LevelBlue LLC logo

Sr. Remediation Specialist (AIR)

LevelBlue LLC
20 hours ago
Full-time
Remote friendly (United States)
United States

LevelBlue reduces risk and builds lasting resilience so organizations can innovate and advance their mission with confidence. As the world’s most analyst-recognized and largest pure-play managed security services provider, LevelBlue elevates client outcomes that matter: stronger defense, faster response, and sustained business continuity. LevelBlue combines AI-powered security operations, advanced threat intelligence, and elite human expertise to provide the most comprehensive portfolio of strategic advisory, managed security, offensive security, and incident response services.

Role Expectations:

The Principal Remediation Specialist is a senior level position with the scope to develop and grow the restoration capability within the AIR practice. The primary goal of each engagement is to recover our clients to an operating capacity post incident.

 

Key Attributes:

Business Support

  • Support the development of bids / proposals associated with the opportunities identified usually from our Digital Forensics and Incident Response practice.
  • Work clients and our sales teams with the generation of SOWs.

Data Collection / Set-up

  • Deployment of client-side data and log collection solutions
  • Assist with forensic collection requests
  • Install Remote Monitoring and Management (“RMM”) utility and/or establish VPN credentials for remote access
  • Deployment of Forensic tools e.g. (SentinelOne / Velociraptor)
  • Develop shared inventory tracking document

Threat Actor Removal

  • Technical engineering efforts to remove the threat actors
  • Acquire third party products and services necessary to remove the threat actors and rebuild, recover, stabilize, and secure the Customer systems and environments
  • Block IOCs within network firewalls as provided by forensics provider
  • Perform impact assessment of servers to determine viability in cooperation with forensics provider

Environment Re-Build

  • Rebuild, recover, stabilize, and secure systems
  • Restoration/ rebuild/ decryption of servers
  • AD Health review and rebuild
  • Domain controller rebuilds and AD hardening
  • Configure segregated networks
  • Hypervisor configurations
  • LAPS (Local Administrator Password Solution) configuration
  • Troubleshooting, impact to and recovery options for Exchange
  • Remote site Firewall Firmware update assistance

Legal / Comms

  • Work with Company, Customer’s General Counsel, Customer’s insurance carrier, and any applicable third parties

Desired Experience:

Due to the varied nature of client systems; as wide and diverse experience across multiple technologies and solutions is preferable. Typical technologies and solutions include:

Leadership

  • More than 10 years in IT / Network / Cloud Engineering roles
  • Leading enterprise recovery type projects
  • Disaster Recovery planning
  • VMware/Hyper-V, AWS/Azure/GCP recovery
  • IaC – Infrastructure as Code (Terraform, Ansible)

Network Recovery SME

  • Veeam, Commvault, Rubrik, Cohesity

Cloud Recovery SME

  • Cloud/SaaS admin
  • AWS/Azure Security Engineer

Infrastructure & Backup Tools

  • VMware vSphere, Hyper-V, AWS Backup, Azure Site Recovery
  • Veeam, Commvault, Rubrik, Cohesity, Zerto
  • Immutable storage: S3 Object Lock, Wasabi Immutable, Dell Data Domain

Network Tools

  • Firewalls: Palo Alto, Cisco ASA/FTD, SonicWall, Watchguard
  • Monitoring: SolarWinds, NetFlow analyzers, Wireshark
  • Segmentation: VLANs, Illumio, Guardicore

Endpoint Tools

  • EDR/XDR: CrowdStrike, Defender ATP, SentinelOne
  • RMM: Screen Connect, Kaseya, NinjaOne
  • MDM: Intune, JAMF, Workspace ONE
  • Imaging: MDT, Clonezilla, Acronis

Cloud & SaaS Recovery Tools

  • AWS/Azure/GCP recovery playbooks
  • SaaS backup: Spanning, Druva, AvePoint
  • IAM monitoring: CloudTrail, Azure Sentinel

Communication & Coordination Tools

  • Project Management: Connectwise, AutoTask, Atera
  • Secure comms: Signal, MS Teams with eDiscovery
  • Crisis platforms: xMatters, Everbridge
  • Documentation: Confluence, SharePoint, ServiceNow

Testing & Validation Tools

  • Red/Yellow/Green segmented environments
  • Sandbox for malware testing: Cuckoo, AnyRun
  • Cyber range and tabletop testing platforms

Qualifications:

  • Relevant academic degree
  • CISM or CISSP (or a commitment to obtain within 12 months)
  • GCWN, ITIL, DRII Certified
  • CCNP Security, PCNSE, GCIA
  • Microsoft 365 Certified, JAMF, Security+
  • Veeam Certified, GEBR
  • CCSP, CCSK

Education:

  • A high school diploma or equivalent is required; a college or university degree is a plus.

Why Join LevelBlue?
At LevelBlue, you’re not just an employee—you’re part of a team making a real difference in the world of cybersecurity. We foster a culture of innovation and creativity where your contributions are valued, and you’ll have the support and resources to grow and thrive.

Benefits and Perks:

  • Comprehensive medical, dental, and vision insurance.
  • 401(k) with employer matching.
  • Generous paid time off and holidays.
  • Flexible spending accounts and health savings accounts.
  • Employee assistance programs.
  • Training and development opportunities.
  • Adoption assistance program.

 

This role is open to candidates legally authorized to work in the United States. At LevelBlue, we support flexible work and bring people together in person for key moments based on role, team, and business needs.

LevelBlue is committed to a culture of respect, inclusion, and equal opportunity. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other status protected under applicable law.

To all agencies: Please do not contact LevelBlue employees outside of the Talent Acquisition team. LevelBlue’s policy is to only accept resumes from agencies through its approved agency process and with a valid agreement in place. Any resume submitted outside this process will be considered the property of LevelBlue, and no fee will be paid if a candidate is hired from such a submission.

 

#LI-MC1