Restoration and Recovery Lead
Listed on 2026-01-12
-
IT/Tech
Cybersecurity
WORKING IN CYBER AT S‑RM
S‑RM is a global intelligence and cyber security consultancy. Since 2005, we’ve helped some of the most demanding clients in the world solve some of their toughest information security challenges.
We’ve been able to do this because of our outstanding people. We’re committed to developing sharp, curious, driven individuals who want to think critically, solve complex problems, and achieve success.
But we also know that work isn’t everything. It’s about the lives and careers it helps us build. We’re immensely proud of this culture and we invest in our people’s wellbeing, learning, and ideas every day.
We’re excited you’re thinking about joining us.
ROLE DESCRIPTIONWe are looking for talented consultants to join the Restoration & Recovery team within our growing Incident Response practice.
You will work across the full lifecycle of security incidents, primarily ransomware, to help our clients respond and recover. S‑RM’s Incident Response team operates a global delivery model, so you will support incidents across multiple geographies, with a focus on Europe and North America.
Key Responsibilities- Developing restoration strategies during Incident Response cases
: working alongside your colleagues in the Incident Response team, you will develop bespoke restoration strategies during live incidents, focusing on ensuring security and capability is maintained. - Executing these strategies to help clients restore their operations quickly and securely
: in partnership with client’s IT and security teams, you will lead on the execution of these strategies, restoring clients to operations in a quick and secure manner. - Leading and developing relationships with supporting restoration partners
: in cases where we need to surge additional resources through our partners, you will manage these relationships and direct the work of our partners to ensure S‑RM’s standards are met. - Capability development
: you will contribute to the development of S‑RM’s restoration and recovery capability, creating playbooks and providing training for the broader Incident Response team to ensure effective collaboration during cases. - On‑site Restoration Support
: in some cases, it may be beneficial to support clients locally at their data centres or office locations. You may be expected to attend their sites during the early stages of restoration to help support these efforts.
Due to the global nature of S‑RM’s Incident Response team, this role requires working in shifts
. The shift pattern will be finalised once all hires for this role have been made. In the interests of transparency, we expect the shift pattern will ensure coverage of core US working hours (Eastern Time) as well as weekends. Responsibility for unsociable shifts will be shared across the team.
- Variety of casework
: no day will be the same. Our team responds to a huge variety of incidents for both public and corporate clients. - Developing an understanding of Incident Response
: you will have opportunities to broaden your security awareness into the wider incident response process, learning how restoration fits into the bigger picture of a response. - Flexible working practices
: responding to incidents can be intense, high‑pressure work. We are mindful of our team’s work/life balance and offer flexible working options to support your wellbeing.
We are seeking candidates with diverse levels of experience and expertise in IT Engineering, System Administration or Cyber Security to join our Restoration & Recovery team.
We nurture a culture of equality, diversity and inclusion and we are dedicated to developing a workforce that displays a variety of talents, experiences and perspectives.
Candidate Profile- In‑depth knowledge of on‑premise, virtualised (ESXi / Hypervisor Technology) and cloud‑hosted (AWS/Azure/GCP) configuration and implementation.
- In‑depth knowledge of Active Directory functions, implementation, and configuration, including integrations with Entra .
- Comprehensive understanding of standard backup solution practices, restoration of data and preparing systems for introduction into production environments.
- Comprehensive…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).