Logo
Surefire Cyber Inc.

Principal Consultant, Restoration and Remediation

Surefire Cyber Inc., Elkridge, Maryland, United States, 21075

Save Job

Principal Consultant, Restoration and Remediation Join to apply for the Principal Consultant, Restoration and Remediation role at Surefire Cyber Inc.

About Surefire Cyber Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents such as ransomware, email compromise, malware, data theft, and other threats. Our client-centric approach reduces stress and provides clients the confidence needed to prepare, respond, and recover from cyber incidents – and fortify their cyber resilience after an event.

Surefire Cyber’s approach and delivery are designed by industry veterans who have worked shoulder-to-shoulder with law firms, insurance carriers, brokers, law enforcement, and impacted organizations in responding to cyber incidents. We are marshaling this experience to address the industry’s persistent challenges of efficiency, predictability, and transparency.

Position details

Job Title: Principal, Restoration and Remediation

Location: Remote (USA)

Employment type: Full time

Your Expertise

10+ years of professional experience in cybersecurity, incident response, systems/network administration, or IT infrastructure engineering

Proven leadership in guiding enterprise-scale recovery efforts during cyber incidents, ideally in a client-facing or consulting capacity

Deep hands-on experience with Active Directory, Azure AD, M365, Exchange, Group Policy, virtualization platforms (VMware, Hyper-V, Citrix), and backup tools (e.g., Veeam, Zerto, Unitrends)

Expert understanding of infrastructure reconfiguration, network segmentation, identity access recovery, and endpoint security post-compromise

Ability to architect and execute remediation plans in coordination with DFIR, SOC, and cloud teams

Comfortable advising senior business and legal stakeholders during high-pressure engagements

Strong written and verbal communication skills, including experience preparing and presenting executive-level remediation updates

Demonstrated experience mentoring and growing technical talent within a team

Familiarity with attacker TTPs, threat actor behaviors, and their implications for recovery sequencing and infrastructure redesign

Demonstrated expertise in cybersecurity, systems engineering, or incident response, whether gained through professional experience, certifications, or equivalent technical training

Advanced certifications (e.g., CISSP, GCFA, MCSE, OSCP) are strongly preferred

Note: Expertise in all these areas is not required; we encourage applicants who are eager to learn and collaborate to apply.

How You’ll Make An Impact As a Principal Consultant on the Restoration and Remediation team, you’ll lead Surefire Cyber’s most complex and sensitive post-incident recovery engagements. You’ll advise clients on restoration strategy, coordinate with cross-functional teams, and oversee technical execution across diverse environments. You’ll also help mature Surefire Cyber’s internal R&R capabilities by mentoring consultants, improving playbooks and tooling, and shaping how we scale recovery operations.

Your Role In Action

Lead end-to-end recovery operations for complex cyber incidents, including ransomware outbreaks, large-scale breaches, and targeted compromises

Architect and manage technical remediation plans across hybrid infrastructure (on-prem, cloud, and SaaS), including user recovery, server rebuilds, reconfiguration, and hardening

Oversee restoration of identity services (Active Directory, Azure AD), messaging systems (Exchange, M365), VPNs, firewalls, MFA, and enterprise backup solutions

Advise client executives (CIOs, CISOs, legal, insurers) on remediation strategy, recovery timelines, and long-term resilience improvements

Coordinate recovery workstreams across DFIR, IT, legal, and insurance stakeholders, ensuring alignment and technical integrity

Act as technical escalation point during recovery engagements, solving roadblocks with precision and speed

Mentor senior and junior consultants on real-time client work and long-term development, including technical coaching, feedback, and project guidance

Document and review client-facing technical reports, timelines, and lessons learned to ensure completeness and clarity

Contribute to the evolution of Surefire Cyber’s recovery methodologies, including internal tooling, knowledge bases, and training paths

Lead or support proactive services including tabletop exercises, remediation readiness assessments, and executive advisory engagements

Participate in after-hours response rotations during major incident events (on-call availability expected)

Benefits

Competitive compensation plan and total rewards package for team members

Remote workforce

Generous paid time off plan and floating holidays

Paid parental leave

Employer paid premiums for both team members and their dependents for medical, dental, and vision

Comprehensive health, vision, dental, 401K matching program, disability, Flexible Spending Accounts (FSA), Health Savings Account (HSA), Life and AD&D benefits

Professional development and career advancement opportunities

We prioritize employee growth and development through a robust performance management platform to provide ongoing coaching, clear feedback, recognition, and opportunities for career growth

EEO Surefire Cyber is an Equal Opportunity Employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex, or gender (including pregnancy, childbirth, and pregnancy-related conditions), gender identity or expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, genetic information, or any other characteristic protected by applicable federal, state or local laws and ordinances.

Seniority level

Director

Employment type

Full-time

Job function

Consulting, Information Technology, and Sales

Industries

Computer and Network Security

#J-18808-Ljbffr