Sr. Remediation Specialist (AIR)

LevelBlue LLC
$125,000 - $165,000Hybrid

About The Position

The Principal Remediation Specialist is a senior level position with the scope to develop and grow the restoration capability within the AIR practice. The primary goal of each engagement is to recover our clients to an operating capacity post incident.

Requirements

  • More than 10 years in IT / Network / Cloud Engineering roles
  • Leading enterprise recovery type projects
  • Disaster Recovery planning
  • VMware/Hyper-V, AWS/Azure/GCP recovery
  • IaC – Infrastructure as Code (Terraform, Ansible)
  • Network Recovery SME
  • Veeam, Commvault, Rubrik, Cohesity
  • Cloud Recovery SME
  • Cloud/SaaS admin
  • AWS/Azure Security Engineer
  • VMware vSphere, Hyper-V, AWS Backup, Azure Site Recovery
  • Veeam, Commvault, Rubrik, Cohesity, Zerto
  • Immutable storage: S3 Object Lock, Wasabi Immutable, Dell Data Domain
  • Firewalls: Palo Alto, Cisco ASA/FTD, SonicWall, Watchguard
  • Monitoring: SolarWinds, NetFlow analyzers, Wireshark
  • Segmentation: VLANs, Illumio, Guardicore
  • EDR/XDR: CrowdStrike, Defender ATP, SentinelOne
  • RMM: Screen Connect, Kaseya, NinjaOne
  • MDM: Intune, JAMF, Workspace ONE
  • Imaging: MDT, Clonezilla, Acronis
  • AWS/Azure/GCP recovery playbooks
  • SaaS backup: Spanning, Druva, AvePoint
  • IAM monitoring: CloudTrail, Azure Sentinel
  • Project Management: Connectwise, AutoTask, Atera
  • Secure comms: Signal, MS Teams with eDiscovery
  • Crisis platforms: xMatters, Everbridge
  • Documentation: Confluence, SharePoint, ServiceNow
  • Red/Yellow/Green segmented environments
  • Sandbox for malware testing: Cuckoo, AnyRun
  • Cyber range and tabletop testing platforms
  • Relevant academic degree
  • CISM or CISSP (or a commitment to obtain within 12 months)
  • GCWN, ITIL, DRII Certified
  • CCNP Security, PCNSE, GCIA
  • Microsoft 365 Certified, JAMF, Security+
  • Veeam Certified, GEBR
  • CCSP, CCSK
  • A high school diploma or equivalent is required

Nice To Haves

  • A college or university degree is a plus.

Responsibilities

  • Support the development of bids / proposals associated with the opportunities identified usually from our Digital Forensics and Incident Response practice.
  • Work clients and our sales teams with the generation of SOWs.
  • Deployment of client-side data and log collection solutions
  • Assist with forensic collection requests
  • Install Remote Monitoring and Management (“RMM”) utility and/or establish VPN credentials for remote access
  • Deployment of Forensic tools e.g. (SentinelOne / Velociraptor)
  • Develop shared inventory tracking document
  • Technical engineering efforts to remove the threat actors
  • Acquire third party products and services necessary to remove the threat actors and rebuild, recover, stabilize, and secure the Customer systems and environments
  • Block IOCs within network firewalls as provided by forensics provider
  • Perform impact assessment of servers to determine viability in cooperation with forensics provider
  • Rebuild, recover, stabilize, and secure systems
  • Restoration/ rebuild/ decryption of servers
  • AD Health review and rebuild
  • Domain controller rebuilds and AD hardening
  • Configure segregated networks
  • Hypervisor configurations
  • LAPS (Local Administrator Password Solution) configuration
  • Troubleshooting, impact to and recovery options for Exchange
  • Remote site Firewall Firmware update assistance
  • Work with Company, Customer’s General Counsel, Customer’s insurance carrier, and any applicable third parties

Benefits

  • Comprehensive medical, dental, and vision insurance.
  • 401(k) with employer matching.
  • Generous paid time off and holidays.
  • Flexible spending accounts and health savings accounts.
  • Employee assistance programs.
  • Training and development opportunities.
  • Adoption assistance program.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service