Incident Response - Recovery Specialist

Incident Response - Recovery Specialist

Full-Time 45000 - 55000 £ / year (est.) No working from home possible
C

At a Glance

  • Tasks: Help clients recover from cyber incidents and restore critical services.
  • Company: Join CYFOR, a leading provider of cyber security services.
  • Benefits: Competitive salary, training, remote work, and fun perks like Netflix subscriptions.
  • Other info: Flexible remote work with opportunities for career growth.
  • Why this job: Make a real impact in cyber security while developing your skills.
  • Qualifications: Experience in infrastructure, cloud, or network engineering is a plus.

The predicted salary is between 45000 - 55000 £ per year.

CYFOR is a leading nationwide provider of cyber security services, digital forensics and eDiscovery. We support clients across a wide range of sectors, including law firms, insurance providers and law enforcement agencies. As our cyber security services continue to grow, we are looking for talented technical specialists who can make a meaningful impact for our clients.

The Role

We are looking for an experienced Incident Response - Recovery Specialist to join our incident response team. This is a hands‑on technical role focused on helping clients recover from cyber incidents, restore critical services, rebuild infrastructure where necessary, and return to business‑as‑usual as safely and efficiently as possible. While the role is primarily aligned to incident response work, it is not limited to live incidents alone. In addition to supporting clients during recovery engagements, you may also assist with ongoing incident response retainers, recovery readiness activities, backup health and restore assurance, and internal technical improvement projects. This role is well suited to candidates with strong engineering fundamentals who may already work in, or come from, roles such as Infrastructure Engineer, Cloud Engineer, Platform Engineer, Backup / DR Engineer, or Network Engineer. We recognise that the right person may not come from a pure DFIR background, but will instead bring deep technical experience in designing, rebuilding, securing and supporting business‑critical systems. Success in this role will depend on your ability to quickly assess unfamiliar environments, ask the right probing questions, work methodically under pressure, and restore key systems even where documentation is limited or unavailable. In some cases, where backups are not viable, you will be expected to help rebuild core systems and services from scratch.

Key Responsibilities

  • Assisting clients with infrastructure remediation, recovery and rebuilds following a cyber incident.
  • Supporting the restoration of critical business services in both on‑premise and cloud environments.
  • Rebuilding key systems from scratch where recovery from backup is not possible or not appropriate.
  • Collaborating with incident response investigators to support containment, remediation and longer‑term resilience.
  • Supporting clients with ongoing incident response retainers and proactive recovery readiness activities between incidents.
  • Monitoring backup health, supporting restore validation, and helping clients improve recovery confidence and resilience.
  • Segmenting infrastructure during a cyber incident to support containment and safe restoration.
  • Collecting and preserving relevant technical evidence, such as firewall, endpoint, authentication and system logs.
  • Supporting Microsoft 365 tenant hardening, Entra / identity recovery, Exchange recovery or migration activities, VMware and Hyper‑V recovery, and firewall rebuilds or rule reviews where required.
  • Automating recovery and administrative tasks using PowerShell and other relevant scripting or command‑line tools.
  • Contributing to internal projects such as automation and tooling, recovery runbooks, backup validation and testing, internal lab development, service improvement initiatives, and internal infrastructure or security projects.
  • Using sound judgement, structured troubleshooting, critical thinking, and appropriate AI‑assisted tooling to improve efficiency, analysis and documentation where suitable.

Essential Skills and Experience

The ideal candidate will have strong practical experience in a number of the following areas:

  • Windows server infrastructure, including Active Directory, Domain Controllers and Exchange.
  • Microsoft 365, Azure and Entra ID.
  • Cloud infrastructure, eg AWS and/or Google Cloud.
  • Backup and recovery technologies, eg Unitrends, Axcient, and Microsoft backup tools.
  • Virtualisation platforms, including VMware and Hyper‑V.
  • Network and security infrastructure, including firewalls, VPNs, switches and core networking concepts.
  • Exposure to endpoint security tooling, similar to SentinelOne, and an understanding of how security tooling supports recovery and remediation.
  • Recovering, rebuilding, migrating or hardening production systems in live business environments.
  • Strong PowerShell and general scripting or command‑line capability.
  • The ability to work through incomplete information, learn environments quickly, and ask effective technical and client‑facing questions.
  • Strong written and verbal communication skills, with the ability to explain technical matters clearly to clients and internal stakeholders.

Desirable Experience

  • Fortinet, SonicWall, Cisco, Meraki, Sophos, and WatchGuard.
  • Additional Microsoft security and cloud technologies relevant to identity, recovery and tenant resilience.
  • Vulnerability scanning, security auditing and general security improvement activity.
  • Recovery planning, resilience testing, and disaster recovery best practices.
  • Experience working in cyber security, incident response, managed service, infrastructure engineering or related technical consulting environments.

Certifications

Candidates should hold, or be working toward, relevant certifications such as CREST or CompTIA Security+. Equivalent technical or cyber security certifications are also welcomed.

Additional Requirements

  • Travel at short notice when required to perform on‑site recovery services.
  • Work primarily remotely, with occasional on‑site engagements depending on client needs.
  • Demonstrate a high level of accuracy, organisation, discretion and confidentiality.
  • Take a flexible and self‑motivated approach to work.
  • Remain calm and professional when supporting clients during high‑pressure incidents.

What You'll Receive

In joining CYFOR, you will receive a salary commensurate with experience, training across cyber security disciplines such as incident response, auditing and forensic investigations, and excellent career prospects within a growing cyber security team. You will also receive:

  • Annual subscriptions from a choice of Netflix, Amazon Prime, Spotify, magazine subscriptions and more.
  • Bupa Cash Plan (or equivalent).
  • CYFOR's statutory pension scheme.
  • An extra day's holiday for your birthday.
  • Loyalty bonuses: 3 years - £300, 5 years - £500, 10 years - £1,000 bonus.

Security Clearance

Please note that this role will require security clearance to SC level. If you do not already hold SC clearance, you will be required to undergo vetting.

Equal Opportunities

As an equal opportunities employer, CYFOR welcomes applicants from all sections of the community regardless of gender, ethnicity, disability, sexual orientation or transgender status. All appointments are made on merit.

Incident Response - Recovery Specialist employer: CYFOR

At CYFOR, we pride ourselves on being a leading provider of cyber security services, offering a dynamic and supportive work environment that fosters professional growth and innovation. Our remote (hybrid) work model allows for flexibility while you engage in meaningful projects that directly impact our clients' recovery from cyber incidents. With competitive salaries, comprehensive training opportunities, and unique benefits like loyalty bonuses and subscriptions to popular services, CYFOR is committed to nurturing talent and ensuring a rewarding career path for our employees.

C

Contact Details:

CYFOR Recruitment Team

StudySmarter Expert Advice🤫

We think this is how you could land Incident Response - Recovery Specialist

Tip Number 1

Network like a pro! Reach out to your connections in the cyber security field, attend industry events, and join relevant online forums. The more people you know, the better your chances of landing that Incident Response - Recovery Specialist role.

Tip Number 2

Show off your skills! Create a portfolio or a GitHub repository showcasing your projects related to incident response, recovery, and automation. This will give potential employers a taste of what you can bring to the table.

Tip Number 3

Prepare for interviews by brushing up on your technical knowledge and soft skills. Practice answering common interview questions and be ready to discuss your experience with tools like PowerShell, Azure, and backup technologies. Confidence is key!

Tip Number 4

Don't forget to apply through our website! We love seeing candidates who are genuinely interested in joining CYFOR. Tailor your application to highlight how your skills align with the Incident Response - Recovery Specialist role and make sure to follow up after applying.

We think you need these skills to ace Incident Response - Recovery Specialist

Incident Response
Recovery and Rebuilds
Infrastructure Remediation
Cloud Environments
Microsoft 365
Azure
Backup and Recovery Technologies

Some tips for your application 🫡

Tailor Your CV:Make sure your CV is tailored to the Incident Response - Recovery Specialist role. Highlight relevant experience and skills that match the job description, especially in areas like infrastructure recovery and cloud technologies.

Craft a Compelling Cover Letter:Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of your past experiences in incident response or recovery, and how they relate to what we do at CYFOR.

Showcase Your Technical Skills:Don’t shy away from showcasing your technical prowess! Mention your experience with tools like PowerShell, backup technologies, and any relevant certifications. We love seeing candidates who can hit the ground running.

Apply Through Our Website:We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates from us!

How to prepare for a job interview at CYFOR

Know Your Tech Inside Out

Make sure you brush up on your technical knowledge, especially around Windows server infrastructure, Microsoft 365, and cloud services like AWS or Google Cloud. Be ready to discuss your hands-on experience with these technologies, as they'll likely come up during the interview.

Prepare for Scenario-Based Questions

Expect to face scenario-based questions that test your problem-solving skills under pressure. Think of examples from your past experiences where you've had to recover systems or manage incidents, and be prepared to explain your thought process and actions clearly.

Showcase Your Communication Skills

Since you'll be working closely with clients, it's crucial to demonstrate your ability to communicate complex technical concepts in a simple way. Practice explaining your previous projects or technical challenges to someone without a tech background to ensure you're clear and concise.

Ask Insightful Questions

At the end of the interview, don’t forget to ask insightful questions about the company's incident response processes or their approach to client recovery. This shows your genuine interest in the role and helps you gauge if the company is the right fit for you.