Consultant, Restoration and Remediation (Remote)

Surefire Cyber

India

Remote

INR 8,604,000 - 13,384,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Equity potential
Paid time off
Medical/dental/vision
401K matching
Parental leave
Career development

Job summary

Surefire Cyber is seeking a Consultant for Restoration and Remediation to work remotely in the USA. You will support active incidents, restore systems, and implement remediation strategies with DFIR teams. Strong communication, technical troubleshooting, and experience with AD/Exchange/Policy tools are essential.

The role emphasizes hands-on remediation, 24/7 incident coverage, and collaboration with clients to restore operations and strengthen defenses against future threats.

Qualifications

  • Foundational knowledge of Windows, Linux, and MacOS environments and their security features.
  • Experience with firewalls, VPNs, Active Directory, Group Policy, Exchange, and common endpoint security tools.
  • Strong technical troubleshooting skills and a proactive, team-first attitude.
  • Excellent written and verbal communication skills, with the ability to explain technical concepts to non-technical stakeholders.

Responsibilities

  • Support post-incident recovery efforts, collaborating with DFIR teams to assess the scope and impact of cyber incidents.
  • Participate in restoring compromised systems to a pre-incident state, including data recovery and system hardening.
  • Assist in developing and executing tailored remediation plans based on technical, operational, and regulatory requirements.
  • Reimage, rebuild, and reconfigure endpoints, servers, and services such as Active Directory, Exchange, Group Policy, and VPN.
  • Document all actions taken with clear findings and decisions for knowledge sharing.

Skills

Windows/Linux/macOS basics
Network troubleshooting
Written communication
Verbal communication
Team collaboration

Tools

Active Directory
Group Policy
Exchange
Firewalls
VPNs
Endpoint security tools

Job description

Consultant, Restoration and Remediation (Remote)

Remote


About Surefire Cyber

Surefire Cyber is redefining the incident response model by delivering a swifter, stronger response to cyber incidents such as ransomware, email compromise, malware, data theft, and other threats. Our client-centric approach reduces stress and provides clients the confidence needed to prepare, respond, and recover from cyber incidents – and fortify their cyber resilience after an event.


Surefire Cyber’s approach and delivery are designed by industry veterans who have worked shoulder-to-shoulder with law firms, insurance carriers, brokers, law enforcement, and impacted organizations in responding to cyber incidents. We are marshaling this experience to address the industry’s persistent challenges of efficiency, predictability, and transparency.


Job Title: Consultant, Restoration and Remediation

Location: Remote (USA)

Role: Full time / Exempt

What Makes You Stand Out

You are a systems-savvy problem solver who thrives in fast-paced environments and brings hands-on experience restoring compromised systems and implementing remediation strategies. You’ve worked in roles like IT Engineer, System Administrator, or Cybersecurity Consultant, and now want to apply those skills in a high-stakes, incident response setting.


You’re comfortable collaborating with Digital Forensics and Incident Response (DFIR) teams, diagnosing problems quickly, and supporting clients with empathy and clear communication during urgent cyber events.


How You'll Make an Impact

As a Consultant on the Restoration and Remediation (R&R) team, you’ll contribute technical expertise during active incidents — helping clients recover from ransomware, malware infections, and breaches. You’ll execute remediation tasks, restore systems, and collaborate with forensic analysts to support response efforts. Through meticulous remediation efforts and application of technical expertise, they’ll help clients regain operational stability and strengthen their defenses against future threats


Your Role in Action


  • Support post-incident recovery efforts, collaborating with DFIR teams to assess the scope and impact of cyber incidents

  • Participate in restoring compromised systems to a pre-incident state, including data recovery, system configuration, and hardening

  • Assist in developing and executing tailored remediation plans based on technical, operational, and regulatory requirements

  • Reimage, rebuild, and reconfigure endpoints, servers, and affected services such as Active Directory, Exchange, Group Policy, and VPN

  • Use systems administration skills to restore and configure computing environments

  • Troubleshoot network issues and assist in resolving infrastructure-level connectivity or access problems

  • Contribute to the collection of digital artifacts and forensic evidence, supporting broader incident response

  • Apply foundational knowledge to investigate and address malware infections, unauthorized access, and system integrity issues

  • Implement endpoint protection and access control tools under supervision from senior R&R team members

  • Document all actions taken in a clear, structured format, capturing technical findings, decisions made, and lessons learned

  • Participate in after-hours (on-call/weekend rotational) support when needed to ensure 24/7 incident response coverage


Your Expertise


  • Foundational knowledge of Windows, Linux, and MacOS environments and their security features

  • Experience with firewalls, VPNs, Active Directory, Group Policy, Exchange, and common endpoint security tools

  • Understanding of cyber incident impact, attacker techniques, and indicators of compromise (IOCs)

  • Strong technical troubleshooting skills and a proactive, team-first attitude

  • Excellent written and verbal communication skills, with the ability to explain technical concepts to non-technical stakeholders

  • Ability to manage competing tasks, adapt quickly to changing scenarios, and contribute in high-pressure situations


Expertise in all these areas is not required , but you should be excited by the opportunity to learn new things and comfortable with working with other team members to expand your knowledge base and experience . We at Surefire Cyber invite you to apply even if you do not feel you have mastery in all the requirements listed on the job description and welcome a further discussion .


Interview Process


  • Submit application on our website

  • Preliminary phone interview with the People Team (approx., 30 mins)

  • Virtual/Teams Interview with Restoration Team Members

  • Virtual/Teams interview with hiring leader/Director of R&R (approx., 45 minutes)

  • Virtual/Teams interview with the Chief Deliver Officer

  • Virtual/Team interview with our CEO


#LIRemote


Benefits for Full-Time Surefire Cyber Team Members


  • Competitive compensation plan and equity for all team members

  • Generous paid time off plan and floating holidays

  • Employer paid premiums for both team members and their dependents for medical, dental, and vision

  • Comprehensive health, vision, dental, 401K matching program, disability, Flexible Spending Accounts (FSA), Health Savings Account (HSA), Life and AD&D benefits.

  • Paid parental leave

  • Professional development and career advancement opportunities

  • We prioritize employee growth and development through a robust performance management platform to provide ongoing coaching, clear feedback, recognition, and opportunities for career growth


Surefire Cyber is an Equal Opportunity Employer that does not discriminate on the basis of actual or perceived race, color, creed, religion, national origin, ancestry, citizenship status, age, sex, or gender (including pregnancy, childbirth, and pregnancy-related conditions), gender identity or expression (including transgender status), sexual orientation, marital status, military service and veteran status, physical or mental disability, genetic information, or any other characteristic protected by applicable federal, state or local laws and ordinances.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Incident Response Specialist
Senior Cybersecurity Incident Response Specialist

Metmox • Hyderabad

On-site
INR 2,400,000 - 3,800,000
Senior Security Analyst
Senior Security Analyst

Cyderes • Bengaluru

On-site
INR 1,800,000 - 2,600,000
Medical Insurance - Employee + depend.
Life Insurance
Retirement Match Program
+6
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Cacheflow • Bengaluru

On-site
INR 1,500,000 - 2,200,000
Medical Insurance
Life Insurance
Hybrid Work Model
+2
Senior Consultant, Offensive Security
Senior Consultant, Offensive Security

Cyderes • Bengaluru

Hybrid
INR 1,800,000 - 2,400,000
Medical Insurance
Life Insurance
Hybrid Work Model
+2
HITRUST Certified Consultant
HITRUST Certified Consultant

Clearwater • India

On-site
INR 8,612,000 - 11,483,000
Threat Analyst 2
Threat Analyst 2

Jobgether • India

Remote
INR 1,200,000 - 2,400,000
Remote-first working model
Exposure to wide security technologies
Collaborative security team
+2
Threat Analyst 2
Threat Analyst 2

Sophos • India

Remote
INR 1,500,000 - 2,100,000
Senior Security Analyst-GSOC
Senior Security Analyst-GSOC

Arete Advisors • Hyderabad

On-site
INR 1,800,000 - 2,400,000
Medical/Dental benefits
Life/Disability Insurance
401(k) and retirement benefits
Senior Malware Detection Engineer
Senior Malware Detection Engineer

SentinelOne • India

On-site
INR 2,500,000 - 5,000,000
RSUs
ESPP
Competitive leave benefits
+7
Incident Response Associate
Incident Response Associate

The Depository Trust & Clearing Corporation (DTCC) • Chennai District

On-site
INR 800,000 - 1,200,000
Competitive compensation
Health and life insurance
Pension / retirement benefits
+2