At a Glance
- Tasks: Help clients recover from cyber incidents and restore critical services.
- Company: Join CYFOR, a leading provider of cyber security services.
- Benefits: Competitive salary, training, remote work, and fun perks like Netflix subscriptions.
- Other info: Flexible work culture with excellent career growth opportunities.
- Why this job: Make a real impact in a fast-paced environment while working with cutting-edge technology.
- Qualifications: Experience in infrastructure engineering or related fields; strong technical skills required.
The predicted salary is between 45000 - 55000 ÂŁ per year.
CYFOR is a leading nationwide provider of cyber security services, digital forensics and eDiscovery. We support clients across a wide range of sectors, including law firms, insurance providers and law enforcement agencies. As our cyber security services continue to grow, we are looking for talented technical specialists who can make a meaningful impact for our clients.
At CYFOR, we value people who are passionate about technology, think critically, communicate well and can make a real difference in challenging situations. Our people are what make CYFOR great, and as they grow, so do we.
If you are looking for a varied and highly rewarding technical role, working with great colleagues in a supportive and fast-moving environment, we would like to hear from you.
The Role
We are looking for an experienced Incident Response – Recovery Specialist to join our incident response team. This is a hands‑on technical role focused on helping clients recover from cyber incidents, restore critical services, rebuild infrastructure where necessary, and return to business‑as‑usual as safely and efficiently as possible.
While the role is primarily aligned to incident response work, it is not limited to live incidents alone. In addition to supporting clients during recovery engagements, you may also assist with ongoing incident response retainers, recovery readiness activities, backup health and restore assurance, and internal technical improvement projects.
This role is well suited to candidates with strong engineering fundamentals who may already work in, or come from, roles such as Infrastructure Engineer, Cloud Engineer, Platform Engineer, Backup / DR Engineer, or Network Engineer. We recognise that the right person may not come from a pure DFIR background, but will instead bring deep technical experience in designing, rebuilding, securing and supporting business‑critical systems.
Success in this role will depend on your ability to quickly assess unfamiliar environments, ask the right probing questions, work methodically under pressure, and restore key systems even where documentation is limited or unavailable. In some cases, where backups are not viable, you will be expected to help rebuild core systems and services from scratch.
Key Responsibilities
- Assisting clients with infrastructure remediation, recovery and rebuilds following a cyber incident.
- Supporting the restoration of critical business services in both on‑premise and cloud environments.
- Rebuilding key systems from scratch where recovery from backup is not possible or not appropriate.
- Collaborating with incident response investigators to support containment, remediation and longer‑term resilience.
- Supporting clients with ongoing incident response retainers and proactive recovery readiness activities between incidents.
- Monitoring backup health, supporting restore validation, and helping clients improve recovery confidence and resilience.
- Segmenting infrastructure during a cyber incident to support containment and safe restoration.
- Collecting and preserving relevant technical evidence, such as firewall, endpoint, authentication and system logs.
- Supporting Microsoft 365 tenant hardening, Entra / identity recovery, Exchange recovery or migration activities, VMware and Hyper‑V recovery, and firewall rebuilds or rule reviews where required.
- Automating recovery and administrative tasks using PowerShell and other relevant scripting or command‑line tools.
- Contributing to internal projects such as automation and tooling, recovery runbooks, backup validation and testing, internal lab development, service improvement initiatives, and internal infrastructure or security projects.
- Using sound judgement, structured troubleshooting, critical thinking, and appropriate AI‑assisted tooling to improve efficiency, analysis and documentation where suitable.
Essential Skills and Experience
The ideal candidate will have strong practical experience in a number of the following areas:
- Windows server infrastructure, including Active Directory, Domain Controllers and Exchange.
- Microsoft 365, Azure and Entra ID.
- Cloud infrastructure, eg AWS and/or Google Cloud.
- Backup and recovery technologies, eg Unitrends, Axcient, and Microsoft backup tools.
- Virtualisation platforms, including VMware and Hyper‑V.
- Network and security infrastructure, including firewalls, VPNs, switches and core networking concepts.
- Exposure to endpoint security tooling, similar to SentinelOne, and an understanding of how security tooling supports recovery and remediation.
- Recovering, rebuilding, migrating or hardening production systems in live business environments.
- Strong PowerShell and general scripting or command‑line capability.
- The ability to work through incomplete information, learn environments quickly, and ask effective technical and client‑facing questions.
- Strong written and verbal communication skills, with the ability to explain technical matters clearly to clients and internal stakeholders.
Desirable
Extensive exposure to any of the following technologies or vendors:
- Fortinet, SonicWall, Cisco, Meraki, Sophos, and WatchGuard.
- Additional Microsoft security and cloud technologies relevant to identity, recovery and tenant resilience.
- Vulnerability scanning, security auditing and general security improvement activity.
- Recovery planning, resilience testing, and disaster recovery best practices.
- Experience working in cyber security, incident response, managed service, infrastructure engineering or related technical consulting environments.
Certifications
Candidates should hold, or be working toward, relevant certifications such as CREST or CompTIA Security+. Equivalent technical or cyber security certifications are also welcomed.
Additional Requirements
You will also be expected to:
- Travel at short notice when required to perform on‑site recovery services.
- Work primarily remotely, with occasional on‑site engagements depending on client needs.
- Demonstrate a high level of accuracy, organisation, discretion and confidentiality.
- Take a flexible and self‑motivated approach to work.
- Remain calm and professional when supporting clients during high‑pressure incidents.
What You’ll Receive
In joining CYFOR, you will receive a salary commensurate with experience, training across cyber security disciplines such as incident response, auditing and forensic investigations, and excellent career prospects within a growing cyber security team. You will also receive:
- Annual subscriptions from a choice of Netflix, Amazon Prime, Spotify, magazine subscriptions and more.
- CYFOR’s statutory pension scheme.
- An extra day’s holiday for your birthday.
- Loyalty bonuses: 3 years - ÂŁ300, 5 years - ÂŁ500, 10 years - ÂŁ1,000 bonus.
Security Clearance
Please note that this role will require security clearance to SC level. If you do not already hold SC clearance, you will be required to undergo vetting.
As an equal opportunities employer, CYFOR welcomes applicants from all sections of the community regardless of gender, ethnicity, disability, sexual orientation or transgender status. All appointments are made on merit.
Incident Response Recovery Specialist in London employer: CYFOR group
Contact Detail:
CYFOR group Recruiting Team
StudySmarter Expert Advice 🤫
We think this is how you could land Incident Response Recovery Specialist in London
✨Tip Number 1
Network like a pro! Reach out to your connections in the cyber security field, attend industry events, and join relevant online forums. The more people you know, the better your chances of landing that Incident Response Recovery Specialist role.
✨Tip Number 2
Show off your skills! Create a portfolio or a GitHub repository showcasing your projects, scripts, or any recovery scenarios you've tackled. This gives potential employers a taste of what you can bring to the table.
✨Tip Number 3
Prepare for interviews by brushing up on your technical knowledge and soft skills. Practice answering common incident response questions and think about how you can demonstrate your problem-solving abilities under pressure.
✨Tip Number 4
Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining CYFOR. Tailor your application to highlight your relevant experience and passion for cyber security.
We think you need these skills to ace Incident Response Recovery Specialist in London
Some tips for your application 🫡
Tailor Your CV: Make sure your CV is tailored to the Incident Response Recovery Specialist role. Highlight relevant experience and skills that match the job description, especially your technical expertise in recovery and rebuilding systems.
Craft a Compelling Cover Letter: Your cover letter should tell us why you're passionate about cyber security and how your background makes you a great fit for our team. Use specific examples to demonstrate your problem-solving skills and ability to work under pressure.
Showcase Your Technical Skills: In your application, don’t shy away from showcasing your technical skills. Mention any relevant tools or technologies you've worked with, like PowerShell or cloud infrastructure, as these are key to the role.
Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you’re considered for the role without any hiccups!
How to prepare for a job interview at CYFOR group
✨Know Your Tech Inside Out
Make sure you brush up on your technical knowledge, especially around Windows server infrastructure, Microsoft 365, and cloud environments. Be ready to discuss your hands-on experience with these technologies, as well as any relevant tools you've used for backup and recovery.
✨Prepare for Scenario-Based Questions
Expect to face scenario-based questions that test your problem-solving skills under pressure. Think about past incidents you've handled and be prepared to explain your thought process, the actions you took, and the outcomes. This will show your ability to work methodically in challenging situations.
✨Communicate Clearly and Confidently
Strong communication skills are key in this role. Practice explaining complex technical concepts in simple terms, as you'll need to convey information clearly to clients and team members. Confidence in your delivery can make a big difference during the interview.
✨Show Your Passion for Cyber Security
CYFOR values candidates who are passionate about technology and cyber security. Share your enthusiasm for the field, any relevant projects you've worked on, and how you stay updated with the latest trends and threats. This will help you stand out as a candidate who truly cares about making a difference.