Incident Response - Recovery Specialist in London
Incident Response - Recovery Specialist

Incident Response - Recovery Specialist in London

London Full-Time 45000 - 55000 ÂŁ / year (est.) Home office (partial)
C

At a Glance

  • Tasks: Help clients recover from cyber incidents and restore critical services.
  • Company: Join CYFOR, a leading provider of cyber security services.
  • Benefits: Competitive salary, training, remote work, and fun perks like Netflix subscriptions.
  • Other info: Flexible work environment with excellent career growth opportunities.
  • Why this job: Make a real impact in cyber security while developing your skills.
  • Qualifications: Experience in infrastructure or cloud engineering; strong technical skills required.

The predicted salary is between 45000 - 55000 ÂŁ per year.

CYFOR is a leading nationwide provider of cyber security services, digital forensics and eDiscovery. We support clients across a wide range of sectors, including law firms, insurance providers and law enforcement agencies. As our cyber security services continue to grow, we are looking for talented technical specialists who can make a meaningful impact for our clients.

The Role

We are looking for an experienced Incident Response - Recovery Specialist to join our incident response team. This is a hands‑on technical role focused on helping clients recover from cyber incidents, restore critical services, rebuild infrastructure where necessary, and return to business‑as‑usual as safely and efficiently as possible. While the role is primarily aligned to incident response work, it is not limited to live incidents alone. In addition to supporting clients during recovery engagements, you may also assist with ongoing incident response retainers, recovery readiness activities, backup health and restore assurance, and internal technical improvement projects.

This role is well suited to candidates with strong engineering fundamentals who may already work in, or come from, roles such as Infrastructure Engineer, Cloud Engineer, Platform Engineer, Backup / DR Engineer, or Network Engineer. We recognise that the right person may not come from a pure DFIR background, but will instead bring deep technical experience in designing, rebuilding, securing and supporting business‑critical systems.

Success in this role will depend on your ability to quickly assess unfamiliar environments, ask the right probing questions, work methodically under pressure, and restore key systems even where documentation is limited or unavailable. In some cases, where backups are not viable, you will be expected to help rebuild core systems and services from scratch.

Key Responsibilities

  • Assisting clients with infrastructure remediation, recovery and rebuilds following a cyber incident.
  • Supporting the restoration of critical business services in both on‑premise and cloud environments.
  • Rebuilding key systems from scratch where recovery from backup is not possible or not appropriate.
  • Collaborating with incident response investigators to support containment, remediation and longer‑term resilience.
  • Supporting clients with ongoing incident response retainers and proactive recovery readiness activities between incidents.
  • Monitoring backup health, supporting restore validation, and helping clients improve recovery confidence and resilience.
  • Segmenting infrastructure during a cyber incident to support containment and safe restoration.
  • Collecting and preserving relevant technical evidence, such as firewall, endpoint, authentication and system logs.
  • Supporting Microsoft 365 tenant hardening, Entra / identity recovery, Exchange recovery or migration activities, VMware and Hyper‑V recovery, and firewall rebuilds or rule reviews where required.
  • Automating recovery and administrative tasks using PowerShell and other relevant scripting or command‑line tools.
  • Contributing to internal projects such as automation and tooling, recovery runbooks, backup validation and testing, internal lab development, service improvement initiatives, and internal infrastructure or security projects.
  • Using sound judgement, structured troubleshooting, critical thinking, and appropriate AI‑assisted tooling to improve efficiency, analysis and documentation where suitable.

Essential Skills and Experience

The ideal candidate will have strong practical experience in a number of the following areas:

  • Windows server infrastructure, including Active Directory, Domain Controllers and Exchange.
  • Microsoft 365, Azure and Entra ID.
  • Cloud infrastructure, eg AWS and/or Google Cloud.
  • Backup and recovery technologies, eg Unitrends, Axcient, and Microsoft backup tools.
  • Virtualisation platforms, including VMware and Hyper‑V.
  • Network and security infrastructure, including firewalls, VPNs, switches and core networking concepts.
  • Exposure to endpoint security tooling, similar to SentinelOne, and an understanding of how security tooling supports recovery and remediation.
  • Recovering, rebuilding, migrating or hardening production systems in live business environments.
  • Strong PowerShell and general scripting or command‑line capability.
  • The ability to work through incomplete information, learn environments quickly, and ask effective technical and client‑facing questions.
  • Strong written and verbal communication skills, with the ability to explain technical matters clearly to clients and internal stakeholders.

Desirable Experience

  • Fortinet, SonicWall, Cisco, Meraki, Sophos, and WatchGuard.
  • Additional Microsoft security and cloud technologies relevant to identity, recovery and tenant resilience.
  • Vulnerability scanning, security auditing and general security improvement activity.
  • Recovery planning, resilience testing, and disaster recovery best practices.
  • Experience working in cyber security, incident response, managed service, infrastructure engineering or related technical consulting environments.

Certifications

Candidates should hold, or be working toward, relevant certifications such as CREST or CompTIA Security+. Equivalent technical or cyber security certifications are also welcomed.

Additional Requirements

  • Travel at short notice when required to perform on‑site recovery services.
  • Work primarily remotely, with occasional on‑site engagements depending on client needs.
  • Demonstrate a high level of accuracy, organisation, discretion and confidentiality.
  • Take a flexible and self‑motivated approach to work.
  • Remain calm and professional when supporting clients during high‑pressure incidents.

What You'll Receive

In joining CYFOR, you will receive a salary commensurate with experience, training across cyber security disciplines such as incident response, auditing and forensic investigations, and excellent career prospects within a growing cyber security team. You will also receive:

  • Annual subscriptions from a choice of Netflix, Amazon Prime, Spotify, magazine subscriptions and more.
  • Bupa Cash Plan (or equivalent).
  • CYFOR's statutory pension scheme.
  • An extra day's holiday for your birthday.
  • Loyalty bonuses: 3 years - ÂŁ300, 5 years - ÂŁ500, 10 years - ÂŁ1,000 bonus.

Security Clearance

Please note that this role will require security clearance to SC level. If you do not already hold SC clearance, you will be required to undergo vetting.

Equal Opportunities

As an equal opportunities employer, CYFOR welcomes applicants from all sections of the community regardless of gender, ethnicity, disability, sexual orientation or transgender status. All appointments are made on merit.

Incident Response - Recovery Specialist in London employer: CYFOR

CYFOR is an exceptional employer, offering a dynamic work culture that prioritises employee growth and development within the rapidly evolving field of cyber security. With a focus on meaningful impact, employees benefit from comprehensive training opportunities, competitive salaries, and unique perks such as annual subscriptions to popular services and loyalty bonuses, all while enjoying the flexibility of a remote (hybrid) work environment.
C

Contact Detail:

CYFOR Recruiting Team

StudySmarter Expert Advice 🤫

We think this is how you could land Incident Response - Recovery Specialist in London

✨Tip Number 1

Network like a pro! Reach out to your connections in the cyber security field, attend industry events, and join relevant online forums. The more people you know, the better your chances of landing that Incident Response - Recovery Specialist role.

✨Tip Number 2

Show off your skills! Create a portfolio or a GitHub repository showcasing your projects related to incident response, recovery, and automation. This will give potential employers a taste of what you can bring to the table.

✨Tip Number 3

Prepare for interviews by brushing up on your technical knowledge and soft skills. Practice answering common interview questions and be ready to discuss your experience with specific tools and technologies mentioned in the job description.

✨Tip Number 4

Apply through our website! We make it easy for you to submit your application directly, and it shows you're genuinely interested in joining our team. Plus, you'll get updates on your application status faster!

We think you need these skills to ace Incident Response - Recovery Specialist in London

Incident Response
Infrastructure Remediation
Recovery and Rebuilds
Cloud Environments
Microsoft 365
Azure
PowerShell Scripting
Backup and Recovery Technologies
Virtualisation Platforms
Network Security Infrastructure
Endpoint Security Tooling
Technical Communication Skills
Critical Thinking
Troubleshooting Skills
Disaster Recovery Best Practices

Some tips for your application 🫡

Tailor Your CV: Make sure your CV is tailored to the Incident Response - Recovery Specialist role. Highlight relevant experience and skills that match the job description, especially in areas like infrastructure recovery and cloud technologies.

Craft a Compelling Cover Letter: Your cover letter should tell us why you're the perfect fit for this role. Share specific examples of your past experiences in incident response or recovery, and how they relate to what we do at CYFOR.

Showcase Your Technical Skills: Don’t shy away from showcasing your technical prowess! Mention your experience with tools like PowerShell, backup technologies, and any relevant certifications. We love seeing candidates who can hit the ground running.

Apply Through Our Website: We encourage you to apply through our website for a smoother application process. It helps us keep track of your application and ensures you don’t miss out on any important updates!

How to prepare for a job interview at CYFOR

✨Know Your Tech Inside Out

Make sure you brush up on your technical skills related to Windows server infrastructure, Microsoft 365, and cloud services. Be ready to discuss your hands-on experience with these technologies, as well as any specific tools you've used for backup and recovery.

✨Prepare for Scenario-Based Questions

Expect to face scenario-based questions that test your problem-solving abilities under pressure. Think of examples from your past experiences where you had to recover systems or manage incidents, and be prepared to explain your thought process and actions clearly.

✨Showcase Your Communication Skills

As a Recovery Specialist, you'll need to explain complex technical issues to clients who may not have a technical background. Practice articulating your thoughts clearly and concisely, focusing on how you can help clients understand the recovery process.

✨Demonstrate Your Adaptability

Highlight your ability to work with incomplete information and adapt to new environments quickly. Share examples of how you've successfully navigated challenging situations in the past, especially when documentation was lacking or when you had to rebuild systems from scratch.

Incident Response - Recovery Specialist in London
CYFOR
Location: London

Land your dream job quicker with Premium

You’re marked as a top applicant with our partner companies
Individual CV and cover letter feedback including tailoring to specific job roles
Be among the first applications for new jobs with our AI application
1:1 support and career advice from our career coaches
Go Premium

Money-back if you don't land a job in 6-months

>