Jobs and Careers
LE

Sr. Remediation Specialist (AIR)

LevelBlue
United States, United Statesfull_timeVerifiedPosted 6 Aug 2026
💰 $165,000/yr($125,000/yr$165,000/yr)

About the role

LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services.
Role Expectations:
The Principal Remediation Specialist is a senior level position with the scope to develop and grow the restoration capability within the AIR practice. The primary goal of each engagement is to recover our clients to an operating capacity post incident.

Key Attributes:
Business Support
• Support the development of bids / proposals associated with the opportunities identified usually from our Digital Forensics and Incident Response practice.
• Work clients and our sales teams with the generation of SOWs.
Data Collection / Set-up
• Deployment of client-side data and log collection solutions
• Assist with forensic collection requests
• Install Remote Monitoring and Management (“RMM”) utility and/or establish VPN credentials for remote access
• Deployment of Forensic tools e.g. (SentinelOne / Velociraptor)
• Develop shared inventory tracking document
Threat Actor Removal
• Technical engineering efforts to remove the threat actors
• Acquire third party products and services necessary to remove the threat actors and rebuild, recover, stabilize, and secure the Customer systems and environments
• Block IOCs within network firewalls as provided by forensics provider
• Perform impact assessment of servers to determine viability in cooperation with forensics provider
Environment Re-Build
• Rebuild, recover, stabilize, and secure systems
• Restoration/ rebuild/ decryption of servers
• AD Health review and rebuild
• Domain controller rebuilds and AD hardening
• Configure segregated networks
• Hypervisor configurations
• LAPS (Local Administrator Password Solution) configuration
• Troubleshooting, impact to and recovery options for Exchange
• Remote site Firewall Firmware update assistance
Legal / Comms
• Work with Company, Customer’s General Counsel, Customer’s insurance carrier, and any applicable third parties
Desired Experience:
Due to the varied nature of client systems; as wide and diverse experience across multiple technologies and solutions is preferable. Typical technologies and solutions include:
Leadership
• More than 10 years in IT / Network / Cloud Engineering roles
• Leading enterprise recovery type projects
• Disaster Recovery planning
• VMware/Hyper-V, AWS/Azure/GCP recovery
• IaC – Infrastructure as Code (Terraform, Ansible)
Network Recovery SME
• Veeam, Commvault, Rubrik, Cohesity
Cloud Recovery SME
• Cloud/SaaS admin
• AWS/Azure Security Engineer
Infrastructure & Backup Tools
• VMware vSphere, Hyper-V, AWS Backup, Azure Site Recovery
• Veeam, Commvault, Rubrik, Cohesity, Zerto
• Immutable storage: S3 Object Lock, Wasabi Immutable, Dell Data Domain
Network Tools
• Firewalls: Palo Alto, Cisco ASA/FTD, SonicWall, Watchguard
• Monitoring: SolarWinds, NetFlow analyzers, Wireshark
• Segmentation: VLANs, Illumio, Guardicore
Endpoint Tools
• EDR/XDR: CrowdStrike, Defender ATP, SentinelOne
• RMM: Screen Connect, Kaseya, NinjaOne
• MDM: Intune, JAMF, Workspace ONE
• Imaging: MDT, Clonezilla, Acronis
Cloud & SaaS Recovery Tools
• AWS/Azure/GCP recovery playbooks
• SaaS backup: Spanning, Druva, AvePoint
• IAM monitoring: CloudTrail, Azure Sentinel
Communication & Coordination Tools
• Project Management: Connectwise, AutoTask, Atera
• Secure comms: Signal, MS Teams with eDiscovery
• Crisis platforms: xMatters, Everbridge
• Documentation: Confluence, SharePoint, ServiceNow
Testing & Validation Tools
• Red/Yellow/Green segmented environments
• Sandbox for malware testing: Cuckoo, AnyRun
• Cyber range and tabletop testing platforms
Qualifications:
• Relevant academic degree
• CISM or CISSP (or a commitment to obtain within 12 months)
• GCWN, ITIL, DRII Certified
• CCNP Security, PCNSE, GCIA
• Microsoft 365 Certified, JAMF, Security+
• Veeam Certified, GEBR
• CCSP, CCSK
Education:
• A high school diploma or equivalent is required; a college or university degree is a plus.
Why Join LevelBlue?
At LevelBlue, you’re not just an e

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

LevelBlue

View company profile →