • Red/Yellow/Green segmented environments
  • Sandbox for malware testing: Cuckoo, AnyRun
  • Cyber range and tabletop testing platforms, * Relevant academic degree
  • CISM or CISSP (or a commitment to obtain within 12 months)
  • GCWN, ITIL, DRII Certified
  • CCNP Security, PCNSE, GCIA
  • Microsoft 365 Certified, JAMF, Security+
  • Veeam Certified, GEBR
  • CCSP, CCSK

Education:

  • A high school diploma or equivalent is required; a college or university degree is a plus., Amazon Simple Storage Service (S3), Amazon Web Services (AWS), Analysis Skills, Ansible, Artificial Intelligence (AI), Business Support, CCNP - Cisco Certified Network Professional, CCSP - Cisco Certified Security Professional, CISM - Certified Information Security Manager, CISSP - Certified Information Systems Security Professional, Cisco ASA (Adaptive Security Appliance), Cloud Computing, CompTIA Security+, Computer Firmware, Computer Forensics, Computer Security, Cryptography, Data Collection, Dell Computers, Dental Insurance, Disaster Recovery, Financial Control, Firewalls, Forensic Science, GCIA - GIAC Certified Intrusion Analyst, GCP (Good Clinical Practices), GCWN - GIAC Certified Windows Security Administrator, Human Intelligence (HUMINT), Hypervisors, Identify Issues, Incident Response, Insurance, Internet Security, Leadership, Malware, Manufacturing Data Management, Microsoft Exchange Server, Microsoft Hyper-V, Microsoft Product Family, Microsoft Windows Azure, Netflow, Network Configuration Management, Project/Program Management, Proposal Development, Protective Services, RMON, Remote Access, Sales, Security Monitoring, Software Engineering, Software as a Service (SaaS), SonicWALL, Statement of Work (SOW), Test Tools, Training/Teaching, VLAN (Virtual Local Area Network), VMWare, VMWare vSphere, VPN (Virtual Private Network), Validation Testing, Vision Plan, Wireshark (Ethereal)

Benefits & conditions

At LevelBlue, you’re not just an employee-you’re part of a team making a real difference in the world of cybersecurity. We foster a culture of innovation and creativity where your contributions are valued, and you’ll have the support and resources to grow and thrive.

Benefits and Perks:

  • Comprehensive medical, dental, and vision insurance.
  • 401(k) with employer matching.
  • Generous paid time off and holidays.
  • Flexible spending accounts and health savings accounts.
  • Employee assistance programs.
  • Training and development opportunities.
  • Adoption assistance program.

About the company

LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services., This role is open to candidates legally authorized to work in the United States. At LevelBlue, we support flexible work and bring people together in person for key moments based on role, team, and business needs.

LevelBlue is committed to a culture of respect, inclusion, and equal opportunity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other status protected under applicable law.

To all agencies: Please do not contact LevelBlue employees outside of the Talent Acquisition team. LevelBlue’s policy is to only accept resumes from agencies through its approved agency process and with a valid agreement in place. Any resume submitted outside this process will be considered the property of LevelBlue, and no fee will be paid if a candidate is hired from such a submission.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerbuilder.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:34 min

Pivoting careers into specialized platform engineering roles

Xavier Portilla Edo · LIVE

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · World Congress 2025

1:29 min

Expanding practical knowledge with community sandboxes and resources

Stuart Clark · LIVE

3:46 min

Navigating a career in cloud transformation consulting

Piet Van Dongen · LIVE

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · World Congress 2024

3:45 min

Prototyping deterministic agents with n8n and PyATS

Alfonso Sandoval Rosas Alfonso Sandoval Rosas · Europe 2026 Virtual

Videos

See all

Related articles

See all