Skip to main content
Surefire Cyber

Principal Consultant, Restoration and Remediation

RemoteUnited States only
Published
Role
Security
Experience
Principal
Employment
Full-time
Salary not disclosed
Check eligibility

Open to US only. Set where you work from to check your eligibility.

No BS summary

Principal-level cybersecurity incident response leader for US remote full-time work. Needs 10+ years across cyber incident recovery, enterprise IT infrastructure, Active Directory/Azure AD/M365/Exchange, virtualization, and backup tools. Must be able to lead client-facing post-incident restoration and remediation under pressure.

Core skills

Active DirectoryAzure ADM365

Required skills

ExchangeGroup PolicyVMwareHyper-VCitrixVeeamZertoUnitrends

Optional skills

CISSPGCFAMCSEOSCP

What you'll do

  • Lead end-to-end recovery operations for complex cyber incidents, including ransomware outbreaks, large-scale breaches, and targeted compromises
  • Architect and manage technical remediation plans across hybrid infrastructure, including on-prem, cloud, and SaaS environments, user recovery, server rebuilds, reconfiguration, and hardening
  • Oversee restoration of identity services, messaging systems, VPNs, firewalls, MFA, and enterprise backup solutions
  • Advise client executives on remediation strategy, recovery timelines, and long-term resilience improvements
  • Coordinate recovery workstreams across DFIR, IT, legal, and insurance stakeholders, ensuring alignment and technical integrity
  • Act as technical escalation point during recovery engagements, solving roadblocks with precision and speed
  • Mentor senior and junior consultants on real-time client work and long-term development, including technical coaching, feedback, and project guidance
  • Document and review client-facing technical reports, timelines, and lessons learned to ensure completeness and clarity
  • Contribute to the evolution of Surefire Cyber’s recovery methodologies, including internal tooling, knowledge bases, and training paths
  • Lead or support proactive services including tabletop exercises, remediation readiness assessments, and executive advisory engagements
  • Participate in after-hours response rotations during major incident events

What they require

  • You are a senior technical leader in cybersecurity and incident response, known for restoring order and confidence during high-severity events.
  • You’ve led the full lifecycle of post-incident recovery efforts, from strategic planning and stakeholder advising, to hands-on systems restoration and network reconfiguration.
  • You bring deep technical skills across enterprise IT infrastructure.
  • You have the confidence and clarity to lead clients, coach teammates, and evolve internal capabilities.
  • You thrive in high-pressure environments, take initiative, and are passionate about growing the next generation of cyber responders.
  • 10+ years of professional experience in cybersecurity, incident response, systems/network administration, or IT infrastructure engineering
  • Proven leadership in guiding enterprise-scale recovery efforts during cyber incidents, ideally in a client-facing or consulting capacity
  • Deep hands-on experience with Active Directory, Azure AD, M365, Exchange, Group Policy, virtualization platforms, and backup tools
  • Expert understanding of infrastructure reconfiguration, network segmentation, identity access recovery, and endpoint security post-compromise
  • Ability to architect and execute remediation plans in coordination with DFIR, SOC, and cloud teams
  • Comfortable advising senior business and legal stakeholders during high-pressure engagements
  • Strong written and verbal communication skills, including experience preparing and presenting executive-level remediation updates
  • Demonstrated experience mentoring and growing technical talent within a team
  • Familiarity with attacker TTPs, threat actor behaviors, and their implications for recovery sequencing and infrastructure redesign
  • Demonstrated expertise in cybersecurity, systems engineering, or incident response, whether gained through professional experience, certifications, or equivalent technical training.
  • Preferred: Advanced certifications are strongly preferred.
  • Expertise in all these areas is not required, but you should be excited by the opportunity to learn new things and comfortable with working with other team members to expand your knowledge base and experience.
  • After-hours response rotations during major incident events, with on-call availability expected

Benefits

  • Competitive compensation plan and total rewards package for team members
  • Remote workforce
  • Generous paid time off plan and floating holidays
  • Paid parental leave
  • Employer paid premiums for both team members and their dependents for medical, dental, and vision
  • Comprehensive health, vision, dental, 401K matching program, disability, Flexible Spending Accounts (FSA), Health Savings Account (HSA), Life and AD&D benefits
  • Professional development and career advancement opportunities
  • Employee growth and development through a robust performance management platform to provide ongoing coaching, clear feedback, recognition, and opportunities for career growth

Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents such as ransomware, email compromise, malware, data theft, and other threats.

Cybersecurity

Details

Apply routeGreenhouse
Salary not disclosed